Link to home
Start Free TrialLog in
Avatar of DEFclub
DEFclub

asked on

DNS forwarding mistery

Due to some mysterious traffic, I’ve configured my Microsoft (2003) DNS servers to route dns through a DNS sinkhole.  In DNS, I set the DNS forwarder to the IP of the sinkhole; however, I still see DNS traffic from the DNS server bypassing the sinkhole and hitting the firewall. What am I missing? I thought setting the DNS forwarder would do the trick but I’m missing something. Help ?
Avatar of archerslo
archerslo
Flag of United States of America image

Doesn't your incoming traffic hit the firewall BEFORE hitting your DNS server? Seems like expected behavior to me. Sounds like you need to make a change at your registrar if you want the traffic to stop hitting your server.
Is the DNS server set to use itself only as the DNS server. If its set to use anything else it might be just sending the queries out to the internet itself.
I am with Aegil
Avatar of DEFclub
DEFclub

ASKER

They are set to themselves. Wouldn't DNS use the forwarder, if a forwarder is set, before using root hints? and is it safe to remeove the root hints? I've removved the root hints on one box but still the box is not forwarding all traffic to the forwarder... any more ideas?
Avatar of DEFclub

ASKER

?
Avatar of DEFclub

ASKER

Ok, I removed root hinks and the the mail stopped bypassing the forwarding to the sinkhole - so it looks like the root hinks were the issue; however, removing the root hinks broke DNS. How can I remove the root hinks and not break DNS, or how can I get the root hinks to forward to my DNS sinkhole? Anyone?
ASKER CERTIFIED SOLUTION
Avatar of Aegil
Aegil
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Avatar of Steve
Steve
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of DEFclub

ASKER

Looks like the resolution was to check the box "dont use recursion for this domain" in front of my face the whole time. It looks like if I check this box it will use the forwarder to forward to the next dns server for recursion which is what i want; the next dns server is the sinkhole...

totallytonto, are you sure if i disable resursion the forwarder will not work? looks like its working to me?