Tech or Treat! Write an article about your scariest tech disaster to win gadgets!Learn more

x
?
Solved

Windows 2008 DNS server forwarding issue ???

Posted on 2009-04-02
15
Medium Priority
?
1,205 Views
Last Modified: 2013-12-29
Hi Experts,

I'm running SBS 2008 domain and I use SBS inbuilt DNS server to forward my external requests. I have added my ISP's DNS server in to the "Forward" list. Both DNS server are identifying and this was working fine from past couple of months. But from yesterday users are getting time outs (DNS issues) when they are browsing.

I have added ISP DNS to client's machine then and then situation will be ok.

how do I troubleshoot this ??? Please advices ??

Thanks a lot !
0
Comment
Question by:Shakthi777
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 4
  • 3
  • +1
15 Comments
 
LVL 8

Expert Comment

by:halejr1
ID: 24047423
First what are the DNS settings on your interface of the server?

I would check using NSLOOKUP and pointing directly to the servers provided by your ISP.  Also make sure that port 53 is open for DNS traffic.  It sounds like your ISP may be having the issues, and you could allow forward lookup to standard recommended dns hosts if you set your servers DNS server to itself.

It doesn't sound like a browser issue if you are having the same problem via multiple browsers.  Just do some basic IP troubleshooting, i.e. ping , tracert, etc. etc.

Good luck
Let me know what you find.
0
 

Author Comment

by:Shakthi777
ID: 24047425
The timeouts still happening with the ISP DNS server in the client machines. But it's resolved temporarily (for about 15 minutes) when I do ipconfig /renew

Please advise !!!!  
0
 

Author Comment

by:Shakthi777
ID: 24047447
ok thanks halejr1: I'll try with your command line tools and post you result ! BTW the SBS server is running on VMware ESXi
:::Server Interface:::
 
Ethernet adapter Local Area Connection:
 
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network Connection
   Physical Address. . . . . . . . . : 00-0C-29-BB-58-97
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::4c51:b8fd:e0ea:c2d5%10(Preferred)
   Link-local IPv6 Address . . . . . : fe80::d550:5f5a:24f6:cae9%10(Preferred)
   IPv4 Address. . . . . . . . . . . : 192.168.1.1(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.1.254
   DNS Servers . . . . . . . . . . . : fe80::d550:5f5a:24f6:cae9%10
                                       192.168.1.1
   NetBIOS over Tcpip. . . . . . . . : Enabled

Open in new window

0
Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

 
LVL 8

Expert Comment

by:halejr1
ID: 24047482
ipconfig /renew -- on local system?  shouldn't matter, if you've got a lease and the parameters don't change, renew won't do anything for you on  a client machine.  

your IP address, Default Gateway and Subnet mask probably don't change

Also, do an IPconfig / all from you local  "problem" PC's.  If you have static DNS entries, this too could be a problem.
0
 

Author Comment

by:Shakthi777
ID: 24047525
ipconfig /renew -- on local system?
YES
shouldn't matter, if you've got a lease and the parameters don't change, renew won't do anything for you on  a client machine.
BUT IT'S STARTING BROWSING !

Also, do an IPconfig / all from you local  "problem" PC's.  If you have static DNS entries, this too could be a problem.
I DID, ALL ARE CORRECT !
0
 
LVL 21

Accepted Solution

by:
suppsaws earned 600 total points
ID: 24047565
Hello Shakthi777,

the clients should never have an isp dns server in their tcp/ip configs.
The ONLY place you -could- configure an external dns forwarder is on the SBS server itself.
can you give an ipconfig /all of the client?
how were the clients joined to the domain? via http://connect?
http://blogs.technet.com/sbs/archive/2009/01/29/cannot-resolve-names-in-certain-top-level-domains-like-co-uk.aspx
http://msmvps.com/blogs/bradley/archive/2008/12/14/dns-root-hints-and-forwarders.aspx


Regards,

suppsaws
0
 
LVL 8

Assisted Solution

by:halejr1
halejr1 earned 300 total points
ID: 24047612
Shakthi,

when you say it's starting browsing are you referring to the fact that browsing works after you do an IPconfig?  I think that is an anomoly or coincidence.  Maybe not.  The DNS settings of hte client machines is what I am interested in.
Do an IPCONFIG /ALL and post here.

Thanks.  

Like I mentioned inthe first post, if the DNS server is pointing to itself, it will be doing forward lookup based on the root hints provided the server.  this is all standard and automatic -- by design stuff.

