Solved

DNS does not escalate for its own domain name

Posted on 2004-10-16
10
348 Views
Last Modified: 2010-04-10
Situation:
an inhouse net with AD domain "mydomain.com".
outside ISP with web server: www.mydomain.com and some more subdomains as: x.mydomain.com, y.mydomain.com,...
The ISP provides 2 DNS server: NS1 and NS2
My inhouse DNS server has all inhouse ip mapped to names.

I could access by IE6 all inhouse of mydomain and all other (not my domain)  targets outside (usual web access)
>>> I could not access my (outside) www and subdomains!
Obviously my DNS does not resolve the outside domains when it has to look for inhouse domain names outside (escalating to the ISP provided 2 DNS server).

The outside domains has 2 DNS server (provided by the ISP) which are listed as 2nd and 3rd when listing with ipconfig /all
First DNS server is my inhouse DNS server.

I made a test by moving one of the outside DNS server to position 1 in my list.
Now I have access to all outside and "www.mydomain.com" too. but i.e. Outlook doesn't resolve to my (local /inhouse) Exchange2003 server. It says the server maybe down. But the problem the local server is not found as its name is not resolved. (MY! inhouse DNS server doesn't obviously resolve it as it is not asked or not asked early enough when it is a timing problem.)

Internet access is by DSL and an dynamic IP for the DSL-Router

Whats wrong?
Could it be that timing plays a role. How should I over came that?
How could I make my DNS server escalating an unresolved name to DNS 2 and DNS3? As it obviously does for all foreign domains but not for the AD (inhouse) domain?

Any help would be really appreciated.
Juergen Loewner
0
Comment
Question by:JLoewner
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
10 Comments
 
LVL 15

Expert Comment

by:scampgb
ID: 12327653
Hi JLoewner,
If the DNS server is configured to be authoritative for "mydomain.com" (which is is) then it won't refer to another DNS server if it doesn't have a record that matches the request.
Instead it'll just return that the record can't be found.
This is correct behaviour.

What you'll have to do is add "A" records to your Internal DNS zone on your server that points to the external IPs.  For example "www.mydomain.com" A 1.2.3.4

Does that help?
0
 

Author Comment

by:JLoewner
ID: 12327683
This I have done already. It works.

But I don't want to care about the mappings locally as it is intended to have lots of subdomains as some diferent other domains..
As everything is on the ISPs NS1 and NS2 why can't it work this way: if it is not resolved here lets look as usual in the listed DNS server?

Or is there a workaround gain this?

0
 
LVL 3

Expert Comment

by:_Jochen_
ID: 12327740
tell your internal DNS server the IP of the external DNS Servers for a Forwarding Lookup Zone.
All unkown names will be forewarded to the external Servers.
Something general: Dont use the same DNS Name for internal net, as you use for external net.
0
NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

 

Author Comment

by:JLoewner
ID: 12327809
>>tell your internal DNS server the IP of the external DNS Servers for a Forwarding Lookup Zone

I guess I have already done that:
in DNS admin I added an record i.e.: nameserver (NS) ns27.1and1.com

That hasn't worked.

Or do you mean someting different?
0
 

Author Comment

by:JLoewner
ID: 12327849
>>tell your internal DNS server the IP of the external DNS Servers for a Forwarding Lookup Zone

some additional info to this:

When I tied this I had the following effect:
nslookup found my external name.
But I couldn't ping it.
And I couldn't reach it by IE6
0
 
LVL 15

Expert Comment

by:scampgb
ID: 12327896
_Jochen_:
> tell your internal DNS server the IP of the external DNS Servers for
> a Forwarding Lookup Zone.
> All unkown names will be forewarded to the external Servers.

That's not quite the whole story.  Any request for a domain for which the DNS server doesn't have a cached response will be sent on to the forwarders UNLESS the DNS server itself is authoritative for that zone.

If the Internal domain zone is the same as one hosted elsewhere you will need to duplicate your "external" entries on your Internal DNS server.

LJowner: you could consider subdomain delegation for handling the subdomains, but the "mydomain.com" Internal zone will still need to have entries from your External one.
0
 

Author Comment

by:JLoewner
ID: 12327981
So I have to stick with my 1st comment:
All external xyz.mydomain.com (varying xyz) have to be entered manually at my local DNS server!?

This is not very satisfying.
It is ok for 1 or 2 servers outside.

But if you have to care for a bunch of it with changing entries on a nearly weekly basis this is an foreseeable error prone work.

No workaround?
No flash of inspiration folks?
0
 
LVL 15

Expert Comment

by:scampgb
ID: 12327991
JLoewner:
Sorry - the only "solution" is for you to be using a different DNS zone for your Internal network.
0
 
LVL 71

Accepted Solution

by:
Chris Dent earned 100 total points
ID: 12328535

Split Brain DNS (mutliple "Start of Authority" Servers for a single Domain) is a far from ideal set-up (aka high maintainance).

You could always rename your Private Domain, then requests would be handled as you want by your Internal DNS.

http://www.microsoft.com/windowsserver2003/downloads/domainrename.mspx
0

Featured Post

Resolve Critical IT Incidents Fast

If your data, services or processes become compromised, your organization can suffer damage in just minutes and how fast you communicate during a major IT incident is everything. Learn how to immediately identify incidents & best practices to resolve them quickly and effectively.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
VLAN Questions 3 70
Domain Controller/ Old server 9 71
line utilization 4 29
exchange, IIS, AUTODISCOVER, OWA 18 68
If your business is like most, chances are you still need to maintain a fax infrastructure for your staff. It’s hard to believe that a communication technology that was thriving in the mid-80s could still be an essential part of your team’s modern I…
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question