Solved

DNS Corect Setup on Active Directory

Posted on 2009-05-08
6
214 Views
Last Modified: 2012-05-06
I recently started experiencing some problems after one of my DNS server crashed. I have a network with 500 worskstations and I have 8 DC servers running at each of my subnets.
When my Primary DC crashed at my main site, all workstations stoped resolving when trying to get to my internet.
All of our internet traffic goes out from our main site and since that DC had the Forward Pointers to external DNS all the rest of my DNS servers could not rsolve for them
All my DNS are active-directory integrated.
My question is ; do I have to setup Forwarders on all my DNS to use external ISP dns?
Also I noticed that even thought all my workstations had a secondary DNS they did not use it to resolve.
Any help is greatly appreciated
0
Comment
Question by:sammydlc
  • 3
  • 2
6 Comments
 

Expert Comment

by:dpm2009
Comment Utility
You should just need to setup your Primary DC's DNS settings to your external DNS.  While all local dns requests can point to the primary DC....
0
 
LVL 82

Expert Comment

by:oBdA
Comment Utility
Yes, it's best to setup the forwarders to your ISP's DNS on all DNS servers; otherwise the servers will by default use the root hints to resolve external lookups. Were your additional DCs pointing to your main DC as forwarder, and/or could there be any firewall issues on the additional DCs?
And how did you check whether your machines weren't using the secondary DNS?
Are your additional DCs Global Catalogs?
0
 

Author Comment

by:sammydlc
Comment Utility
Ok, I just modified that. Now all my Dcs have Forwarders to External ISP DNS.
Yes some of my DNS servers had only my Main DNS listed on theyr external forwarders. They had not external DNS. i do not think we have a firewall issue because I was able to ping fine internally if I did it manually. All my remaining DNS servers responded fine when I pinged them.

As for the workstations not able to use the secondary DNS i verified that the workstation had a DHCP address assigned. when I did an ipconfig I saw that my primary DNs was the server that had crased.
My secondary DNS was a server that was operational except it was on a different subnet than where my stations were. When I pinged an internal name I got a response. When I pinged an external name I did not get a response.
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 82

Accepted Solution

by:
oBdA earned 250 total points
Comment Utility
If your other DNS servers were set to forward to your main DNS server, then that's simply why.
This should work flawlessly with the external forwarders on all DNS servers.
0
 

Author Comment

by:sammydlc
Comment Utility
OK everything is working ok except that my secondary DNs is still not resolving.
I tested because one of my stations has the Crashed DNS as primary DNS and my Working DNS as 2nd.

If I ping by name I am still  not resolving.

If I move my working DNS to primary and ping by name, I get a response.
Am I missing something on DNs configuration>?
0
 

Author Comment

by:sammydlc
Comment Utility
Secondary DNS is now responding. I guess it just needed some time to start responding. Now if I have my working DNs as Secondary Even 3rd I can resolve without problems.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

I wrote this article to explain some important DNS concepts that should be known to avoid some typical configuration errors I often see in forums. I assume that what is described here is the typical behavior of Microsoft DNS client. I don't know …
On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

6 Experts available now in Live!

Get 1:1 Help Now