Windows DNS does not work

I have some computers on my network where DNS resolution in Windows XP Home does not work. I can ping an outside IP address, but I can't ping an outside address if I ping by name. I've tried booting the computer in safe mode with networking and it still has the same problem. I've tried changing DNS servers but that doesn't do anything. I have also reinstalled the drivers but that does nothing for me. The HOSTS file appears to be normal. I have 2 computers that are affected by this and both are Windows XP Home and both occured at the same time. However, I'm in WIndows XP Professional and I don't have this problem. The Home machines are up to date in terms of patches. It is beginning to seem more and more like a virus/trojan to me than some kind of glitch in Windows. Can someone please tell me how to resolve this issue and confirm that this is a virus/trojan?
LVL 1
majikmanAsked:
Who is Participating?

Improve company productivity with a Business Account.Sign Up

x
 
boxcar7Connect With a Mentor Commented:
Your XP machines should probably be using the router as your DNS server.  That will elimate the need to contact outside DNS servers.  Is your Netgear getting it's DNS information from DHCP?  Check in your Netgear's interface what machines it is using for DNS.  If it is nothing, see if it can get that information from DHCP from the ISP.  If not, check with your ISP what DNS servers you can use and set it manually in the NetGear.

Also, some routers have an nslookup or a ping utility.  See if you can use it to ping by name or look up a name.

0
 
mrpez1Commented:
What happens when you do a NSLookup? If you haven't already, do a virus scan and adaware scan to rule out the virus/spyware.
0
 
majikmanAuthor Commented:
its not adware or spyware because i just formatted one of the computers and completely reinstalled. turns out the problem is with my router. for some reason, i don't think its letting udp packets through properly. thats probably why dns isn't working. i have a netgear wireless router and i just flashed it to the lastest version. so if anyone can provide me help with this now, i'd be very grateful
0
Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

 
majikmanAuthor Commented:
my router doesn't have a nslookup or ping utility, or else i can't find it. the router is set to assign computers requesting dhcp dns servers as specified by the isp. the router works fine on my computer, but for some reason, every other computer doesn't work.
0
 
mrpez1Commented:
Again, what happens wehn you do a NSlookup from the Home computers?
0
 
brett273Commented:
Try this:

Find out what your DNS servers' IP addresses are (if you don't already know). Say, for example, one is 10.1.1.1.

(the following is assuming you can ping the DNS server IP address from the PC. If you can't then you definitely have a problem in your router somewhere, but from what you're saying it doesn't sound like this will be the problem)

Drop to a Command prompt and try to telnet to that IP address on port 53: "telnet 10.1.1.1 53". You should just get a blank screen. If so then at least you can talk to the DNS server itself. If you get a timeout or a connection refused then something (most likely your router) is blocking it.

If it's not working, try eliminating the router by your cable/DSL modem directly to the problematic PC. This should enable it to get an IP address directly from your ISP's DHCP server. If it works then, it's probably the router (though I've never seen that happen before...weird)

BTW, nslookup is simply a DNS testing utility. If you type, say, "nslookup experts-exchange.com" you chould get a response from your DNS server telling you it's name and IP address and the IP address of the domain you requested:

Example from my machine:

C:\Documents and Settings\bwhite>nslookup experts-exchange.com
Server:  baran.ronconet.com
Address:  208.247.106.7

Non-authoritative answer:
Name:    experts-exchange.com
Address:  64.156.132.140

Hope this helps!

0
 
infotraderCommented:
Under your TCP/IP properties of those computers, did you check to see if "Internet Connection Firewall" is turned on?

- Info
0
 
majikmanAuthor Commented:
Internet Connection Firewall is not turned on. This is what I get from nslookup

DNS request timed out.
    timeout was 2 seconds.
*** Can't find server name for address 24.205.1.14: Timed out
DNS request timed out.
    timeout was 2 seconds.
*** Can't find server name for address 66.215.64.14: Timed out
*** Default servers are not available
Default Server:  UnKnown
Address:  24.205.1.14

as for brett's entry, just because you can't ping a dns server does not mean its down. pinging uses icmp packets while dns requests typically use udp packets. therefore, a server admin can firewall the dns server from the icmp packets and it would still work as a dns server. as i have already said in a comment up above, i have already established that the problem is with my netgear router/switch combo. here's another wierd thing i've just noticed. on my windows xp machines, dns will only work if my ip is set to 192.168.0.2. if i change it to 192.168.0.3, or anything else for that matter, it won't work. on top of that, i have a windows me machine and a linux machine and both will work regardless of the ip assigned. i am curious if i add another win98 or nix machine if either one of those will also have its dns fail but unfortunately, i don't have another machine to test that out. so, anyone think they can figure this out? btw, i've tried looking for something that is blocking specific ips in my router configuration but there is no such option. i've also reset my router to factory settings.
0
 
