<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't get AD and SMB to work from Azure to On-prem server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-ad-and-smb-to-work-from-azure-to-on-prem-server/m-p/593412#M118102</link>
    <description>&lt;P&gt;So, it turns out that private DNS zone was stopping things from working properly. Weird but as soon as I removed private DNS zone I was able to get SMB and Active Directory to work with on-prem with some further tweaks with network peering in Azure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jul 2024 01:11:28 GMT</pubDate>
    <dc:creator>jimjams2020</dc:creator>
    <dc:date>2024-07-30T01:11:28Z</dc:date>
    <item>
      <title>Can't get AD and SMB to work from Azure to On-prem server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-ad-and-smb-to-work-from-azure-to-on-prem-server/m-p/592779#M117973</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I'm working on a newly created Azure environment with very little networking set up. Our setups are as follows:&lt;/P&gt;
&lt;P&gt;Azure:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Working S2S VPN&lt;/LI&gt;
&lt;LI&gt;Route table pointing to the on-prem subnet&lt;/LI&gt;
&lt;LI&gt;A VM for testing with an NSG allowing all traffic both inbound and outbound&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;On-Prem:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Necessary firewall rules (Palo Alto) to allow AD, SMB, RDP, and ping&lt;/LI&gt;
&lt;LI&gt;A domain controller and a file server&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I've just managed to get RDP and ping to work, but there was a strange issue (I'm new to all this). The issue was related to how RDP traffic from Azure was detected under the "cotp" app ID instead of "ms-rdp," which I normally see in the logs.&lt;/P&gt;
&lt;P&gt;Right now, I'm at a loss trying to get the Azure VM to talk to the on-prem Domain Controller and the file server. The only traffic I'm seeing on the firewall for SMB shows up under the "quic" app ID. I've allowed this traffic to go through, but I still can't access the file server over SMB. No other traffic is showing in the logs except for "quic," which has been allowed. The other weird issue is that I can't see any AD-related traffic at all. I was hoping to see something getting blocked at the very least, but I see absolutely nothing. I've also configured the Azure VM's DNS to point to the on-prem DC, and that didn't help either.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone please shed some light on whether something is missing? I just want to be able to connect to the on-prem server from Azure via SMB and join the server to the domain but no meaningful traffic is showing up in the logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks,&lt;/P&gt;
&lt;P&gt;J&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 12:10:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-ad-and-smb-to-work-from-azure-to-on-prem-server/m-p/592779#M117973</guid>
      <dc:creator>jimjams2020</dc:creator>
      <dc:date>2024-07-23T12:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get AD and SMB to work from Azure to On-prem server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-ad-and-smb-to-work-from-azure-to-on-prem-server/m-p/592837#M117985</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1300905573"&gt;@jimjams2020&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;OS's based on Windows 11 will attempt to utilize QUIC for SMB transfers by default, and RDP traffic being recognized as cotp on the firewall early in the session is not really unexpected in my experience. The SMB traffic should fail back to proper SMB instead of QUIC as soon as the quic connection fails, so the fact that you're not seeing that is a little odd.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you say you setup a site-to-site with Azure, how exactly did you do that? Did you use a VM-series firewall or did you use Azure's native site-to-site connection capability through a VPN gateway? Can you validate that you followed &lt;A href="https://learn.microsoft.com/en-us/azure/vpn-gateway/tutorial-site-to-site-portal" target="_blank"&gt;https://learn.microsoft.com/en-us/azure/vpn-gateway/tutorial-site-to-site-portal&lt;/A&gt; properly?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I personally always try to get folks to use a VM-series so that they have proper logging on both sides. Azure's native networking leaves a lot to be desired in that aspect (in my opinion).&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2024 21:32:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-ad-and-smb-to-work-from-azure-to-on-prem-server/m-p/592837#M117985</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-07-23T21:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get AD and SMB to work from Azure to On-prem server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-ad-and-smb-to-work-from-azure-to-on-prem-server/m-p/592857#M117995</link>
      <description>&lt;P&gt;Thank you for your reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I didn't create S2S VPN myself, but I was told it was created using the guide you'd provided. The virtual network gateway was created using VpnGw2AZ - Generation 2. The whole Azure thing is new to me so I'm learning as I go. I will set up logging and see what I can find there. Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 06:14:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-ad-and-smb-to-work-from-azure-to-on-prem-server/m-p/592857#M117995</guid>
      <dc:creator>jimjams2020</dc:creator>
      <dc:date>2024-07-24T06:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get AD and SMB to work from Azure to On-prem server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-ad-and-smb-to-work-from-azure-to-on-prem-server/m-p/593412#M118102</link>
      <description>&lt;P&gt;So, it turns out that private DNS zone was stopping things from working properly. Weird but as soon as I removed private DNS zone I was able to get SMB and Active Directory to work with on-prem with some further tweaks with network peering in Azure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 01:11:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-ad-and-smb-to-work-from-azure-to-on-prem-server/m-p/593412#M118102</guid>
      <dc:creator>jimjams2020</dc:creator>
      <dc:date>2024-07-30T01:11:28Z</dc:date>
    </item>
  </channel>
</rss>

