Ok guys, here is the story:
I have installed 6 network so far, 6 different Forests therefore domains. In all cases DNS runn on the same machine as Active Directory. One server in 5 cases and three in the 6th case (two DC's and a member). When I query DNS prior to installing AD using ls -d mydomain.com i get result for the query, query by type? no problem. The I run AD installation and DCPROMO detects the DNS server (don't forget: in the same machine) and install smoothly, no errors whatsoever. Clients log in, resolve using DNS, everything fine. BUT! I go to DNS manager, try the lying monitoring tab and the tests pass. when I type NSLOOKUP this is what I get:
> ls -d mydomain.org
*** Can't list domain mydomain: Query refused
Asked everyone I know, teachers @ MCSE class, microsoft white never find pages and I can not get it to work. However I know clients are resolving using DNS. other queries pass, forwarding to ISP DNS is ok. This is in all of these networks, so it must be me. If you need the sequence of steps that I follow to install DNS and AD, let me know.
Thank you very much