Solved

DNS Forwarders not working for out other Domain

Posted on 2009-04-08
6
483 Views
Last Modified: 2012-05-06
I have a problems with Conditional Forwarding in Windows 2003 DNS.

First the Background.
We have a active Directory Domain called something.com which DNS in integrated in AD.
This Domains has 2 DNS servers, which are also ours DC and GC
The We have an Unix Domain Called something.net but also with have an Internet domain called something.net too

The Unix Domain has its own DNS server and here where the problem begins.

The Unix Domain are only use by internal application use by the servers.
The NT Domain its use for End Users.

So my problem is that We had set up a condition that when you try to do a query for the domain something.net should first go to the Internal Domain something.net and if is not found there go to the DNS of our Internet Domain.

But for some reason this isn't working .

I try an NSLOOKUP to ftp.something.net should found it on the Internet domain but I just received this error
------------
C:\>nslookup
Default Server:  DC1.something.com
Address:  172.22.xx.xxx

ftp.something.net
Server:  DC1.something.com
Address:  172.22.xx.xxx

*** dc1.something.com can't find ftp.something.net: Non-existent domain
-------------------------------------------------------

Its like isn't even looking in the right place.

-------------------------------------------------------------------------------
I ran a DCdiag test:dns and all went just fine, no even a single failure
------------------------------------------------------
We have our DNS forwarders are setup as follows.

Forwarders

ALL other DNS Domains
are pointing to 2 of ours Internet DNS

extranet.net
Pointing to out DMZ DNS

something.com.do
Pointing to our Unix DNS which then point to the correct address for our Email Domain

Something.net
is pointing to our Unix Domain DNS & to our Internet DNS

Thank you
0
Comment
Question by:Nehemoth
  • 5
6 Comments
 
LVL 10

Expert Comment

by:Darylx
ID: 24097623
If the internal DNS server hosts something.net, it will never forward any requests to the external DNS server hosting something.net.  It will just look in it's own something.net zone and if it can't find the record you're looking for, it will return a 'not found'.  You need to add all the external something.net records to the internal something.net DNS server.
0
 
LVL 1

Author Comment

by:Nehemoth
ID: 24097794
Yes I understood that.

By my problems right now are from something.com to something.net be the internal or the external
0
 
LVL 1

Author Comment

by:Nehemoth
ID: 24098419
I also found this error in our Event Viever

Event Type:      Error
Event Source:      DCOM
Event Category:      None
Event ID:      10009
Date:            4/8/2009
Time:            9:07:41 AM
User:            N/A
Computer:      SVRDC1
Description:
DCOM was unable to communicate with the computer 200.42.xxx.xx using any of the configured protocols.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

The IP Correspond to our Internet DNS server
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 1

Author Comment

by:Nehemoth
ID: 24148919
Still waiting for the answer
0
 
LVL 1

Author Comment

by:Nehemoth
ID: 24206520
Still, someone knows?.
0
 
LVL 1

Accepted Solution

by:
Nehemoth earned 0 total points
ID: 24597421
nobody gave an answer so I will close it.
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
In-place Upgrading Dirsync to Azure AD Connect
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

680 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question