Solved

Can't access external website over internal domain

Posted on 2010-09-19
8
1,398 Views
Last Modified: 2012-08-13
Hi,

SBS 2008 - new setup

DOMAIN NAME:   companysafety.com
IP:   64.23.137.246 (3rd party webhost IP)

A RECORD:   www.companysafety.com
IP:   64.23.137.246 (3rd party webhost IP)

- webhost does not control domain name
- webhost uses shared IP / storage for websites


A RECORD:   remote.companysafety.com
IP:   62.35.125.210 (Static WAN IP of Server)
- used for Remote Web Workplace, Outlook Web Access, Remote Desktop etc.

MX RECORD:   mail.companysafety.com
IP:   62.35.125.210 (Static WAN IP of Server)
- used for Exchange


Server Domain:   company.local
Server IP / DNS:   192.168.15.1
DHCP enabled through Server

Client machines logged onto the server cannot access "www.companysafety.com", even though it's located offsite on a separate WAN IP.
However, when the Client machine is using a different DNS address (ISP's DNS supplied through the router), it can see "www.companysafety.com"
Anyone using a separate internet connection can also see "www.companysafety.com"

Does anyone know what's causing this issue and how I can fix it?

Thanks
   
 
0
Comment
Question by:Clownie669
  • 4
  • 2
  • 2
8 Comments
 
LVL 10

Expert Comment

by:ddiazp
ID: 33712027
do:

nslookup
server 4.2.2.2
www.companysafety.com  (or whatever domain you're working with)
(record IP in output)


Does this IP match what you have on your A record (www) under the companysafety.com zone?


When your clients query DNS for a domain, if your DNS server has that domain configured, the server will take control of any query to that domain.

For example, if you add a zone microsoft.com, and your clients query update.microsoft.com or *.*.microsoft.com for that matter, DNS will fail unless you have the matching records.
0
 

Accepted Solution

by:
Insideview earned 125 total points
ID: 33712331
If you  check the forward lookup zone on the server and enter a Cname for Www pointing it to the external address it should work after a reboot
0
 

Author Comment

by:Clownie669
ID: 33712366
The server is currently down.  I'll be going in later tonight to finish the setup.
I'll try your suggestion.

Thanks
0
 

Author Comment

by:Clownie669
ID: 33713836
I went to "DNS" through "Administrative Tools" and expanded the "Forward Lookup Zones"
There are 4 listings:

_msdcs.company.local
company.local
companysafety.com
remote.companysafety.com

I added a "New Host (A or AAAA)..." record to all except "_msdcs.company.local" and rebooted the server.
Didn't work.

I'm new to this.  
Which listing am I supposed to add the new record too?
- "remote.companysafety.com" is the current public domain I setup using the "Set up your Internet address" wizard in the SBS Console
- company.local is the local domain
- "companysafety.com" is the old public domain I setup using the wizard.


Thanks
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Expert Comment

by:Insideview
ID: 33714106
Ah perhaps the 4 are the problem,
On my server I only have 2 in the forward lookup
_msdcs.mycompany.local
and
mycompany.local
perhaps if you companysafe.com were removed the computers inside the LAN would be forced to look outside on the WAN for the website
0
 
LVL 10

Assisted Solution

by:ddiazp
ddiazp earned 125 total points
ID: 33717353
what do you get when you do :

nslookup www.companysafety.com

on the client machines?

and what do you get when you do:

nslookup
server 4.2.2.2
www.companysafety.com

on the client machiines?


The result must match - if it doesn't, you haven't added an 'A' record "www" with the correct IP.

When you add the A record make sure to name it "www" and not "www.companysafety.com" (DNS will append the domain name to the record).

Also, check the hosts file for the clients to make sure there's no entry for www.companysafety.com pointing somewhere else:

C:\WINDOWS\system32\drivers\etc\hosts
0
 

Author Comment

by:Clownie669
ID: 33718744
Sorry for not responding sooner.

I was having another issue getting a trusted SSL Cert approved.
I'll have access to the server later tonight and will try your suggestions.


Thanks
0
 

Author Closing Comment

by:Clownie669
ID: 33804846
Sorry for not responding sooner...again.

The solutions provided by Insideview and ddiazp were correct.


Thanks again!
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

I’m often asked about newer and larger USB drives connected to SBS2008 and 2011 failing Windows Server Backup vs the older USB drives not failing. As disk space continues to grow and drive technology change SBS2008 and some SBS2011 end up with the f…
If you are a user of the discontinued Microsoft Office Accounting 2008 (MSOA) and have to move to a new computer running Windows 8, you will be unhappy to discover that it won't install.  In particular, Microsoft SQL Server 2005 Express Edition (SSE…
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now