This article describes the issue of Windows users being unable to logon to a computer, which uses AD authentication. Further investigation also found that DNS lookups for the AD server host name also fails.
Assume that the following topology leads to asymmetric routing (compare it with your topology):
DNS-Server Y (1.1.1.1 UDP:53) | | ^ v ^ v | | +--->>>----ROUTER-2--->>>----+ | | ^ v ^ v | | +--+--+ +--+--+ |SRX-1| |SRX-2| <<< Packet is dropped by SRX-2 +--+--+ +--+--+ | | ^ | ^ | | | +---<<<----ROUTER-1----------+ | | | | ^ | ^ | | | Host X (2.2.2.2 UDP:12345)
Session ID: 10000, Policy name: T2U/1, Timeout: 60, Valid In: 2.2.2.2/12345 --> 1.1.1.1/53;udp, If: ge-0/0/0.0, Pkts: 1, Bytes: 60 Out: 1.1.1.1/53 --> 2.2.2.2/12345;udp, If: ge-0/0/1.0, Pkts: 0, Bytes: 0 << No packets coming back
set security flow allow-dns-reply commit