Forefront Edge Security TechCenter >
Forefront Edge Security Forums
>
Forefront Edge Security – IAG/UAG
>
UAG RC0 activation error
UAG RC0 activation error
- I'm using non Microsoft DNS system(Alcatel-Lucent VitalQIP), and allow only selective DNS updates to selected.
I currently allow only CNAME and SRV records updates from domain controllers.
While activating the configuration, I get the following error: "failed to register NCSI lookup entry in the DNS"
Can someone tell me what kind of update the server is trying to perform in the DNS system, so I'll be able to allow this update?
Thanks in advance,
Eyal.
Eyal Shaynis
Answers
- RC0 requires a DNS server that supports dynamic updates.
It's trying to register it the NCSI lookup host (read here: http://technet.microsoft.com/en-us/library/ee382273(WS.10).aspx)
AAAA UAGDirectAccess-corpConnectivityHost ::1
In RTM this wouldn't be a requirement for activation and failure to register this to the DNS will only issue a proper warning- Proposed As Answer byYaniv Naor Monday, October 19, 2009 6:48 AM
- Marked As Answer byBen AriMSFT, OwnerThursday, October 22, 2009 2:09 PM
All Replies
- RC0 requires a DNS server that supports dynamic updates.
It's trying to register it the NCSI lookup host (read here: http://technet.microsoft.com/en-us/library/ee382273(WS.10).aspx)
AAAA UAGDirectAccess-corpConnectivityHost ::1
In RTM this wouldn't be a requirement for activation and failure to register this to the DNS will only issue a proper warning- Proposed As Answer byYaniv Naor Monday, October 19, 2009 6:48 AM
- Marked As Answer byBen AriMSFT, OwnerThursday, October 22, 2009 2:09 PM
Hello,
I am configuring a newly installed UAG server, but I get the same error message: failed to register NCSI lookup entry in the DNS"
I am using Microsoft DNS, but I think my admin account does not have sufficient rights to change the dns.
Can someone explain me what's going wrong and how to fix this manually, so I can ask the dns admin to add the necessary records?
Thanks in advance,
Ramon- The DNS registration is actually done from the machine account and not from your user account, so if dynamic updates are enabled in your organization, there shouldn't be any problem.
Perhaps you do not have a Windows Server 2008 based DNS server? and your current Windows 2003 DNS server supports only IPv4 DNS registrations.
Unfortunately, in the RC0 version, if the DNS registration fails, the entire activation fails and there's not much to do about it.
To workaround this problem, you can configure on the UAG box a different DNS server that will allow you to register the NCSI record.
This can be a hyper-V machine with Windows 2008 server and DNS role installed.
After activation succeeds, configure the UAG box with the real DNS server, and ask the dns admin to add the following record:
AAAA UAGDirectAccess-corpConnectivityHost ::1

