Solved

DNS Corect Setup on Active Directory

Posted on 2009-05-08
6
217 Views
Last Modified: 2012-05-06
I recently started experiencing some problems after one of my DNS server crashed. I have a network with 500 worskstations and I have 8 DC servers running at each of my subnets.
When my Primary DC crashed at my main site, all workstations stoped resolving when trying to get to my internet.
All of our internet traffic goes out from our main site and since that DC had the Forward Pointers to external DNS all the rest of my DNS servers could not rsolve for them
All my DNS are active-directory integrated.
My question is ; do I have to setup Forwarders on all my DNS to use external ISP dns?
Also I noticed that even thought all my workstations had a secondary DNS they did not use it to resolve.
Any help is greatly appreciated
0
Comment
Question by:sammydlc
  • 3
  • 2
6 Comments
 

Expert Comment

by:dpm2009
ID: 24338299
You should just need to setup your Primary DC's DNS settings to your external DNS.  While all local dns requests can point to the primary DC....
0
 
LVL 84

Expert Comment

by:oBdA
ID: 24338332
Yes, it's best to setup the forwarders to your ISP's DNS on all DNS servers; otherwise the servers will by default use the root hints to resolve external lookups. Were your additional DCs pointing to your main DC as forwarder, and/or could there be any firewall issues on the additional DCs?
And how did you check whether your machines weren't using the secondary DNS?
Are your additional DCs Global Catalogs?
0
 

Author Comment

by:sammydlc
ID: 24338432
Ok, I just modified that. Now all my Dcs have Forwarders to External ISP DNS.
Yes some of my DNS servers had only my Main DNS listed on theyr external forwarders. They had not external DNS. i do not think we have a firewall issue because I was able to ping fine internally if I did it manually. All my remaining DNS servers responded fine when I pinged them.

As for the workstations not able to use the secondary DNS i verified that the workstation had a DHCP address assigned. when I did an ipconfig I saw that my primary DNs was the server that had crased.
My secondary DNS was a server that was operational except it was on a different subnet than where my stations were. When I pinged an internal name I got a response. When I pinged an external name I did not get a response.
0
NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

 
LVL 84

Accepted Solution

by:
oBdA earned 250 total points
ID: 24338470
If your other DNS servers were set to forward to your main DNS server, then that's simply why.
This should work flawlessly with the external forwarders on all DNS servers.
0
 

Author Comment

by:sammydlc
ID: 24338774
OK everything is working ok except that my secondary DNs is still not resolving.
I tested because one of my stations has the Crashed DNS as primary DNS and my Working DNS as 2nd.

If I ping by name I am still  not resolving.

If I move my working DNS to primary and ping by name, I get a response.
Am I missing something on DNs configuration>?
0
 

Author Comment

by:sammydlc
ID: 24338807
Secondary DNS is now responding. I guess it just needed some time to start responding. Now if I have my working DNs as Secondary Even 3rd I can resolve without problems.
0

Featured Post

How our DevOps Teams Maximize Uptime

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us. Read the use case whitepaper.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Recently, I had the need to build a standalone system to run a point-of-sale system. I’m running this on a low-voltage Atom processor, so I wanted a light-weight operating system, but still needed Windows. I chose to use Microsoft Windows Server 200…
Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question