Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

DNS Forwarder in Windows 2008

Posted on 2008-10-10
11
Medium Priority
?
5,181 Views
Last Modified: 2010-12-12
I am creating a totally new forrest, basing it off of my current domain, and I am unable to figure out how DNS is working on the current domain. I would assume that you must set up a DNS Forwarder to allow clients to resolve external names. Currently, in the working domain, there aren't any forwarders set up on any of the DC's. The NIC's all point to themselves for DNS, which I understand to be the correct way of doing things. So how is it that they are able to resolve anything on the external side?
0
Comment
Question by:bkrontz
  • 3
  • 2
  • 2
  • +3
11 Comments
 
LVL 12

Expert Comment

by:michaelgoldsmith
ID: 22689983
In Administrative Tools > DNS you can see the forwarders that DNS is using to route traffic to the internet. These are usually provided by your ISP.
0
 
LVL 17

Expert Comment

by:Andres Perales
ID: 22689992
you must check on your dns server, right click , properties, forwarders tab...
0
 
LVL 1

Author Comment

by:bkrontz
ID: 22690006
I'm sorry, maybe I didn't explain this well. On the Forwarder Tab, there isn't anything there for all of my DC's... hence my confusion.
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 71

Accepted Solution

by:
Chris Dent earned 2000 total points
ID: 22690085

> So how is it that they are able to resolve anything on the external side?

Root Hints :)

Each DNS server can resolve names without Forwarders by performing an iterative query starting with the Root DNS servers and working down.

When you configure a Forwarder you hand off that work to another DNS server and just wait for an answer.

Chris
0
 
LVL 2

Expert Comment

by:Matt1705
ID: 22690086
DNS servers don't need forwarders to work and by default there aren't any.  They are configured to query the root dns servers on the internet.  You don't need to worry about this if you don't have any defined.
0
 
LVL 12

Expert Comment

by:michaelgoldsmith
ID: 22690122
Root Hints will resolve everything.
0
 
LVL 1

Author Closing Comment

by:bkrontz
ID: 31505157
Thanks!!!!!
0
 

Expert Comment

by:cameramonkey
ID: 23602005
Michaelgoldsmith: are you sure root hints will resolve everything?

I am experiencing the same thing with my new 2008 DNS server. Its set with the root hints in the list, and recursion/forwarders are disabled. If I try to resolve anything outside the domains that the server has records for, it just returns the "bad error value" when you try to do an nslookup.

Ideas?
0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 23602058

You won't resolve anything outside of local zones if you disable Recursion... Root Hints are used when performing a recursive query on behalf of a client.

Chris
0
 

Expert Comment

by:cameramonkey
ID: 23602543
IC. Even if I set a device with that server as the primary DNS, when a client tries to resolve, it just gets an unknown domain error. it wont even try the secondary server.
0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 23602591

Correct.

NXDomain (does not exist) is considered a good and valid response from a DNS server, only a time-out waiting for a response would cause the client to use any alternate DNS server configured in TCP/IP settings.

Chris
0

Featured Post

 [eBook] Windows Nano Server

Download this FREE eBook and learn all you need to get started with Windows Nano Server, including deployment options, remote management
and troubleshooting tips and tricks

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

OfficeMate Freezes on login or does not load after login credentials are input.
Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

580 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question