[Last Call] Learn how to a build a cloud-first strategyRegister Now


TCP/IP stack bad on SBS 2003 box?

Posted on 2007-08-10
Medium Priority
Last Modified: 2010-05-18
I noticed the other day that our remote offices were having trouble pinging our SBS box at our primary location.  Initially, the primary offices were able to successfully ping SBS box but as of this morning, that is no longer the case either by the ip or the fqdn.  

I can still access our SBS server from the START, Run command and by terminal services.  I can also ping all the other servers and clients FROM the SBS box but they cannot recognize that box is even on the network.  Ive tried disabling the AV firewall on our SBS server, restarting the dns service and eventually the server itself.  Ive also confirmed all the ptr and a records in addition to the NIC configuration.   Ive run dcdiag and netdiag /fix with no luck.  I also ran dcdiag /v /test:dns.   This last test reveals a number of forwarding errors but comparing the configuration with one of our other servers didnt show any differences.  

Per this article, http://support.microsoft.com/kb/317518/, I suspect that I may need to reset the tcp stack on the SBS box but as this is obviously the primary DC, Im hesitant to do so.  Any other ideas on what might be causing the behavior I described?
For further information, we are running 7 servers, all server 2003 except for the one SBS 2003 box.  We have two servers acting as secondary dc's and the SBS box as the primary.  

The only hint towards a possible cause, is an error I show in the dcdiag /test:dns call following after every FQDN listed in the Root Hints tab of the DNS server tab :  

      DNS server: (k.root-servers.net.)
      1 test failure on this DNS server
      This is not a valid DNS server. PTR record query for the failed on the DNS server  [Error details: 9003 (Type: Win32  Description: DNS name does not exist.)]

The odd thing is that these are the same listings on our other servers which are working just fine.  

Question by:jenieh
LVL 70

Accepted Solution

KCTS earned 750 total points
ID: 19674479
Make sure that all of your machines point to one of your own internal DNS server - The SBS box as the preferred DNS server and if you have other internal DNS servers you can put these as alternate DNS servers - otherwise ithe alternate should be blank.

I would always use a forwarder rather than relying on root hints - pointing DNS forwarders at your ISPs DNS servers is more efficient.
LVL 44

Assisted Solution

scrathcyboy earned 750 total points
ID: 19678084
simply rebuild the TCP/IP stack on the system, it is only a few minutes work, see here --


Author Comment

ID: 19686282
Thanks to you both for the suggestions.  KCTS, I already checked the DNS settings on all the servers and reconfirmed that wasn't the problem.  I also have both forwarders and root hints set.  Scratchyboy, rebuilding the stack on a workstation isn't the solution and because this is the primary DNS I'm reticent to rebuild the stack on the SBS box.  

For now I traced part of the issue back to the ISA server that we recently disabled in order to test a web filter appliance that we are evaluating.  

Everytime I tried to review the firewall settings on the SBS box, I kept getting the error message: "Windows Firewall cannot run because another program or service is running that might use the network address translation component (Ipnat.sys)."

I went into Device Manager, chose Show Hidden Devices, and open "Non-Plug and Play Drivers". I stopped the "IP Network Address Translator" and the ISA Server Network Address Translation Driver.  Next, I cleared the cache on the DNS server and restarted it and am now able to ping the server from workstations throughout the network.  Finally, I reran dcdiag /fix and then dcdiag /test:dns /v.  
Unfortunately I'm still getting the fowarding error in the test:dns results.  


Author Comment

ID: 20227651
Neither response really worked for me but I split the points due to the fact that they did help point me in the right direction.

Thanks again to both of you for your help!

Expert Comment

ID: 24574735
Hello Jenieh-

I am having a similar problem with my SBS. How did you end up fixing this issue?


Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Make the most of your online learning experience.
This article will show you step-by-step instructions to build your own NTP CentOS server.  The network diagram shows the best practice to setup the NTP server farm for redundancy.  This article also serves as your NTP server documentation.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question