Solved

sbs 2011  dns issues

Posted on 2011-09-24
17
915 Views
Last Modified: 2012-05-14
I have a newly migrated SBS 2011 server.  I used the swing migration method and am having intermittent DNS issues.

I have a Dell 2970 Dual Quad with 32gig of memory.  The DNS entry for the server NIC is the SBS server itself.  My firewall is open out going.  

I disabled one NIC so I'm using only one Nic as instructed.  I can use the nslookup and resolve internal & external dns.  The problem I have it when I browse to web sites, they come up sometimes, other times the same site doesn't load.  I may get a time out, not found, partial site displayed with no graphics.  If I click reload many times it usually comes up.

Before I decommissioned my swing tempdc, I was having the same issue, but changed the primary DNS server to the temp DC and the internet was fine.  After the decommission, I am not able to reliably browse from the server or workstations.  When using the DNS on the temp browser for the workstations, I still could not surf from the SBS server.  I did change the IE restrictions for administrators, and I'm logged in as the domain administrator.

I've run dcdiag and it looks good.  I've flushed DNS and registered dns.  I've tried putting in valid forwarders in the dns.  Just when I think it is working fine on 5-8 sites, it then seems to lose the ability to resolve and may display page not found or a partial web page.  It could be on a page that was loaded many times like www.msn,com.  The last time I tested, it only loaded a partial page of MSN, and I immediately ran an nslookup on the server and it resolved.

Help.
0
Comment
Question by:JackAitken
  • 9
  • 4
  • 2
17 Comments
 
LVL 10

Expert Comment

by:CSIPComputing
ID: 36594911
Have you tried this solution, which is known to affect Server 2008 and SBS sitting on it?

http://support.microsoft.com/kb/968372
Windows Server 2008 DNS Servers may fail to resolve queries for some top-level domains
0
 

Author Comment

by:JackAitken
ID: 36595395
I have not, and will test it shortly, and will let you know.
0
 

Author Comment

by:JackAitken
ID: 36595656
I just followed the article, and it had no effect.  It brings up a few web sites then times out.  Right after a time out, I ran nslookup, and is timed out, and said timeout was 2 seconds.
0
 
LVL 56

Expert Comment

by:Cliff Galiher
ID: 36596409
I'm guessing you have larger network issues, and this is just a symptom. Try a different network cable. A different swith or port, update your NIC drivers (Broadcom is really bad about buggy drivers) and disable advanced NIC features such as offloading features.

-Cliff
0
 
LVL 10

Expert Comment

by:CSIPComputing
ID: 36598187
Thinking specifically about the partial web pages, I would be looking at overall connectivity too.

Can you do a "ping www.yahoo.com -t" and see if you are getting lost packets over a 5-10 minute period?
0
 

Author Comment

by:JackAitken
ID: 36598982
When I introduced the new SBS 2011 & a tempDC, the DNS wasn't working on the SBS 2011, so I changed it to the tempDC, I made the tempDC as the primary DNS server, and it worked fine for 2 days.  Once i decommissioned the tempDC, the problem came back.  Don't believe it is connectivity due to that.
0
 
LVL 56

Expert Comment

by:Cliff Galiher
ID: 36599700
That is because the tempDC was handling DNS. connectivity on the SBS server would not cause DNS failures. Now that DNS is back on SBS, they will. Not sure why you'd think otherwise.

-Cliff
0
Free Gift Card with Acronis Backup Purchase!

Backup any data in any location: local and remote systems, physical and virtual servers, private and public clouds, Macs and PCs, tablets and mobile devices, & more! For limited time only, buy any Acronis backup products and get a FREE Amazon/Best Buy gift card worth up to $200!

 

Author Comment

by:JackAitken
ID: 36599766
I assume you were talking about connectivity to the internet, which the tempDC shows was fine.  If I ping www.yahoo.com, doesn't it require DNS to resolve?  I could try pinging the IP for www.yahoo.com to take the DNS out of the request.  I'll give that a shot.
0
 
LVL 56

Expert Comment

by:Cliff Galiher
ID: 36599784
No, I'm talking about the NIC connectivity itself. Flaky drivers and poor .NC settings, as well as cables or a failing switch (where one port works and another intermittently drops packets) could all cause the symptoms you describe. Pinging will likely be intermittent as well.
0
 

Author Comment

by:JackAitken
ID: 36599788
I'm pinging now, and so far no time outs.
0
 

Author Comment

by:JackAitken
ID: 36601318
I just finished working with Microsoft.  After testing all the things I did previously, they tried adding my firewall (192.168.1.1) as a forwarder, and that worked!  First time I ever added an internal address as a forwarder.  Internet is as fast as ever, and sites are resolving.
0
 

Author Comment

by:JackAitken
ID: 36707741
Just spent 5 more hours with microsoft.  What a beating.  They can't figure out why the dns is working the way it was designed.  We are still using the internal gateway address as a forwarder.  Does this pose any security risk?
0
 
LVL 56

Expert Comment

by:Cliff Galiher
ID: 36707759
No more so than using any other forwarder. The reliability of its replies and susceptibility to DNS poisoning is dependent in the DNS implementation if the gateway. Could be rock solid. Or could have been coded by chimpanzees. So the question is, do you trust your gateway manufacturer/vendor from a security perspective?
0
 

Author Comment

by:JackAitken
ID: 36707779
I need to figure this out, but didn't want to expose ourselves.  Funny thing is I can browse find with my laptop hard codeing ip & DNS, just not the SBS 2011 server.
0
 

Accepted Solution

by:
JackAitken earned 0 total points
ID: 37361594
Turns out to be the firewall.  The Netgear was set to use itself as a proxy.  Strange thing was the setting was not changed and existed when the SBS 2003 server was in place.
0

Featured Post

Promote certifications in your email signature

Has your company recently won an award or achieved a certification? They'll no doubt want to show it off. Email signature images used to promote certifications & awards can instantly establish credibility with a recipient and provide you with numerous benefits.

Join & Write a Comment

Suggested Solutions

A quick step-by-step overview of installing and configuring Carbonite Server Backup.
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now