question

nUber avatar image
0 Votes"
nUber asked nUber commented

Name Resolution Policy Table (NRPT) only active on device tunnel but not user tunnel

Hi there,


We have configured NRPT on our "Always On VPN - UserTunnel" configuration profile in Intune.


Configuring it on the device tunnel is not supported as this article states: https://docs.microsoft.com/en-us/windows-server/remote/remote-access/vpn/vpn-device-tunnel-config


However, when I am connected with the device tunnel only and I run the Get-DnsClientNrptPolicy Powershell cmdlet then I see the correct NRPT configuration (which we defined on the user tunnel).


Then when I connect the user tunnel VPN, the device tunnel automatically disconnects and the NRPT configuration disappears (the Get-DnsClientNrptPolicy cmdlet gives no output anymore and desired DNS behaviour doesn't work as expected anymore).


Am I missing something here or is this situation the opposite of what it is supposed to be?


Thanks already for the help.

windows-10-network
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

LimitlessTechnology-2700 avatar image
0 Votes"
LimitlessTechnology-2700 answered nUber commented

Hello @nUber

Yes, it s a very strange behavior but I have seen it before.

The fact that something is not supported, it not always means that will not work, just that might not be coherent :)

What I have seen is that it mostly fails when configured as "Device Tunnel" only. But if you configure it as Device and User tunnel, it does work. This has been already repro'd by many people posting on communities. But at the same time, considering that it makes it work, I can also break the one in User Tunnel. My recommendation will be to remove the configuration for Device Tunnel and leave only User Tunnel policy.

More details on the settings here: https://docs.microsoft.com/en-us/windows-server/remote/remote-access/vpn/vpn-device-tunnel-config

Besides being quite interesting and exotic, I usually don't dig into troubleshooting services or settings not supported or not recommended, as the results are very inconclusive most of the times and jjust gets to a rabbit hole.

Hope this helps,
Best regards,

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi @LimitlessTechnology-2700 , thanks so much for the useful feedback. A few questions:

  • Is NRPT not supported?

  • Can you configure a Tunnel to be both device AND user tunnel at the same time or is that not what you mean?

Good point about troubleshooting exotic settings. I've been deep in the rabbit hole a couple of times for services or settings that are actually not well developed or supported. It's a shame you have to find out those things only after digging so much.



0 Votes 0 ·