Solved

Open DNS

Posted on 2006-06-25
8
238 Views
Last Modified: 2010-04-18
Hi All,

Im running Windows 2003 Server with SP2 (domain controller), and Exchange 2003 SP2(separate box) and file server that runs win 2003 SP2.

I went to www.dnsreport.com to do a test on my domain. In Open DNS row it says thas i have an open DNS server. I did what the recommended:

Open DNS.
In the console tree, right-click the applicable DNS server, then click Properties.
Click the Advanced tab.
In Server options, select the Disable recursion check box, and then click OK.

Once i applied the above changes o could not browse the internet.


Any ideas ?


Thanks
Chris
0
Comment
Question by:aucklandnz
  • 3
  • 2
8 Comments
 
LVL 51

Expert Comment

by:Netman66
ID: 16980502
In DNS, on the properties of the server, make sure you are only servicing (listening) on the internal NIC.
Also, put the ISP DNS address on the Forwarder tab.

0
 
LVL 3

Author Comment

by:aucklandnz
ID: 16980594
i have done it and i still cant browse the net

thanks
0
 
LVL 51

Expert Comment

by:Netman66
ID: 16980675
Make sure every NIC inside the LAN only points to your DNS - including the server.

If there is a root zone "." then delete it and restart DNS (or the server).

0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 3

Author Comment

by:aucklandnz
ID: 16980716
There is no "." root zone. and when i run ipconfig /all on clients it says that clients point to my domain controller for dns

thanks
0
 
LVL 3

Author Comment

by:aucklandnz
ID: 16981270
any other suggestions ?
0
 
LVL 70

Accepted Solution

by:
Chris Dent earned 125 total points
ID: 16982269

Turn recursion back on and don't allow inbound traffic (from the Internet) on Port 53 (UDP) to your DNS Server.

If you disable Recursion for the entire server you will not be able to use Forwarders and you will not be able to resolve external names as you have taken away all it's means to do so.

An Open DNS server mans that others can use it for queries - it's not good practice to use your AD domains DNS Server as a public one - in many cases because Dynamic Updates will play merry hell with a public domain if left switched on.

Chris
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
Learn about cloud computing and its benefits for small business owners.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This tutorial gives a high-level tour of the interface of Marketo (a marketing automation tool to help businesses track and engage prospective customers and drive them to purchase). You will see the main areas including Marketing Activities, Design …

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question