Link to home
Start Free TrialLog in
Avatar of hertewafik
hertewafikFlag for Afghanistan

asked on

www.microsoft.com is not opening with error 11001 DNS Error

i changed a rule in ISA from all users to authenticated users and after that microsft website is not accessible from ISA or any computer behind ISA . however i can browse the site with IP which is being resolved correctly . please help. this is problem with only microsft site.  User generated image
Avatar of SpamwareMP
SpamwareMP
Flag of Netherlands image

You could try to clear the DNS cache.
Does DNS resolve www.microsoft.com ok?
Other websites working normal?
Which NIC is pointing to the DNS?

And to which DNS the TMG NIC Cards is currently pointing?

Internal or external DNS?

Also, try to ping microsoft .com from the TMG server it self and check if it can resolve and then try to ping from client side.

Avatar of hertewafik

ASKER

internal NIC is pointing to internal DNS
external NIC is pointing to external DNS ( ISP DNS )

i am able to resolve www.microsoft.com and also browse by ip but when i try to browse by name i get the error.

other websites are working fine except for www.eset.com , www.mcafee.com , www.kaspersky.com
No need to point the external NIC to any DNS,  remove the dns setting from external NIC and flush the dns and try again.

Here is a very good article which will explain to you how to setup the ISA NICS correctly:

https://www.experts-exchange.com/Microsoft/Windows_Security/A_1477-Configuring-ISA-2004-2006-Forefront-Threat-Management-Gateway-for-basic-networking-and-DNS-settings.html

i did as stated by mkhairy but still i get the same problem. this is happening only to 4 websites namely www.microsoft.com , www.eset.com , www.mcafee.com , www.kaspersky.com 

is this some kind of virus infection ? as it was working fine and this problem came just before 2 weeks.
ASKER CERTIFIED SOLUTION
Avatar of Mohamed Khairy
Mohamed Khairy
Flag of Egypt image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
i changed back the specific to allow all users but still i get the same problem. once i swapped the primary DNS with secondary DNS of ISP in the forwarders on DNS server , it worked fine for 5 min , but again same problem started. i am fed up of this ISA . someone please help me.

thanks
i sorted out the problem . it was infection by conflicker worm. downloaded kaspersky removal tool. scanned the server and deleted any infections found. restarted the server and it worked.

thanks to all for ur efforts .
none of the answers solved my problems but mkhairy atleast tried his level best to help me.