Recovered VMs in a failover test to VMware Cloud Director get no DNS settings, so domain logons fail

Modified on Mon, 28 Sep at 12:26 PM

Recovered VMs in a failover test to VMware Cloud Director get no DNS settings, so domain logons fail

Machine-distilled from a resolved support ticket on 2026-09-28. Source ref: 351e91d800a6. Verify before relying on it.

Applies to: Zerto failover tests and recoveries into VMware Cloud Director where VM networking is set by vCD guest customisation (version not specific).

Symptom: During a Zerto failover test into a VMware Cloud Director (vCD) target, recovered VMs boot and get IP addresses, but domain logons fail, including with a known good break glass account, even after the password is reset and the domain controller is rebuilt. Ping between VMs may work, but the affected VMs' network adapters show no DNS servers and no DNS suffix. VMs on different network segments may also be unable to reach each other.

Cause: The recovered VMs take their network settings from the org VDC network (segment) through vCD guest customisation. The target network segments had no primary DNS server or DNS suffix configured, so the VMs came up without DNS and could not locate or authenticate against the domain controllers. Separately, the target edge gateway had no firewall rule allowing traffic between the internal test segments. This can happen when target networking is recreated (for example after a platform or data centre move) and not all settings are carried over.

Resolution: 1. Log on to an affected VM with a local account and check the adapter settings (IP, DNS servers, DNS suffix) to confirm DNS is missing. 2. If VMs on different segments cannot reach each other, check the edge gateway firewall rules on the target and add rules that allow the required traffic between the internal test segments. A broad temporary rule can prove the diagnosis, but replace it with scoped rules afterwards. 3. As an immediate workaround, set the correct DNS servers (the recovered domain controllers) and DNS suffix on the affected VM, restart it and retest the domain logon. 4. For a permanent fix, update every relevant org VDC network in vCD with the correct primary DNS server and DNS suffix so that guest customisation applies them at recovery time. 5. Stop the failover test and rerun it with a single VM (for example a jump box) as a pre-flight check. Confirm with a screenshot of the adapter settings that the IP, DNS servers and suffix are applied, then schedule the full environment test.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article