Log In

Come Join Us!

Are you a
Computer / IT professional?
Join Tek-Tips Forums!
  • Talk With Other Members
  • Be Notified Of Responses
    To Your Posts
  • Keyword Search
  • One-Click Access To Your
    Favorite Forums
  • Automated Signatures
    On Your Posts
  • Best Of All, It's Free!
  • Students Click Here

*Tek-Tips's functionality depends on members receiving e-mail. By joining you are opting in to receive e-mail.

Posting Guidelines

Promoting, selling, recruiting, coursework and thesis posting is forbidden.

Students Click Here


DNS for Exchange over VPN doesn't work

DNS for Exchange over VPN doesn't work

DNS for Exchange over VPN doesn't work


I have a perfectly working DNS environment on the LAN, however on the VPN something strange happens with Outlook clients connecting to the Exchange server. Outlook always connects to the Exchange on the LAN, there is no DNS issue there.

However, on the VPN, for some reason Outlook clients will not connect to Exchange. The workaround is to edit the local client hosts file to add in the IP Address and mail.domain.com, then the Outlook client connects over the VPN.

The problem is, our AV clears entries to the hosts file and I would prefer this to stay in place. So I have users who can work with Outlook on the LAN, then when they connect via VPN they cannot work on Outlook and I manually add the entry to their hosts file to make it work, however after a couple of days, the AV clears the entry on the hosts file and then the next time that user is on the VPN, Outlook doesn't work again, and I add the entry again...

I would prefer to sort out why the Exchange server IP address is not being resolved over the VPN. The strange thing is, all other servers are resolving over the VPN. The VPN server pushes the same DNS server settings to VPN clients as are used on the LAN. So I cannot work out where the problem with Exchange being resolved over the VPN lies.

Environment: Windows 10, Server 2012, Outlook 2013, Exchange 2013, OpenVPN-AS.

Any help would be appreciated.


RE: DNS for Exchange over VPN doesn't work

Make sure your VPN handoff includes the required DNS server which has to be reachable by the VPN client. That way your client's resolver will query the needed DNS first. Hosts file entries is something one should avoid.

CODE -->

and look at the order of DNS servers to make sure.

RE: DNS for Exchange over VPN doesn't work

Thanks Iggsterman.

Of course, the host file changes are only a workaround.

And that's the weird thing. DNS settings are the same for LAN and VPN. ipconfig /all shows exactly the same information on the LAN and the VPN, DNS server order included. With the only difference being the IP Address which is a different subnet to LAN IP addresses.

And weirder still. All servers resolve successfully on the VPN. The only one is Exchange that has the problem.

I don't know if this would make a difference, our mail is in the format @company.com but our domain is corp.company.co.jp

RE: DNS for Exchange over VPN doesn't work

So you a4re confirming that you can reach the DNS servers from VPN? When you run nslookup can you confirm the replies come from the needed DNS server? Maybe it times out and the resolver goes down the list.
Another possibility is and you need to ask your friendly network engineer, if they are doing what is called "DNS rewrite".

Red Flag This Post

Please let us know here why this post is inappropriate. Reasons such as off-topic, duplicates, flames, illegal, vulgar, or students posting their homework.

Red Flag Submitted

Thank you for helping keep Tek-Tips Forums free from inappropriate posts.
The Tek-Tips staff will check this out and take appropriate action.

Reply To This Thread

Posting in the Tek-Tips forums is a member-only feature.

Click Here to join Tek-Tips and talk with other members!

Close Box

Join Tek-Tips® Today!

Join your peers on the Internet's largest technical computer professional community.
It's easy to join and it's free.

Here's Why Members Love Tek-Tips Forums:

Register now while it's still free!

Already a member? Close this window and log in.

Join Us             Close