?
Solved

Open DNS

Posted on 2006-06-25
8
Medium Priority
?
242 Views
Last Modified: 2010-04-18
Hi All,

Im running Windows 2003 Server with SP2 (domain controller), and Exchange 2003 SP2(separate box) and file server that runs win 2003 SP2.

I went to www.dnsreport.com to do a test on my domain. In Open DNS row it says thas i have an open DNS server. I did what the recommended:

Open DNS.
In the console tree, right-click the applicable DNS server, then click Properties.
Click the Advanced tab.
In Server options, select the Disable recursion check box, and then click OK.

Once i applied the above changes o could not browse the internet.


Any ideas ?


Thanks
Chris
0
Comment
Question by:aucklandnz
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
8 Comments
 
LVL 51

Expert Comment

by:Netman66
ID: 16980502
In DNS, on the properties of the server, make sure you are only servicing (listening) on the internal NIC.
Also, put the ISP DNS address on the Forwarder tab.

0
 
LVL 3

Author Comment

by:aucklandnz
ID: 16980594
i have done it and i still cant browse the net

thanks
0
 
LVL 51

Expert Comment

by:Netman66
ID: 16980675
Make sure every NIC inside the LAN only points to your DNS - including the server.

If there is a root zone "." then delete it and restart DNS (or the server).

0
Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

 
LVL 3

Author Comment

by:aucklandnz
ID: 16980716
There is no "." root zone. and when i run ipconfig /all on clients it says that clients point to my domain controller for dns

thanks
0
 
LVL 3

Author Comment

by:aucklandnz
ID: 16981270
any other suggestions ?
0
 
LVL 71

Accepted Solution

by:
Chris Dent earned 500 total points
ID: 16982269

Turn recursion back on and don't allow inbound traffic (from the Internet) on Port 53 (UDP) to your DNS Server.

If you disable Recursion for the entire server you will not be able to use Forwarders and you will not be able to resolve external names as you have taken away all it's means to do so.

An Open DNS server mans that others can use it for queries - it's not good practice to use your AD domains DNS Server as a public one - in many cases because Dynamic Updates will play merry hell with a public domain if left switched on.

Chris
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

So you have two Windows Servers and you have a directory/folder/files on one that you'd like to mirror to the other?  You don't really want to deal with DFS or a 3rd party solution like Doubletake. You can use Robocopy from the Windows Server 200…
by Batuhan Cetin In this article I will be guiding through the process of removing a failed DC metadata from Active Directory (hereafter, AD) using the ntdsutil tool in a Windows Server 2003 environment. These steps are not necessary in a Win…
This is my first video review of Microsoft Bookings, I will be doing a part two with a bit more information, but wanted to get this out to you folks.
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question