Troubleshooting DirectAccess Client Connectivity Problems
ISSUE: Cannot resolve intranet FQDNs (root cause)
When CLIENT1 is on the Internet, it uses encrypted IPsec tunnels to the DirectAccess server (EDGE1) to access the intranet DNS server (DC1) and intranet resources. If the IPsec tunnels cannot be successfully negotiated, CLIENT1 cannot resolve intranet names or connect to intranet resources.
ISSUE: Cannot resolve intranet FQDNs (root cause)
When CLIENT1 is on the Internet, it uses encrypted IPsec tunnels to the DirectAccess server (EDGE1) to access the intranet DNS server (DC1) and intranet resources. If the IPsec tunnels cannot be successfully negotiated, CLIENT1 cannot resolve intranet names or connect to intranet resources.
In this troubleshooting scenario, you will configure the
DirectAccess server to use the wrong root CA for IPsec authentication and then
troubleshoot the results.