Solved

Forwarding ISP's Ip

Posted on 2004-10-07
10
234 Views
Last Modified: 2010-05-18
I have a single DC running DNS and DHCP on them. In DHCP I have the scope configuration  listing the ISP's DNS address along with my DNS server. I want to be able to forward the ISP address thru DNS and have my DNS server listed as the only DNS server on my lan. I can do this right???  If I have DHCP only list the dc as the DNS server and have the ISP's address listed as a forwarder my internet stops working on all 4 of my subnets. I don't have a root zone "." listed so I am at a loss. We do have a PIX box doing NAT but we just got that installed so I know very little about it. Where should I start on this one?
0
Comment
Question by:Backbiter
  • 6
  • 4
10 Comments
 
LVL 15

Expert Comment

by:adamdrayer
ID: 12258854
well i would say to make sure that the PIX is forwarding port 53, but if you had internet connectivity ever, then i would say that it is already working.

Here's what you should do...

Set DHCP to only hand out your DC as the DNS server.  Delete all forwarders from your DNS settings.  Clear your DNS cache.  goto a client, type "ipconfig /release"  and then "ipconfig /renew"  then type "nslookup www.google.com" and see if it resolves.  Windows Server doesn't need forwarders.  if the nslookup fails, then try this "nslookup -d2 www.google.com" and post results.
0
 
LVL 15

Expert Comment

by:adamdrayer
ID: 12258897
make sure you uncheck "enable forwarders"
0
 

Author Comment

by:Backbiter
ID: 12259926

C:\>nslookup www.google.com
Server:  apollo.misd.local
Address:  172.16.11.4

DNS request timed out.
    timeout was 2 seconds.
*** Request to apollo.misd.local timed-out

C:\>nslookup -d2 www.google.com
------------
SendRequest(), len 42
    HEADER:
        opcode = QUERY, id = 1, rcode = NOERROR
        header flags:  query, want recursion
        questions = 1,  answers = 0,  authority records = 0,  additional = 0

    QUESTIONS:
        4.11.16.172.in-addr.arpa, type = PTR, class = IN

------------
------------
Got answer (73 bytes):
    HEADER:
        opcode = QUERY, id = 1, rcode = NOERROR
        header flags:  response, auth. answer, want recursion, recursion avail.
        questions = 1,  answers = 1,  authority records = 0,  additional = 0

    QUESTIONS:
        4.11.16.172.in-addr.arpa, type = PTR, class = IN
    ANSWERS:
    ->  4.11.16.172.in-addr.arpa
        type = PTR, class = IN, dlen = 19
        name = apollo.misd.local
        ttl = 1200 (20 mins)

------------
Server:  apollo.misd.local
Address:  172.16.11.4

------------
SendRequest(), len 43
    HEADER:
        opcode = QUERY, id = 2, rcode = NOERROR
        header flags:  query, want recursion
        questions = 1,  answers = 0,  authority records = 0,  additional = 0

    QUESTIONS:
        www.google.com.MISD.local, type = A, class = IN

------------
------------
Got answer (106 bytes):
    HEADER:
        opcode = QUERY, id = 2, rcode = NXDOMAIN
        header flags:  response, auth. answer, want recursion, recursion avail.
        questions = 1,  answers = 0,  authority records = 1,  additional = 0

    QUESTIONS:
        www.google.com.MISD.local, type = A, class = IN
    AUTHORITY RECORDS:
    ->  misd.local
        type = SOA, class = IN, dlen = 41
        ttl = 3600 (1 hour)
        primary name server = apollo.misd.local
        responsible mail addr = hostmaster
        serial  = 1743
        refresh = 900 (15 mins)
        retry   = 600 (10 mins)
        expire  = 86400 (1 day)
        default TTL = 3600 (1 hour)

------------
------------
SendRequest(), len 32
    HEADER:
        opcode = QUERY, id = 3, rcode = NOERROR
        header flags:  query, want recursion
        questions = 1,  answers = 0,  authority records = 0,  additional = 0

    QUESTIONS:
        www.google.com, type = A, class = IN

------------
DNS request timed out.
    timeout was 2 seconds.
timeout (2 secs)
SendRequest failed
*** Request to apollo.misd.local timed-out

C:\>
Here are the results that I came up with . The internet service works fine as long as we have the ISP address in Name Servers. Not sure exactly what the above is saying so please diagnose for me...and thank you for your help.
Ben
0
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

 
LVL 15

Expert Comment

by:adamdrayer
ID: 12260052
on the forwarders tab for the DNS server, do you have checked "do not use recursion"?  if so disable it.

also on the monitoring tab, try running a recursive query to other DNS servers.  Are you sure your Server has internet access?
0
 
LVL 15

Expert Comment

by:adamdrayer
ID: 12260061
>>on the forwarders tab for the DNS server, do you have checked "do not use recursion"?  if so disable it.

I mean, uncheck it.
0
 

Author Comment

by:Backbiter
ID: 12261026
The server does not have internet access. I should have mentioned that. The "do not use recursion" is unchecked and it fails the recursive test. Thanks.
0
 

Author Comment

by:Backbiter
ID: 12261030
Also the dns server is on a 172.16.11.x subnet.
0
 
LVL 15

Accepted Solution

by:
adamdrayer earned 250 total points
ID: 12261267
well, the server needs internet access.

If you are asking your clients to use only the DNS server for DNS name resolution, and then asking your DNS server to forward unknown requests to an IP address on the internet, it will need access to the internet.
0
 

Author Comment

by:Backbiter
ID: 12262646
Thanks, makes good sense to me...now :)
0
 
LVL 15

Expert Comment

by:adamdrayer
ID: 12262947
thanks.  glad to help
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
CISCO ASA 5505 - strange behavior (Inside Interface down) 4 72
Routing between two networks? 10 54
Win10 RDP Disconnect/can't reconnect 5 76
Surface Pro 4 wifi 4 24
Greetings, Experts! First let me state that this website is top notch. I thoroughly enjoy the community that is shared here; those seeking help and those willing to sacrifice their time to help. It is fantastic. I am writing this article at th…
This article is in response to a question (http://www.experts-exchange.com/Networking/Network_Management/Network_Analysis/Q_28230497.html) here at Experts Exchange. The Original Poster (OP) requires a utility that will accept a list of IP addresses …
This Micro Tutorial will give you a basic overview how to record your screen with Microsoft Expression Encoder. This program is still free and open for the public to download. This will be demonstrated using Microsoft Expression Encoder 4.
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question