0
 
LVL 15

Assisted Solution

by:Dave_AND
Dave_AND earned 600 total points
ID: 24047806
Open DNS, go to the server properties, and then forwarders. Remove the ISP DNS Servers, and replace with 208.67.222.222 and 208.67.220.220 (these are opendns servers far better than any ISP Servers) once thats done, on the SBS server open DHCP,  open the server> IPv4>Scope>Scope Options and make sure the DNS servers is set to your SBS Server's IP.

Once thats done, install the telnet client on the server, start>run>cmd>pkgmgr /iu:"TelnetClient"

While that installs, disable IP6 on the Network card, just open the properties of the Network card, and un tick the IP6, and hit ok. Telnet should now be installed, so go back to your cmd line, and type nslookup and hit enter. You should get something like this:

C:\Users\admin>nslookup
Default Server:  server.domain.local
Address:  192.168.0.1

>

now type google.co.uk and make sure you get a responce. Reboot your client PCs and test. Let me know if it dosnt work.
0
 

Author Comment

by:Shakthi777
ID: 24048253
ok Dave I have did exactly what you have explained.  But when I'm unchecked IPv6 my out look clients are not connected to the SBS server, then i have enabled it again and not it's connecting. and so far I didn't get DNS issues.

And what about the root hints ?? Do I need to "Copy from the server" ???
0
 

Author Comment

by:Shakthi777
ID: 24048400
Dave; it's happened again, below is the nslookup details; actually my DNS server IP is not 192.168.1.1 !!!!  

I think some serious thing is going on, something is changing my client's DNS entry,  and the thing is it will again get back to normal when I do ipconfig /renew

Please advise !!!!
C:\Users\hsn>nslookup
DNS request timed out.
    timeout was 2 seconds.
Default Server:  UnKnown
Address:  192.168.1.1
 
> www.google.com
Server:  UnKnown
Address:  192.168.1.1
 
DNS request timed out.
    timeout was 2 seconds.
DNS request timed out.
    timeout was 2 seconds.
DNS request timed out.
    timeout was 2 seconds.
DNS request timed out.
    timeout was 2 seconds.
*** Request to UnKnown timed-out
>

Open in new window

0
 
LVL 15

Assisted Solution

by:Dave_AND
Dave_AND earned 600 total points
ID: 24055242
Lets get back to basics.. Did you run the connect to the internet wizard? That fixes a lot of your problems..

Now, what SHOULD your DNS Server be? It looks like you have another DHCP Server on the network or somthing.. try this to test.. disable the DHCP server service, and do an IPconfig /release and /renew and see if you get an I.P.

You say it shouldnt be 192.168.1.1, but earlyer, you said your server's I.P is 192.168.1.1.. these should be the same..

Can you do an Ipconfig /all for before its wrong, and after its wrong, so i can see the differances?

Thanks
0
 
LVL 21

Assisted Solution

by:suppsaws
suppsaws earned 600 total points
ID: 24057039
as dave said, did you ran the WIZARDS?
here you have an overview of what wizards you should run:
http://sbs.editme.com/wizard2008
make sure you run the SBS 2008 BPA http://blogs.technet.com/sbs/archive/2008/10/16/sbs-2008-bpa-is-live.aspx
and the Fix my network wizard.
Just make sure the SBS server is the ONLY dhcp server, and the clients are on dhcp, and point to the SBS server ad their dns server.
Do NOT disable Ipv6 on the sbs: http://blogs.technet.com/sbs/archive/2008/10/24/issues-after-disabling-ipv6-on-your-nic-on-sbs-2008.aspx
0
 
LVL 21

Expert Comment

by:suppsaws
ID: 24057041
I also didn't see an ipconfg /all of the server + one client, and also not how the clients were joined to the domain?
0
 

Author Closing Comment

by:Shakthi777
ID: 31565672
Thanks for all you valuable comments and I have learned a lot ! I have found one of my network users running test DHCP server.

Again thanks for your great support !
0
 
LVL 8

Expert Comment

by:halejr1
ID: 24057085
Shakti --

what version of antivirus are you running on your server?  Just a thought with a similar problem that I had in a previous life.

Need that IPCONFIG /ALL from the server and one or more of your clients.

Thanks.


0

Featured Post

Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Windows 10 Creator Update has just been released and I have it working very well on my laptop. Read below for issues, fixes and ideas.
In the absence of a fully-fledged GPO Management product like AGPM, the script in this article will provide you with a simple way to watch the domain (or a select OU) for GPOs changes and automatically take backups when policies are added, removed o…
The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…
In this video, viewers will be given step by step instructions on adjusting mouse, pointer and cursor visibility in Microsoft Windows 10. The video seeks to educate those who are struggling with the new Windows 10 Graphical User Interface. Change Cu…

647 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question