question

01402412 avatar image
0 Votes"
01402412 asked FanFan-MSFT commented

Vpn connected users to communicate with ad server placed in dmz only.and to change the users password by clicking alt+cntrl+delete

Dear team,

i have three active directory servers.

1)ad-a (primery domain controller)

2)ad-b ( secondery domain controller)

3) ad-c (domain controller placed in dmz )

i want my vpn connected users to communicate with my 3rd active directory server which is placed in dmz. i need to change vpn users to change their password by clicking alt+cntl+Delete keys. but they cant change the password ,because its communicating with primery ad only.

for vpn users we not allowed any communiction with primery and secondery ad from our firewall.we only given communication from active directory server which we placed in dmz region. but when we try change password its trying to communicate with primery ad automaticaly. that trafic i can see in my firewall.

i can update group policy .but i can not change user password.

what will be the reason and how we can resolve the issue.

i hope you understand the issue.your assistance will be appreciated.



windows-serverwindows-active-directorywindows-server-2016
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi,
I am checking to see if the problem has been resolved.
If there's anything you'd like to know, don't hesitate to ask.
Best Regards,

0 Votes 0 ·

1 Answer

FanFan-MSFT avatar image
0 Votes"
FanFan-MSFT answered FanFan-MSFT commented

Hi,

What's the error message when you tried to change the password?
Based on my test, user password can be performed on other DCs in the domain even can't connect to the PDC.
So, you may try to confirm the ports used to change the password on the clients and DCs in the DMZ.
Following information about the ports for your reference:
https://techgenix.com/domain-controllers-required-ports/
This response contains a third-party link. We provide this link for easy reference. Microsoft cannot guarantee the validity of any information and content in this link.

Best Regards,


· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi,
 
Just want to confirm the current situations.
If there's anything you'd like to know, don't hesitate to ask.

Best Regards,

0 Votes 0 ·