Name resolution on domain is not working correctly

Posted on 2009-04-02
Medium Priority
Last Modified: 2012-05-06
My company has one main office and several branch offices.
In the main office we have the DC, a Windows 2003 server, which is also the primary DNS server for the PC's in that area. In one of the branch offices we have a Windows 2003 Server which acts as a DNS slave. This is the primary DNS server for the PC's in that area. The DNS slave used to be a Linux machine with BIND DNS daemon, but was replaced a few months back with the Windows machine.
What happened after the replacement was that PC's both at the main office and at the branch office have problems resolving internal addresses. It looks as if WINS is still working because we can ping COMPUTERNAME, but not COMPUTERNAME.some.domain. The only solution is to run the command 'net stop dnscache' on the clients. Then it works. Afterwards we can turn the dnscache on again and it will still work, but we always have to turn it off after booting the PC's.
Does anyone have an idea on what is going on?
Question by:Ole_Brun

Expert Comment

ID: 24047376
have you tried to use as a primary DNS on the branch PCs the DNS from the main office?

Author Comment

ID: 24048262
Well, users not using the DNS server from branch office are also having the same problem...
But I have changed now on one of the machines. Will report back my findings.

Expert Comment

ID: 24048267
Couple of things to get clear picture...

1. Is the NSLOOKUP resolves FQDN(COMPUTERNAME.some.domain) and Hostname (COMPUTERNAME) ??

2. Do you have DNS suffix inplace?

- Cheers!
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.


Expert Comment

ID: 24049770
Please help me understand your environment.  Is the zone for the domain Active Direcory Intigrated.  If so the DNS server in the branch office is the same as a primary.  The reason I ask this is I wanted to know where your clients are registering their records.  If it is AD intergrated then the clients are registering the records locally if not thy have to go across the WAN to register their records.  Then they have to be transfered to the local DNS server.

Author Comment

ID: 24058345
To answer nskurs first:
1. Before doing a 'net stop dnscache' nslookup will not resolve FQDN, but Hostname is ok.
2. Yes, suffic is inplace

Not sure what you mwan by integerated, but the server in the branch office is not setup to be a DC. Only the DNS service has been added. It is merely a slave zone, and no computer is registering with this server. the only reason for having it is to speed up lookups for local machines.

Btw, I tried changing primary dns on one machine to be the DC, but the problem remains.
That makes me believe that the backup dns server might not be the problem after all.
Or what do you think?

Expert Comment

ID: 24059250
What do you mean by the term slave.  The DNS server in the Branch office is either a secondary server, ie it has a read only copy of the zone in the main office, if so please verify the zone is actually a secondary zone. Or, it is a caching server, ie: it has no zone and forwards all requests to the main office DNS server and caches the response.

When running nslookup verify which DNS server nslookup is using to resolve your query.  Please confirm if it is your local DNS Server or your Primary

Author Comment

ID: 24059940
I'm used to BIND dns server... Slave means secondary server.

I just did a nslookup mail.domain.com, and it resolved just fine to the internal ip address!
Then I did a ping mail.domain.com which resolved in the EXTERNAL address for the domain.

You see out dns servers resolve internal addresses (192.168.x.x). However the ISP is hosting the dns for our external addresses. So internally mail.domain.com resolves to 192.168.x.x whereas externally it is 213.225.x.x.
So when doing a nslookup the internal address is shown, whereas ping gives me the external one...

Accepted Solution

MSE-JNegus earned 1000 total points
ID: 24060072
This could be your problem.  Your clients need to reslove the internal addresses.  Have you configured your clients with a preferred and alternate DNS servers.  If so is one of the alternates your ISPs DNS server.  This is a no no.  You should have your preferred as your local DNS server and your alternate as your DNS server in the main office.

Expert Comment

ID: 24060101
You should also check to see if the external record exists in the zone.

Author Closing Comment

ID: 31565670
Yes, one external DNS server was actually configured in the DHCP server. Removed that, and now everything is back to normal :) I guess that mistake was done when we upgraded the firewalls a while back.
Thanks for your help!

Featured Post

Easily Design & Build Your Next Website

Squarespace’s all-in-one platform gives you everything you need to express yourself creatively online, whether it is with a domain, website, or online store. Get started with your free trial today, and when ready, take 10% off your first purchase with offer code 'EXPERTS'.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

This article will help to fix the below errors for MS Exchange Server 2016 I. Certificate error "name on the security certificate is invalid or does not match the name of the site" II. Out of Office not working III. Make Internal URLs and Externa…
Scripts are great for performing batch jobs against users, however sometimes the GUI is all you need.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

600 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question