Solved

DNS Server can't access the internet

Posted on 2004-08-24
8
252 Views
Last Modified: 2010-04-14
We have a small network of about 8 computers to include a windows 2000 DC which is also a DNS Server. We all use a private address behind a cicso firewall. Currently all the computers use a static ip address. Our default gateway(cicsco firewall) is 192.168.1.1
The DNS Server is 192.168.1.2. The rest of the computers are anwhere from 192.168.1.5
to 192.168.21.

Every computer in our network can access the interest with IE6 and browse with no problem except the DNS Server. If I give the DNS Server a public address and plug it directly into our internet router it browses with no problem. If none of the computers could access the internet I would think it was firewall problem but all the computers behind the firewall can access the internet but the DNS Server

I've deleted the "." root zone on the DNS server and enabled fowarding with the two address from our ISP. I've tried pointing the DNS server to itsself and I've tried pointing it to the two public IP addresses but I still can't get it to browse the internet. One of our remote users who connects to the cisco firewall with the cisco vpn client can ping every computer on our network but the DNS Server.

Would there be anything in how I have dns setup that would prevent the DNS server from accessing the internet with the private ip addressis uses behind the cicso firewall? What can I do to get the DNS Server to access the internet. I'm thinking that if it can access the Internet then our remote user will be able to ping it and map a network drive to it.
0
Comment
Question by:gardnerbartlett
8 Comments
 
LVL 5

Assisted Solution

by:dgroscost
dgroscost earned 125 total points
ID: 11888586
You probably want to check the config of your cisco firewall to see if it's not set up to allow traffic from the DNS Server outbound to the Internet.  
0
 
LVL 12

Accepted Solution

by:
Housenet earned 250 total points
ID: 11889092
Hello..
I guess this is a Pix firewall. There definatly good reasons why this sounds like the firewall is the proble,.

Things to try to eliminate major possibilites.

1. On the DNS server drop to dos and try this.
nslookup -q=soa 2000domainname.lan. 192.168.1.2
nslookup -q=mx microsoft.com. <enter>
nslookup -q=mx microsoft.com. 206.235.86.11(or other known good DNS IP other than the one's you have been using)
Q-Did this return what looks like good results?
-Check internet explorer settings for things like "proxy settings"
-Are the results different from another machine with no explorer problem?

2. Disconnect the server cable, change one of the stations IP to 192.168.1.2/24 gw192.168.1.1.  You either have to clear the arp cache on the cisco, or do this while it is powered off.
Q- Does the Station with the IP 192.168.1.2 function correctly?

0
 

Author Comment

by:gardnerbartlett
ID: 11893473
It is a pix firewall. The DNS server could access the internet before it crashed and I had to reinstall the OS. I gave it the same name and ip address.

When I did nslookup -q=soa domainname.lan 192.168.1.2 I got can't find server server name for address 192.168.1.2. I tried domainname.com.lan and got same response. If I ping server name I get 4 replys with the 192.168.1.2.

When i type nslookup -q=mx microsoft.com I get the same error message for the 192.168.1.2 address and the two forwarder addresses of our isp 216.175.203.34 and 216.175.203.43. when I type When i type nslookup -q=mx microsoft.com 206.235.86.11
I get can't find server server name for address 206.235.86.11.

They all have "automatic doscovery of proxy server" box checked.  I will try disconnecting server cable and giving one of the other workstations the ip address this evening after every leaves work.

Thanks for the comments.  




0
 
LVL 9

Assisted Solution

by:jdeclue
jdeclue earned 125 total points
ID: 11894048
Just double check, if the workstations can resolve the server can as well. Your DNS should be configured as Active Directory Integrated, Forwarding should be enabled and pointing to the External DNS servers, the DNS server should be pointing only to itself, if this is the only DNS server on the inside. After that verify the settings in the Forward lookup zone. You should have Host, NS (Name Server), and a SOA (Start of Authority) records with the DNS server name.




J
0
Free Gift Card with Acronis Backup Purchase!

Backup any data in any location: local and remote systems, physical and virtual servers, private and public clouds, Macs and PCs, tablets and mobile devices, & more! For limited time only, buy any Acronis backup products and get a FREE Amazon/Best Buy gift card worth up to $200!

 

Author Comment

by:gardnerbartlett
ID: 11894796
The workstations can access the server with the servername. We all work off of a drive letter mapped to the DNS Server. DNS is Active Directory integrated. forwarding points to external dns servers but it can't even ping those numbers.

I have 3 lines where the name is "same as parent folder"  the 3 types are:
Start of Authority      [1431], servername.domainname.com., admin.
Name Server            servername.domainname.com
Host                        192.168.1.2

At first I thought if it were a Cisco problem why does it only affect the DNS server but since it is a new install maybe the pix is where I have to look. This evening I'm going to try giving the workstation that address and see what happens.

0
 

Author Comment

by:gardnerbartlett
ID: 11899097
just change my computers ip address to 192.168.1.2 and i accessed the internet with ie6. I changed the ip address on the server to 192.168.1.4 and it still can't access the internet. If it is a cisco pix problem maybe it's tied to the mac address.
0
 

Author Comment

by:gardnerbartlett
ID: 11905657
called cisco, pix seems ok but I cannot ping the default gateway which is the cisco firewall 192.168.1.1. I can ping every other computer on the network. I changed cables and plugged into a different rj45 connector. We are all plugged into the same switch which is plugged into the same cisco firewall.  I'm going to unistall the network card and
reinstall it, move it to a different slot and try a nother network card. ipconfig shows the 192.168.1.1 default gateway but what I see is not what it always is.

I will award points after I resolve this.
0
 

Author Comment

by:gardnerbartlett
ID: 11914436
Turns out I could not ping the default gateway which is the cisco firewall. I changed the network card and can now access the internet.

Every computer was connected to the same switch. One cable connects the switch to the cisco firewall. Another cable connects the cisco firewall to the internet. I can't phantom why the server could ping every workstation connected to the switch but could not ping the cisco firewall which is also connected to the same switch.

I suppose a flaky NIC can cause strange things to happen. I certainly should have checked the basics before getting hung up on DNS but I could ping all of the comupters on the network so I never thought to try to ping the default gateway. thanks for the comments

0

Featured Post

Free Gift Card with Acronis Backup Purchase!

Backup any data in any location: local and remote systems, physical and virtual servers, private and public clouds, Macs and PCs, tablets and mobile devices, & more! For limited time only, buy any Acronis backup products and get a FREE Amazon/Best Buy gift card worth up to $200!

Join & Write a Comment

Suggested Solutions

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
In this article, I will show you HOW TO: Suppress Configuration Issues and Warnings Alert displayed in Summary status for ESXi 6.5 after enabling SSH or ESXi Shell.
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now