• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 5184
  • Last Modified:

DNS Forwarder in Windows 2008

I am creating a totally new forrest, basing it off of my current domain, and I am unable to figure out how DNS is working on the current domain. I would assume that you must set up a DNS Forwarder to allow clients to resolve external names. Currently, in the working domain, there aren't any forwarders set up on any of the DC's. The NIC's all point to themselves for DNS, which I understand to be the correct way of doing things. So how is it that they are able to resolve anything on the external side?
0
bkrontz
Asked:
bkrontz
  • 3
  • 2
  • 2
  • +3
1 Solution
 
michaelgoldsmithCommented:
In Administrative Tools > DNS you can see the forwarders that DNS is using to route traffic to the internet. These are usually provided by your ISP.
0
 
Andres PeralesCommented:
you must check on your dns server, right click , properties, forwarders tab...
0
 
bkrontzAuthor Commented:
I'm sorry, maybe I didn't explain this well. On the Forwarder Tab, there isn't anything there for all of my DC's... hence my confusion.
0
Improved Protection from Phishing Attacks

WatchGuard DNSWatch reduces malware infections by detecting and blocking malicious DNS requests, improving your ability to protect employees from phishing attacks. Learn more about our newest service included in Total Security Suite today!

 
Chris DentPowerShell DeveloperCommented:

> So how is it that they are able to resolve anything on the external side?

Root Hints :)

Each DNS server can resolve names without Forwarders by performing an iterative query starting with the Root DNS servers and working down.

When you configure a Forwarder you hand off that work to another DNS server and just wait for an answer.

Chris
0
 
Matt1705Commented:
DNS servers don't need forwarders to work and by default there aren't any.  They are configured to query the root dns servers on the internet.  You don't need to worry about this if you don't have any defined.
0
 
michaelgoldsmithCommented:
Root Hints will resolve everything.
0
 
bkrontzAuthor Commented:
Thanks!!!!!
0
 
cameramonkeyCommented:
Michaelgoldsmith: are you sure root hints will resolve everything?

I am experiencing the same thing with my new 2008 DNS server. Its set with the root hints in the list, and recursion/forwarders are disabled. If I try to resolve anything outside the domains that the server has records for, it just returns the "bad error value" when you try to do an nslookup.

Ideas?
0
 
Chris DentPowerShell DeveloperCommented:

You won't resolve anything outside of local zones if you disable Recursion... Root Hints are used when performing a recursive query on behalf of a client.

Chris
0
 
cameramonkeyCommented:
IC. Even if I set a device with that server as the primary DNS, when a client tries to resolve, it just gets an unknown domain error. it wont even try the secondary server.
0
 
Chris DentPowerShell DeveloperCommented:

Correct.

NXDomain (does not exist) is considered a good and valid response from a DNS server, only a time-out waiting for a response would cause the client to use any alternate DNS server configured in TCP/IP settings.

Chris
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Cloud Class® Course: C++ 11 Fundamentals

This course will introduce you to C++ 11 and teach you about syntax fundamentals.

  • 3
  • 2
  • 2
  • +3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now