• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 216
  • Last Modified:

Open DNS Server Q

We have a number of W2003 servers and host our own DNS.  I went to dnsreport.com and ran a report on it.  It indicated a FAIL message:

ERROR:  One or more of your name servers reports that is is an open DNS server.  Blah, blah, blah.

To corrent this problem, it instructed me to go into the DNS server manager and check the advanced option "Disable Recursion" so I did.

The entire Exchange outbound queue stalled saying it couldn't resolve DNS for any of the domains it was trying to send to.  I'm confused by this.  The exchange server is also a secondary DNS server for the domain.  The AD master roles and primary DNS are held by a server inside the firewall.  The server's TCP/IP properties specify the master and another secondary (not itself) for its DNS servers.

Why would this Exchange server not be able to resolve DNS queries when recursion is disabled and why is this a good idea?

Thanks!
0
tomrwilson
Asked:
tomrwilson
  • 2
  • 2
1 Solution
 
LauraEHunterMVPCommented:
Is your DNS server configured with a forwarder?  If not, after you disabled recursion you would no longer be able to resolve any DNS records other than those hosted on your local server.  DNS requires either recursion or a forwarder to be able to resolve non-local queries - a forwarder is more efficient if you have one available, as the DNS server will simply send a query to the forwarder for anything that it can't resolve locally.
0
 
tomrwilsonAuthor Commented:
Thanks for the reply.

Yes, I'm using two forwarder addresses supplied by our ISP.  All that makes sense, I'm just curious, why would DNS reports tell me to disable recursion in the first place?  Is it possible to emply recursion without the DNS server being considered "open"?
0
 
tomrwilsonAuthor Commented:
Oh crap, my forwarders are unreachable.  That explains it.  I'll be back.
0
 
LauraEHunterMVPCommented:
> "why would DNS reports tell me to disable recursion in the first place"

It's a best practice for smaller networks and/or corporate networks to streamline/minimize network traffic - your ISP's DNS servers are there for a reason.
0

Featured Post

Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now