Problem resolving a specific URL

Posted on 2010-11-18
Last Modified: 2012-05-10
We believe we have an internal DNS problem.  We are running Windows Server 2008R2 and Windows XP workstations.  Over 99% of our DNS queries resolve and function properly.  We encountered a problem with users attempting to reach on our LAN.  
* We can reach this site by IP address.
* We can resolve and reach the site using but not using
* On workstations we can ping or run nslookup using but not using
* On domain controllers we can ping or run nslookup using  We can ping, but cannot run nslookup using
* We can reach both addresses from our DMZ.  
* We have flushed DNS caches locally and on our domain controllers and were still able to repeate all of the above behaviors.
* Adding an entry for on our domain controller allows the domain controller to resolve, but not a workstation, perhaps due to dns forwarding.
* Adding an entry for on a local computer, resolves the issue for that computer as expected.  
Any thoughts regarding what might be causing this or how to resolve it?
Question by:isaIT
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2

Expert Comment

ID: 34167225
Out of curiousity, if you statically assign an IP to one of these workstations and set their dns server as an outside dns (Such as does it resolve your issue?
LVL 71

Expert Comment

by:Chris Dent
ID: 34167731

Do you have Forwarders configured on your DNS servers at the moment?

When you attempt to resolve using nslookup, what happens? Timeout? Server Failure? Doesn't exist?


Author Comment

ID: 34167950
Thank you for the comments,

When we statically assign an IP to one of the workstations and set their dns server to an outside dns, it does resolve the issue.

We do have DNS forwarders configured for everything outside of our domain..

When we attempt to resolve using nslookup it times out.  

Here is another interesting bit of information we just discovered, this doesn't explain why it won’t resolve from our LAN.

When we do an nslookup on vs we see different IP addresses depending upon the DNS sever we query.

 Internal nslookup using or
- resolves to  Address:
- does not resolve
External lookup using or
- resolves to  Address:
-  resolves to
External lookup using
- resolves to  Address:
-  resolves to

Both and bring up the target web site.
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.


Expert Comment

ID: 34168000
Are your computers setup to obtain IP addresses via DHCP or Manually? Have you checked to make sure that the DNS that DHCP is assigning is correct?

LVL 71

Accepted Solution

Chris Dent earned 250 total points
ID: 34168052

If you use Forwarders on your DNS servers no amount of clearing the cache will do any good, the answer (or lack of answer) is inherited from the forwarder.

You might try setting your internal DNS server to forward to and (both belong to Google).


Author Comment

ID: 34168058
We are using DHCP.  This appears to be working preperly and is assigning the correct DNS server.

Author Closing Comment

ID: 34168141
Thanks for the help Chris.  You rock.

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
How to transfer activity to a new domain controller? 40 75
RDP authentication error 3 71
Cisco WLC certificate question 4 16
sync 2 servers 2008 9 72
One of the most often confused topics in the area DNS is the idea of GLUE records. Specifically, what they are, when they are needed, when they are provided, and how they are created. First, WHAT IS GLUE? To understand GLUE, you must first under…
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question