• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 564
  • Last Modified:

DNS resolution very slow

Hi

Users on my lan are complaining that there when they click onto ie for the first time it takes a very long time for the homepage to appear. We have a DSL connection to the internet and a vigor router connected to a sonicwall. It seems as if takes time to recognise the inital web site for example at the bottom right of ie it says web site found but then takes a good few to display. We run our own windows 2003 AD with internal DNS with forwarders pointing to our DSL provider DNS servers.

What could be wrong or how would i go about finding out what is making the internet for users so slow.

ta
0
kingcastle
Asked:
kingcastle
  • 10
  • 4
  • 3
  • +3
1 Solution
 
mredfelixCommented:
troubleshooting

Are you using a proxy?
trying pluging a PC/laptop into the back off the sonicwall and see if it takes a long time.
Change to a different isp dns servers.
0
 
kingcastleAuthor Commented:
no proxy invloved here at all.

i tried actually plugging my laptop directly into the vigor rotuer and it was fast enough but then again i would expect that i was the only one plugged into that device.

cheers
0
 
mredfelixCommented:
how fast is it on the windows server?

have you cleared the dns cach?
0
Worried about phishing attacks?

90% of attacks start with a phish. It’s critical that IT admins and MSSPs have the right security in place to protect their end users from these phishing attacks. Check out our latest feature brief for tips and tricks to keep your employees off a hackers line!

 
kingcastleAuthor Commented:
windows server is much the same as lan and yes cleared the cache
0
 
Brian PiercePhotographerCommented:
If your DSL router supports DNS proxy - most do, then you may be better off pointing the forwarder at the router, that way, if the ISP updates the DNS servers, the proxy will update automatically and you will not have to re-configure the forwarder
0
 
kingcastleAuthor Commented:
would implementing a proxy server on the lanb help this situation?
0
 
kingcastleAuthor Commented:
kc how would i do that then, sound like a good plan becuase every thime the isp changes the dns server i have to call them up.

ta
0
 
mredfelixCommented:
are you lan pc's pointed to the gateway or the server?

If it is the gateway does it still take  along time when you are plugged into the first switch/hub the router is plugged in.

with the router set your nics dns to point to the router and imagine there is a tick box on the web console to turn it on.
0
 
kingcastleAuthor Commented:
all gateways are pointed to the firewall
0
 
BertlingCommented:
if you log in to your sonicwall admin can you see how many conections are present? this is under the status section where you can see the serial and model etc.

if it is over 16000 then this could be your problem, as it will wait for a session to end before the next node is can access.

i have had this issue when one of our nodes had a virus on it. creating 1000s of sessions. it was being used to ddos or something allong those lines.
0
 
kingcastleAuthor Commented:
hi all yeah the thing is that my dsl router is in front of my sonicwall in other words its on a differnt subnet so say my dsl router is on 192.168.10.100 but my sonicwall which is my lan default gateway is on 172.16.1.0 so how would i be able the point my dns forwarders from my AD DNS server on 172.16.1.0 to the router?cheers
0
 
Brian PiercePhotographerCommented:
You make sure all the machines on the domain point to the internal DNS server ONLY and then set up a forwarder as detailed at http://www.petri.co.il/configure_dns_forwarding.htm
0
 
kingcastleAuthor Commented:
hi kcts, yip i know that bit ok but at the mo my forwarders are pointing to my isp and i was interested when you said you could point them to your router and your router would handle it when the isp changed these dns settings, but on my last post i mentioned that all my lan clients point to the firewall and not the router so i was wondering how i get your way to work in that situation.

ta
0
 
Press2EscSystems IntegratorCommented:
I am wondering if you are not having a line issue...  By default, when you repeatedly visit the same website (eg., homepage) your browsers work off of local cache.  

Have you ran a speed test recently?
Have you checked for packet loss recently (e.g., ping -t myhomepage.com)?
Have you added any new hardware or software?  Any network config changes?

P2E
0
 
BertlingCommented:
can you please advise the number of sessions on your firewall, as requested to rule this out
0
 
kingcastleAuthor Commented:
no its defo not the number of connections, and its not a line problem either i dont think.

that dns automatically changing as and when the isp cahnges their dns server sounds good tho but i cant see where to do it as explained earlier
0
 
ChiefITCommented:
DCdiag /fix:DNS
0
 
ChiefITCommented:
Or you could try to flush the DNS cache of the server and remove all HOST file records except the 127 loopback address. The server will go to its DNS cache and HOST records before HOST A records in the forward lookup zone, then to an outside server.

To flush the DNS cach: type IPconfig /flushdns at the command prompt
To edit the HOST file, use a text editor (like wordpad), and delete all records except the loopback address. The host file is found in C:\Windows\system32\drivers\ect\Host
0
 
kingcastleAuthor Commented:
im going give chiefit the points here as this turned out to be a dns issue. the first dns forwarder we had on our internal dns server was one our isp had taken offline once we moved to the proper dns forwarder from the isp it all worked well again.

so thanks all
0
 
Brian PiercePhotographerCommented:
My comment was :!

" If your DSL router supports DNS proxy - most do, then you may be better off pointing the forwarder at the router, that way, if the ISP updates the DNS servers, the proxy will update automatically and you will not have to re-configure the forwarder "
0
 
kingcastleAuthor Commented:
oh good point, but my point was how would i do that, if my gateway on the lan was actually my firewall and not the router.

anyway how can i re assign some of these points
0
 
Brian PiercePhotographerCommented:
Its up to you - but if you want to, select "Request attention" and ask for the question to be re-opened.
0
 
ChiefITCommented:
Well done KCTS: (ID: 22603644)

That's a good idea using a proxy to allow the outside DNS to dynamically update any changes. I like that idea.




0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Worried about phishing attacks?

90% of attacks start with a phish. It’s critical that IT admins and MSSPs have the right security in place to protect their end users from these phishing attacks. Check out our latest feature brief for tips and tricks to keep your employees off a hackers line!

  • 10
  • 4
  • 3
  • +3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now