DEFclub
asked on
DNS forwarding mistery
Due to some mysterious traffic, I’ve configured my Microsoft (2003) DNS servers to route dns through a DNS sinkhole. In DNS, I set the DNS forwarder to the IP of the sinkhole; however, I still see DNS traffic from the DNS server bypassing the sinkhole and hitting the firewall. What am I missing? I thought setting the DNS forwarder would do the trick but I’m missing something. Help ?
Doesn't your incoming traffic hit the firewall BEFORE hitting your DNS server? Seems like expected behavior to me. Sounds like you need to make a change at your registrar if you want the traffic to stop hitting your server.
Is the DNS server set to use itself only as the DNS server. If its set to use anything else it might be just sending the queries out to the internet itself.
I am with Aegil
ASKER
They are set to themselves. Wouldn't DNS use the forwarder, if a forwarder is set, before using root hints? and is it safe to remeove the root hints? I've removved the root hints on one box but still the box is not forwarding all traffic to the forwarder... any more ideas?
ASKER
?
ASKER
Ok, I removed root hinks and the the mail stopped bypassing the forwarding to the sinkhole - so it looks like the root hinks were the issue; however, removing the root hinks broke DNS. How can I remove the root hinks and not break DNS, or how can I get the root hinks to forward to my DNS sinkhole? Anyone?
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Looks like the resolution was to check the box "dont use recursion for this domain" in front of my face the whole time. It looks like if I check this box it will use the forwarder to forward to the next dns server for recursion which is what i want; the next dns server is the sinkhole...
totallytonto, are you sure if i disable resursion the forwarder will not work? looks like its working to me?
totallytonto, are you sure if i disable resursion the forwarder will not work? looks like its working to me?