So I setup a Domain Controller in my VMWare Workstation setup the other day and I got caught up on such a trivial issue. My DC could access the internet but none of my clients could even though I had all my settings setup correctly. The Fix: I had recently redone my network and removed my Home network card from each machine and only had my vmnet7 (DC LAN) enabled. I thought since it had the correct Default Gateway the computers would get internet, but alas my vmnet7 does not have any access to the WAN! Needed to install RAS (Routing and and Remote Access) which I didn’t.
So here are the NIC settings for my DC:
1 2 3 4 5 6 7 8 9 10 11 12 13
NIC1: Home DHCP 192.168.0.150 (reserved router side) NIC2: LAN 192.168.13.10 255.255.255.0 192.168.13.1 (vmnet7 in vWorkstation DHCP disabled due to me having a DC with DHCP/DNS) NIC3: iSCSCI 192.168.89.10 255.255.255.0 192.168.89.1 (vmnet2 in vWorkstation DHCP disabled due to me having a DC with DHCP/DNS)
Due to NIC1 having access to my home network on my DC, I could ping 188.8.131.52 just fine and was pulling the appropriate info in ipconfig /all.
The clients would get the following output from cmd:
1 2 3 4 5 6 7 8 9
ipconfig /all 192.168.13.x (something in the DHCP range) 255.255.255.0 192.168.13.1 DHCP/DNS: 192.168.13.10 nslookup google.com Server: Unknown IP: 192.168.13.10
What threw me off is when I would ping google.com, they would resolve the IP but the packets would just “request timed out”. I then did the regular troubleshooting and pinged:
- Local IP = all good
- DC IP/hostname = all good
- Router IP/Hostname = all good
- Started a tracert to 184.108.40.206 and noticed it wouldn’t even get one hop.
I had even gone into DHCP on the DC and set the server options:
1 2 3 4
003 = Router 192.168.13.1 005 = Name Servers 192.168.13.10 006 = DNS Servers 192.168.13.10 015 = int.domain.com
I started thinking to myself, why the hell does this always work on a real network and not this one? Then it dawned on me, If the default gateway cannot route packets, how the hell are we supposed to get anything past the LAN!
- NOTE TO SELF: Read the following Technet article to setup RAS if you want your DC to do LAN-WAN conversions (not common unless you setup a VPN server).