DNS Server 2008

Posted on 2011-02-25
Last Modified: 2012-05-11
Hello Gurus,
I have a Open recursive DNS resolver. How could I solve this issue? Cause if I disable recursion, the forwarders will no longer be in operation. Will root hints do the resolving at this time?
Question by:uscstevens
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 2
LVL 78

Expert Comment

ID: 34983650
What is your setup?  Do you have authoritative zones that are externally accessible?
i.e. external servers need to connect to your dns server to obtain information.

Author Comment

ID: 34984091
I have forwarders configured, but it turns out to be a  Open recursive DNS resolver. If I were to disable recursion, could resolution still happen via Root Hints??
LVL 78

Expert Comment

ID: 34984450
Could you kindly answer the questions posed?

Must you expose your DNS server to the Internet at large?

Forwarders are configured on your server to send requests out?

Disable external access to your internal DNS server if you do not host public domains on your DNS server.
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!


Author Comment

ID: 34984891
Yes, No, Yes.. I wish to disable recursion, could you help?
LVL 78

Expert Comment

ID: 34985121
There is no need to disable recursion, you need to disable external access to the DNS server.
Either by removing the port forward or if your system has two nics,enable the firewall rules on the external NIC.

I have no idea what your setup is so it is rather hard to suggest a course of action.
LVL 78

Expert Comment

ID: 35240614
root hints are hints for the resolver on the dns server. if you disable recursion on your local dns, you will have issues on the LAN.  the use of forwarders means that your server forwards requests it can not answer to the forwarders which do the recursion and yours stores/caches the response.
LVL 78

Accepted Solution

arnold earned 500 total points
ID: 35269044
If disabling the external firewall to prevent access to the DNS server is not an option.
Open the DNS management interface.

NOTE that one you disable recursion on your DNS server and this server is used by your WORKSTATION in the LAN, they will generate errors because they will be expecting a complete answer and not a reference. i.e. if you disable recursion and using your browser to go to, your non-recursive DNS server instead of telling your workstation go here, it will tell it to consult  Your workstation in turn will tell you that there is an error because it is incapable of recursive lookups which is the service an internal DNS server provides.

With that out of the way and you are now aware of the consequences of implementing the change you seek.

If you have a test environment, make sure to test what you intend to do within it as a test so that you are fully aware of the consequences and the impact.

Featured Post

NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Need Script to resolve IPs to Public DNS Names 5 38
Replication problems 6 25
How to properly configure _msdcs child zone? 14 31
iMac not resolving DNS 7 30
There have been a lot of times when we have seen the need to enter a large number of DNS entries in a forward lookup zone. The standard procedure would be to launch the DNS Manager console, create the Zone and start adding new hosts using the New…
It’s been over a month into 2017, and there is already a sophisticated Gmail phishing email making it rounds. New techniques and tactics, have given hackers a way to authentically impersonate your contacts.How it Works The attack works by targeti…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question