Solved

DNS Resolution Issue

Posted on 2012-03-13
4
362 Views
Last Modified: 2012-04-08
Hello EE,

I have i bit of a DNS issue going on at the moment that i am struggling to get my head around.
 
Our network has a number of sites, but only the two primary sites have AD/DNS.

Site A 172.16.0.0/16
Site B 172.18.0.0/16

I run VLANS and the above sites are broken down into /24 subnets  for the different departments etc just in case your wondering.

When clients at Site B ping DOMAIN.LOCAL the reply comes from and '169.254' address, when i flush the DNS cache on the client and try again, the DNS server at that site replies. 172.16.20.1 in this case.

Quite often computers at Site A cannot reach the DNS at site A, but the DNS at Site B responds. Same thing again, if i flush the DNS cache on the client at Site A. It will then get a reply from 172.16.20.1 server at Site A.

I think the cause is more likely to be related to my lack of in depth DNS knowlege, i have probably configured something wrong at some stage during the life of this network.
0
Comment
Question by:nammit-man
  • 2
4 Comments
 
LVL 20

Expert Comment

by:edster9999
ID: 37713998
I would start with the basic network layout.

Assuming you have it split to something like :

172.16.20.X = servers
172.16.21.X = User group A
172.16.22.X = User Group B

etc

Each subdomain must have a default gateway.
This number MUST be inside the subnetwork for that range.  So the IPs in 172.16.21.X need a gateway in 172.16.21.1 - 172.16.21.254
The normal layout would be to use 172.16.21.1
This does however have to be a device on the network that will handle routing to get to the other subnets / vLans.  if your switches are clever enough (L3 type switches) it can be them otherwise it has to be the router all these switches are plugged into - and that needs to be configured to understand all the vlans and gateways.

In places where this is not set up right, the switches will try to build their own routing plans and learn where things are.  This would explain why it doesn't work at the start but after a bit of traffic it starts to work.

Go back and check the network setup first.
0
 

Author Comment

by:nammit-man
ID: 37714024
The swiches do have layer 3 functionality but this is all disabled as i have proper routers.

I have two core routers at site A and a core router at Site B, with multiple VPN's for redundancy.  I run OSPF so most of the routing is done dynamically. Everything is reachable via IP address, so im pretty sure that the routing is all fine.

Also as i mentioned previously once i flush the cache the reponse is as per the design.

I am pretty sure that this is related to the DNS config on the server.
0
 
LVL 59

Accepted Solution

by:
Darius Ghassem earned 500 total points
ID: 37714776
You need to look on your DNS servers disable any secondary network cards.
0
 
LVL 20

Expert Comment

by:edster9999
ID: 37717335
Use a tool like 'dig' (which you can get for linux or windows) to do DNS tests.
This tells you where the result comes from and what is asked / replied etc.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The password reset disk is often mentioned as the best solution to deal with the lost Windows password problem. In Windows 2008, 7, Vista and XP, a password reset disk can be easily created. But besides Windows 7/Vista/XP, Windows Server 2008 and ot…
Ever notice how you can't use a new drive in Windows without having Windows assigning a Disk Signature?  Ever have a signature collision problem (especially with Virtual Machines?)  This article is intended to help you understand what's going on and…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question