Solved

Weird DNS problem

Posted on 2007-03-20
13
622 Views
Last Modified: 2012-06-27
Hi Experts,

We have a windows 2003 DNS Server (Not AD integrated)... non-secure update enabled. All the client systems pointing to that DNS using DHCP options.

Now the problem is the clients can ping a system using FQDN most of the times and sometimes they can't.
When it stops working ipconfig /flushdns don't make any differrence.
After doing a repair in network connection it starts working.

Please suggest what could be the possible cause of this problem?

Many Thanks
0
Comment
Question by:shiplu44
  • 7
  • 6
13 Comments
 
LVL 18

Expert Comment

by:chicagoan
Comment Utility
When is stops working, have you checked if there is basic connectivity to the DNS server?
Can you ping it? What happens when you query DNS on a client via NSLOOKUP?
What happens when you query the name server by running NSLOOUP on the name server host?
Anything in the event logs?
0
 

Author Comment

by:shiplu44
Comment Utility
Yes I can still ping the DNS server while it stops working.

I didn't try NSLOOKUP ... I wilol try this when the problem happens again and will come back.
Also I will check the event log
0
 

Author Comment

by:shiplu44
Comment Utility
When I try to ping - Fails
=========================
Ping request could not find host host.domain.local. Please check the name and try again.

NSLOOKUP - Success
=========================
C:\>nslookup
Default Server:  dns.domain.local
Address:  10.10.10.10
> host.domain.local

Server:  dns.domain.local
Address:  10.14.98.21

Name:    host.domain.local
Address:  10.10.10.10

PING DNS IP - successful
=========================
C:\ping 10.10.10.10

Pinging 10.10.10.10 with 32 bytes of data:

Reply from 10.10.10.10: bytes=32 time<1ms TTL=125
Reply from 10.10.10.10: bytes=32 time<1ms TTL=125
Reply from 10.10.10.10: bytes=32 time<1ms TTL=125
Reply from 10.10.10.10: bytes=32 time<1ms TTL=125

Ping statistics for 10.10.10.10:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
0
 
LVL 18

Expert Comment

by:chicagoan
Comment Utility
this is from the dhcp client?

nslookup succeeds in resoving the address but pinging the host by fqdn fails where pinging by ip succeeds?

can you post the output of ipconfig /all and the hosts on the dhcp client?
0
 

Author Comment

by:shiplu44
Comment Utility
Yes this is from the client

nslookup succeeds in resoving the address but pinging the host by fqdn fails where pinging by ip succeeds - Thats correct !


C:\>ipconfig /all

Windows IP Configuration

        Host Name . . . . . . . . . . . . : host1
        Primary Dns Suffix  . . . . . . . : domain-a.local
        Node Type . . . . . . . . . . . . : Hybrid
        IP Routing Enabled. . . . . . . . : No
        WINS Proxy Enabled. . . . . . . . : No
        DNS Suffix Search List. . . . . . : domain-a.local
                                            domain-b.local
                                            domain-c.local
                                            domain-d.local

Ethernet adapter Local Area Connection:

        Connection-specific DNS Suffix  . : domain-a.local
        Description . . . . . . . . . . . : Broadcom NetXtreme 57xx Gigabit Controller
        Physical Address. . . . . . . . . : ##-##-##-##-##-##
        Dhcp Enabled. . . . . . . . . . . : Yes
        Autoconfiguration Enabled . . . . : Yes
        IP Address. . . . . . . . . . . . : 10.10.10.12
        Subnet Mask . . . . . . . . . . . : 255.255.248.0
        Default Gateway . . . . . . . . . : 10.12.24.1
        DHCP Server . . . . . . . . . . . : 11.11.11.11
        DNS Servers . . . . . . . . . . . : 10.10.10.10
                                            13.13.13.13
        Primary WINS Server . . . . . . . : 11.11.11.11
        Secondary WINS Server . . . . . . : 12.12.12.12
        Lease Obtained. . . . . . . . . . : 21 March 2007 3:03:20 PM
        Lease Expires . . . . . . . . . . : 21 March 2007 7:03:20 PM

C:\>
0
 
LVL 18

Expert Comment

by:chicagoan
Comment Utility
Are these other addresses valid?
DNS Servers . . . . . . . . . . . : 10.10.10.10
                                            13.13.13.13
Primary WINS Server . . . . . . . : 11.11.11.11
Secondary WINS Server . . . . . . : 12.12.12.12
Even with a rather large subnet of  255.255.248.0 both wins servers would be on different networks.
If you don't have these servers, I'd remove them from the DHCP config. You don't HAVE to have a secondary DNS or any wins servers.
The DHCP server seems on a different network as well - which can be done with a helper address - but are these addresses greeked or is this what you're serving up from 11.11.11.11?

Have you checked basic stuff like speed/duplex mismatches, extraeneous host file entries, etc?
How  about the event logs?
0
What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

 

Author Comment

by:shiplu44
Comment Utility
Thanks I will try with one DNS IP. Do you think WINS is causing this issue?
0
 
LVL 18

Expert Comment

by:chicagoan
Comment Utility
I don't think WINS is the issue but if your clients have unavailable resources specified your troubleshooting will be much more complex.

>Have you checked basic stuff like speed/duplex mismatches, extraeneous host file entries, etc?
>How  about the event logs?
0
 

Author Comment

by:shiplu44
Comment Utility
Where do I check the speed? This is a complex large network with lots of CISCO 4500 routers and lotf os VLANS.

Sorry please explain me what is extraeneous host file entries?

Event logs in DNS Server or client?
0
 
LVL 18

Expert Comment

by:chicagoan
Comment Utility
You (on the network admin) would have to look on the switch and the host to check what speed / duplex had been negotiated. If in doubt you can set both explicitly.

The hosts file is in <system root>\system32\etc on the client and can contain ip/name entries that supercede DNS resolution. There could also be an LMHOSTS file that supercedes WINS resolution.

Check both event logs.
0
 

Author Comment

by:shiplu44
Comment Utility
Speed is full duplex autonegotiated ... in client sire 100 mbps and in DNS server 1Gbps

There is no host or LMhost entries

No error or warning in server event log but Lots of dhcp warning messages in client side

Event Type:      Warning
Event Source:      Dhcp
Event Category:      None
Event ID:      1003
Date:            22/03/2007
Time:            9:33:58 AM
User:            N/A
Computer:      C4D3C2J
Description:
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 0013728F34C5.  The following error occurred:
The semaphore timeout period has expired. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 79 00 00 00               y...    
0
 
LVL 18

Accepted Solution

by:
chicagoan earned 500 total points
Comment Utility
if your dhcp lease is not renewing you're going to see some erratic behavior - maybe solve that first and then see how things are behaving.
0
 

Author Comment

by:shiplu44
Comment Utility
Ok Thanks I will try this too. I will also try with static IP
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

Suggested Solutions

If you have a multi-homed DNS setup in windows, you can have issues with connectivity to the server that hosts the DNS services (or even member servers of your domain if this same DNS server is a DC). This is because windows registers all of its IPs…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now