2003 DNS resloves only 25% of internet name resolution

I am preping for a migration to 2003 AD. I configure the first DC runing DNS. I am successful in creating a trust to my production NT domain and can join users to the new domain. Interent name resoultion just stops working after initial install. My root servers are listed, simple and recursive queries test OK. If I add my local ISP as a forwarder it also starts to work then fails after several hours. I am running a 2000 DNS server on my NT domain with no problems. The only difference is my NT domain is not a registered FQDN and my new 2003 doamin is. When I run an NSlookup everything points to itself (the local box) even if I perform a NSlookup on yahoo.com. I'm getting tired of rebuilding the O/S.
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Chris DentPowerShell DeveloperCommented:

I take it no error messages appear for this problem in the Event Log?

At the time of failure, what happens when you try and query an address using nslookup?

Are both Forward and Reverse Lookup zones still answering queries when external resolution fails?

Can the DNS still ping it's gateway?

Are there any restrictions for outbound traffic on Port 53 on your gateway?
rptsysadminAuthor Commented:
No errors appear
nslookup all point to the DC itself, even one that are the DC are not authorative for. suach as yahoo.com
internal name resoultion works fine
yes DNS can ping it gateway. If I put my ISP DNS's in my NIC card properties the server itself can browse the public internet.
All outbound traffic is being permitted
Chris DentPowerShell DeveloperCommented:

You already tested it using Root Hints rather than Forwarders?

At the time of failure can it still ping an address like and resolve an address for a.root-servers.net?

I take it there is no abnormal load on the server such as heavy CPU or memory usage?
Cloud Class® Course: Microsoft Azure 2017

Azure has a changed a lot since it was originally introduce by adding new services and features. Do you know everything you need to about Azure? This course will teach you about the Azure App Service, monitoring and application insights, DevOps, and Team Services.

Chris DentPowerShell DeveloperCommented:

You don't use a PIX firewall do you?
rptsysadminAuthor Commented:
I first tried it with root hints only, same problem.
then with forwards,same problem
there is no load at all, it is the first box on the new domain. The hardware id Dell power edger 1650, dual processor and gig of ram
It truly confusing because I have performedt his before for other client with 2000 AD and 2003 AD.
I'm beginning to think it just a bad install
rptsysadminAuthor Commented:
yes we do. But again all traffic from the internal network is allowed out.
Chris DentPowerShell DeveloperCommented:

There was a problem with PIX firewalls discussed in another thread.The problem was very very much like yours.


And to quote:

The problem is not with udp packets being bigger than 512, but with edns0 packet which is sent from microsoft dns server.

The command:

dnscmd /Config /EnableEDnsProbes 0

Deactivates the feature.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
rptsysadminAuthor Commented:
After going over this with my WAN administrator all of the other networks are running PIX IOS 6.3 [4] (were this is not an issue)
This network's PIX is running 6.3[1]
were upgradeing tonight.
Thaks for everyone input.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Networking

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.