Expiring Today—Celebrate National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Some external domaine not resolving on new 2003 to 2008 migration.

Posted on 2011-10-04
16
Medium Priority
?
282 Views
Last Modified: 2012-05-12
We recently migrated from Server 2003 to 2008 DNS and DCs we are having a weird issue where paypal and it seems to only be paypal so far is unreachable or pingable. If I connect to our public Wireless network(outside our DMZ and using same link) it works fine. I have a feeling it may have something to do with Root hints or something but I don't know enough to troubleshoot. It's just weird that it is not for all sites. We are not using any forwarders.

Thanks in Advance
0
Comment
Question by:nocalerts
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 4
  • 2
  • +3
16 Comments
 
LVL 13

Expert Comment

by:BCipollone
ID: 36911770
Hmm I would flush the DNS and ARP tables.  Are you able to ping either the host name or the IP seperately?  Have you narrowed it down to your DNS server?  Is it resolving the correct IP address?  
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 36911865
0
 

Author Comment

by:nocalerts
ID: 36912003
I will try restarting DNS and if that fixes it I'll try the Reg fix. Does anyone see a problem restarting the DNS service in the middle of the day is I have 2 Servers?
0
Introducing the WatchGuard 420 Access Point

WatchGuard's newest access point includes an 802.11ac Wave 2 chipset, providing the fastest speeds for VoIP, video and music streaming, and large data file transfers. Additionally, enjoy the benefits of strong security as the 3rd radio delivers dedicated WIPS protection!

 
LVL 37

Expert Comment

by:Neil Russell
ID: 36912223
DNS takes a few seconds max to do a service restart. a few clients may get web page not found etc if they are real unlucky.
0
 

Author Comment

by:nocalerts
ID: 36912230
Ok Thanks I'll let you know how it goes.
0
 

Author Comment

by:nocalerts
ID: 36912274
No luck. I'll try in a few minutes incase something has to replicate. Any other ideas if it still doesn't work?
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 36912282
You have done the regfix?
0
 

Author Comment

by:nocalerts
ID: 36912287
no not yet
0
 

Author Comment

by:nocalerts
ID: 36912291
I will try that tonight
0
 
LVL 10

Expert Comment

by:ddiazp
ID: 36912308
May sound dumb but did you create a forward zone for paypal?

On one of the machines where you can't access it do:

nslookup
set type=ns
paypal.com

(ensure the result is valid)

then:
server <any of the servers from the results above>
set type=a
<hostname you want to ping>
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 36912336
IF it is the issue i posted about then WHEN you restart DNS it will seem to work, even though you havent done the reg fix. FOR A WHILE.

The whole point is its a known bug and a reboot/restart of DNS will fix it very short term.
0
 

Author Comment

by:nocalerts
ID: 36912497
restarting DNS services didn't fix the problem. So should I still try the reg fix?

ddiazp: I'm not sure what you mean by setup a forward zone. Shouldn't the root hints forward it correctly?
0
 
LVL 59

Accepted Solution

by:
Darius Ghassem earned 2000 total points
ID: 36912777
I would use DNS Forwarders there are known issues with Root Hints in Windows 2008 Server

http://technet.microsoft.com/en-us/library/cc773370(WS.10).aspx
0
 
LVL 10

Expert Comment

by:ddiazp
ID: 36913977
Yes, mine was a rather tricky question.

If you added a forward lookup zone for the domains you cant access then that would explain it. other than that, probably the other guys are onto something
0
 
LVL 20

Expert Comment

by:brwwiggins
ID: 36914407
If it were me I would try disabling eDNS. It's an easy command line and does not require a server restart (although I would personally restart DNS). This has helped me numerous times on 2008 servers

http://support.microsoft.com/kb/832223

From an elevated command prompt, type the following and hit enter

dnscmd /config /enableednsprobles 0

NOTE: that is the number zero and not "O"
0
 

Author Comment

by:nocalerts
ID: 36932214
I fixed it by adding google's dns servers as a forwarder. (8.8.8.8) I would recomend setting that if you can. It made our page loads faster than I have ever seen them

Thanks everyone.
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question