Solved

DNS Resolving local Names as external IP address

Posted on 2010-09-23
4
344 Views
Last Modified: 2012-05-10
This occures randomly through out the day. All workstations have experienced it. It usually only lasts for a few minutes or until I flush and register the DNS on the workstation.

This is a standard SBS 2003 server that does DHCP, DNS, File serving, print serving. Just basic stuff.

I have scoured through the DNS settings, they seem ok. I have also checked the firewall to make sure DNS is disabled on it.

In the example below it should be resolve 192.168.4.233
Example:
C:\Documents and Settings\user>ping server01

Pinging p12p-i.geo.vip.re4.yahoo.com [216.39.57.107] with 32 bytes of data:

Reply from 216.39.57.107: bytes=32 time=86ms TTL=52
Reply from 216.39.57.107: bytes=32 time=109ms TTL=52
Reply from 216.39.57.107: bytes=32 time=96ms TTL=52

Ping statistics for 216.39.57.107:
Packets: Sent = 3, Received = 3, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 86ms, Maximum = 109ms, Average = 97ms
0
Comment
Question by:demmons-ssit
  • 2
4 Comments
 
LVL 59

Accepted Solution

by:
Darius Ghassem earned 500 total points
ID: 33749117
Make sure you are only pointing to the SBS server only within the TCP\IP settings of the clients and server.
0
 
LVL 13

Expert Comment

by:markusdamenous
ID: 33749180
Check the hosts file also.

C:\Windows\System32\Drivers\etc

Should only really need to have localhost in there as an entry, anything is prob. suspicious.
0
 

Author Comment

by:demmons-ssit
ID: 33749668
Just fixed it... This was a doozey!

The DNS settings all look fine on the server.

I checked DHCP and there was an entry for two external IP addresses as secondary DNS servers being dished out to workstations. So every workstation could browse the intertubes even if the server went down. Mind you I just took over this environment, don't know what the previous sys admin was thinking. The two Public IP's set as DNS servers for workstations were from CBeyond and a DSL company.

Looking at the A records for the company website host name I noticed an odd A record that was resolving *.DomainName.com to the Yahoo IP in the OP.

Basically the path and randomness looked like this...
Server was overloaded with requests, the workstation tapped its secondary DNS, the secondary DNS can resolve *.domainname.com so it was resolving private hostnames as that public Yahoo IP. The local DNS server finally cools off from requests and the clients revert back to primary DNS.

I can confirm the fix, the DNS path and everything but the workstations flipping to secondary DNS. I don't know how to track that.

Thanks guys!
0
 

Author Closing Comment

by:demmons-ssit
ID: 33749680
Thank you, checking the DNS settings using ipconfig /all did indeed show the two extra public IP's under the secondary DNS field. Which is what I believe you were trying to convey here.
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
analyzing possible malicious link 8 26
Trust DNS Resolution for Unqualified Names 3 40
Doing AD cleanup with Powershell 9 56
Shared files and folders migration 2 26
If you have a multi-homed DNS setup in windows, you can have issues with connectivity to the server that hosts the DNS services (or even member servers of your domain if this same DNS server is a DC). This is because windows registers all of its IPs…
I will assume you are running a non-server version of some sort of Windows throughout this article. There are many flavors of Windows since Windows Server 2000 - 2008, XP Home & Pro, Vista Home & Pro, and Windows 7 Starter, Home, Pro, Ultimate, etc.…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question