Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Server 2003 DC - Recursive Query fails in DNS

Posted on 2011-09-19
6
Medium Priority
?
351 Views
Last Modified: 2012-05-12
Have two servers (server1 and server 2) which are both DCs.
For some reason they are not replicating.  Believe the issue is with DNS on server1.
This was first noticed when server1 could not access the internet.  Can ping internal names and IP addresses.  But cannot ping outside names (e.g. www.google.com) - will not resolve.
Am not onsite but able to remote to server2.  Cannot RDP to server1.  All network shares cannot be seen on server1.  From DNS Manager on server2 cannot open DNS settings for server1.
Had an onsite user check and appears DNS is setup correctly on server1.  On server1 can open DNS Manager and can see the settings for server1.  It fails the recursive query test.
Tried to force AD replication but encountered DNS errors.
Am reviewing the even viewer for errors.
Have rebooted server1.  
Any ideas?  Anyone have a troubleshooting doc?
Thanks
0
Comment
Question by:abpExpert
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
6 Comments
 
LVL 13

Expert Comment

by:Govvy
ID: 36561960
What are your forwarders set to on the DNS server which can't communicate externally? Good troubleshooting guides listed here: http://social.technet.microsoft.com/wiki/contents/articles/2285.aspx
0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 36561981
> For some reason they are not replicating

AD isn't? Or DNS isn't?

If it's AD, or the DNS zone you're having trouble with is AD Integrated, DCDiag, "repadmin /showreps" and the Directory Service event logs are a good steps.
> But cannot ping outside names (e.g. www.google.com) - will not resolve.

This is a different problem. Perhaps we should look at how your Forwarders are set (if any are set at all)? And we must consider Firewalls and other devices that may block DNS traffic (mostly UDP/53).

> From DNS Manager on server2 cannot open DNS settings for server1.

Error message? Could be related to replication, so back to AD.

> It fails the recursive query test.

Repeat of above really, it's the same problem you saw when you couldn't get www.google.com.

In summary:

If it's AD having trouble: DCDiag, RepAdmin, Directory Service event logs.
If it's just DNS having trouble: Start with checking the things you've set as Forwarders.

And, of course, post any findings and we can all help you work through it.

Chris
0
 

Author Comment

by:abpExpert
ID: 36566904
Got more/verified info from someone onsite.

SERVER1
can ping by name and IP on the LAN
ping resolves name but no reply when trying to ping the WAN
DNS setting (i.e. forwarders seem correct)
file shares are not accessible
RDP is not working
Cannot modify Group Policies through the snap in
DCDIAG fails the FRSEVENT test
Still reviewing the event viewer
Ran MalwareBytes and removed three trojans

SERVER2
DCDIAG fails all tests related to accessing SERVER1

Both servers are Domain Controllers and SERVER1 holds the FSMO roles

Came across KB 839499 article and looking into that.
0
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

 

Author Comment

by:abpExpert
ID: 36567379
One other note.

SERVER1 had an ISP DNS server listed in the NIC DNS properties setting.  According to the person onsite it had always been there.

My experience is you never do that.  Removed it and rebooted the server and the issue remained.

Also, both servers are set up to use themselves as primary DNS and the other server as a secondary.  Thought the setup was to use only itself as the DNS server on the NIC.  Have seen both used but believe that is not recommended.

Bottom line the RPC service is started but not working.  Any ideas?  Thanks in advance.
0
 

Accepted Solution

by:
abpExpert earned 0 total points
ID: 36569942
Here was the fix:

The IPSec service had been enabled through the services
So we stopped the service
We had to go into the MMC
Add the snap in
IP Security Monitor and
IP Security Policy Management unassigned the Policy in the MMC
Then restart the IPSec Service.

Once we stopped the IPSec Service the computer came alive.
0
 

Author Closing Comment

by:abpExpert
ID: 36708116
found solution
0

Featured Post

Looking for the Wi-Fi vendor that's right for you?

We know how difficult it can be to evaluate Wi-Fi vendors, so we created this helpful Wi-Fi Buyer's Guide to help you find the Wi-Fi vendor that's right for your business! Download the guide and get started on our checklist today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Scenerio: You have a server running Server 2003 and have applied a retail pack of Terminal Server Licenses.  You want to change servers or your server has crashed and you need to reapply the Terminal Server Licenses. When you enter the 16-digit lic…
I've always wanted to allow a user to have a printer no matter where they login. The steps below will show you how to achieve just that. In this Article I'll show how to deploy printers automatically with group policy and then using security fil…
In this video, Percona Director of Solution Engineering Jon Tobin discusses the function and features of Percona Server for MongoDB. How Percona can help Percona can help you determine if Percona Server for MongoDB is the right solution for …
Please read the paragraph below before following the instructions in the video — there are important caveats in the paragraph that I did not mention in the video. If your PaperPort 12 or PaperPort 14 is failing to start, or crashing, or hanging, …
Suggested Courses

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question