Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Find source of DNS reuquest

Posted on 2010-11-26
8
369 Views
Last Modified: 2012-05-10
I am trying to trace back to the source of a DNS reuquest.  I can see the request to a BAD IP ADDRESS from our internal DNS server.  I would like to trace back to the system that made the original request.  How can this be done?
0
Comment
Question by:McFarlandClinic
8 Comments
 
LVL 10

Expert Comment

by:moon_blue69
ID: 34218044
What is your operating System.

I would suggest using network monitor if its a windows system. It can be added via add or remove windows componets.

Or wireshark
0
 

Author Comment

by:McFarlandClinic
ID: 34218062
I have run wireshark, but I am a novice at using it.  I can see where my internal DNS tried to resolve the name, but I can't tell what internal system my DNS is doing the lookup for.
0
 
LVL 10

Expert Comment

by:moon_blue69
ID: 34218076
What platform you are on?? Windows Server 2003??
0
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

 
LVL 10

Expert Comment

by:moon_blue69
ID: 34218101
Have you got enough client access licesnses ? (CAL)?
0
 
LVL 10

Expert Comment

by:moon_blue69
ID: 34218206
"Have you got enough client access licesnses ? (CAL)?"

sorry that was a wrong message posted
0
 

Author Comment

by:McFarlandClinic
ID: 34218219
Windows server 2003
0
 
LVL 70

Expert Comment

by:Chris Dent
ID: 34221575

> I have run wireshark, but I am a novice at using it.  I can see where my internal DNS tried to resolve the name, but I can't tell
> what internal system my DNS is doing the lookup for.

You'd need to capture the request from the client, not the request from the server to the rest of the world. The logging options in the DNS console should permit this although it won't be easy.

DNS packets do not contain a history of who asked what, therefore your only chance is to grab the request and its source IP.

Chris
0
 
LVL 26

Accepted Solution

by:
DrDave242 earned 500 total points
ID: 34235317
You can also turn on debug logging on the DNS server:

Open the DNS console, right-click on your DNS server, and select Properties.  Click the Debug Logging tab and select the checkbox for Log packets for debugging.  Then you have a whole pile of options for which types of packets you want to log.  You can select and deselect those as appropriate.  (I'd leave both Outgoing and Incoming selected, as well as Request and Response.)

The log file is saved as system32\dns\dns.log by default, although you can change that in the Properties window also.  Open the log in Notepad or your favorite text editor, do a little searching, and you should have the source of the query in no time.

Don't forget to turn off debug logging when you're done.
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
DNS Scavenging configuration 5 75
DHCP DNS Set up 4 83
DNS issue with resolving request 14 106
Windows server:  Forwarding to 8.8.8.8 vs using root hints 2 26
Most DNS problems are VERY easily troubleshot and identifiable if you can follow the steps a DNS query takes. I would like to share the step-by-step a DNS query takes from the origin to the destination. _____________________________________________…
BIND is the most widely used Name Server. A Name Server is the one that translates a site name to it's IP address. There is a new bug in BIND (https://kb.isc.org/article/AA-01272), affecting all versions of BIND 9 from BIND 9.1.0 (inclusive) thro…
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question