Joseph NyaemaIT ConsultantCommented:
What is the IP address range in your network?
Also what is the IP assigned to the router?
And are the DNS server IPs?
0
 
spikeworldCommented:
go to cmd window..
type in ipconfig /all >> c:\ip.txt
go open that file c:\ip.txt in notepad, copy the text and
paste it here.

things to check
go to network in control panel, click on local area connection, click on properties, click on tcpip, click properties.
set the first dns server to 38.9.212.2, save it and see if you can hit say.. www.msn.com  what is your result?
0
 
majikmanAuthor Commented:
Windows IP Configuration
        Host Name . . . . . . . . . . . . : adam-winxp
        Primary Dns Suffix  . . . . . . . :
        Node Type . . . . . . . . . . . . : Hybrid
        IP Routing Enabled. . . . . . . . : No
        WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Local Area Connection:
        Connection-specific DNS Suffix  . : charterpipeline.net
        Description . . . . . . . . . . . : Realtek RTL8139/810x Family Fast Ethernet NIC
        Physical Address. . . . . . . . . : 00-E0-7D-AE-41-6B
        Dhcp Enabled. . . . . . . . . . . : Yes
        Autoconfiguration Enabled . . . . : Yes
        IP Address. . . . . . . . . . . . : 192.168.0.3
        Subnet Mask . . . . . . . . . . . : 255.255.255.0
        Default Gateway . . . . . . . . . : 192.168.0.1
        DHCP Server . . . . . . . . . . . : 192.168.0.1
        DNS Servers . . . . . . . . . . . : 24.205.1.14
                                                    66.215.64.14
                                                    66.215.64.14
        Lease Obtained. . . . . . . . . . : Friday, March 26, 2004 1:45:49 PM
        Lease Expires . . . . . . . . . . : Friday, April 02, 2004 1:45:49 PM

i don't see how this is affecting anything. i'm not going to change the ip of my dns because, as i said, my dns servers are working. i know they are working because i am using those same dns servers in my linux machine and i am having no problem with that system. please read everything i have written above before you decide to comment as i have made about 2 or 3 updates to the status of the problem. btw, if i try to browse to a page, it doesn't work.
0
 
shaggybCommented:
here are a few things to try out.... please let me know how this goes because this is a baffeling thing for me....  I have seen this a number of times at work and havent been able to devote much tmie at all for one of these things........ Ususaly our answer is restore restore restore......  and that might be waht you have to do anyway.

http://support.microsoft.com/default.aspx?scid=kb;en-us;Q241344


good luck
0
 
majikmanAuthor Commented:
no that won't work. as i have said, the problem is with the router. restoring won't work because i've already tried that and on top of that, i completely formatted one system and reinstalled the os. as i have said, the problem is with the router. if i am the only computer on the network and i change my ip to 192.168.0.3, my dns fails. if i change it to 192.168.0.2, it works.
0
 
Joseph NyaemaIT ConsultantCommented:
And there are no duplicate IPs on your network?
What error messages do you get in event viewer, especially do to with networking?
0
 
majikmanAuthor Commented:
no duplicate ips. windows would notify me if there were. no error messages in event viewer. everything in networking seems to load up fine. i can ping outside ip's, its just that my dns doesn't work.
0
 
shaggybCommented:
forgive me i missed that detail, that does change everything....

have you reset the router configuration to default yet?
perhaps you have somthing with port forwarding or port triggering

what kind of router is it. make model etc.....

0
 
chicagoanCommented:
Let' see of you can talk to ANY dns servers:
Enter these commands in a DOS window:

NSLOOKUP

SERVER 63.208.196.90

DYNDNS.ORG

SERVER 192.168.0.1

WWW.MICROSOFT.COM

> i change my ip to 192.168.0.3, my dns fails. if i change it to 192.168.0.2
That would argue for some filtering somewhere... your router could be whacked - have you looked for updated firmware or refreshed the firmware/set to factory defaults?
Have you tried a number of other addresses (i.e. 192.168.0.100 - 192.168.0.105)





0
 
Jman8RCommented:
Hi,

You should be able to enter the routers web admin page or similar and check out it's firewall. If you can post the information given on the routers web page for the firewall, we can have a look and verify that it is a problem with the router.

When you said that you can set the IP to '.2' and it works, I assume that this is manually configured. When you change it to '.3' are you leaving it as manually configured or setting it back to be a DHCP client?

It sounds like the firewall is blocking all requests for ip's that are not '.2' so if you can post the routers firewall config here, we can have a look at it for you!


0
 
vermaatiCommented:
Just refresh the DNS resolver cache... ipconfig /flushdns and ipconfig /registerdns

ping the ip by typing ping .. .. .. .. ..
do a reverse lookup by typing ping -a .. .. .. .. ..

some time must be given in between the refresh and the register processes. the ping test is a very good test it will resolve the ip to hostname and hostname to ip. if this works then everything is fine. also check the default gateway. if routing is not enabled on your network or your router is not routable then your dns will not work.

is your default gateway your dhcp ip or your router ip?

cheers
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.