Solved

SBS 2011 DNS Issues

Posted on 2012-04-12
3
1,634 Views
Last Modified: 2012-12-28
We have a Small Business Server 2011 implementation with 8 PCs.  All of our users could not get on sites like fedex.com or ups.com.  Most other sites were fine, but when we browse to UPS or Fedex, it redirects to an obviously spoofed Google page with spammy ads.   I change the default DNS settings at the client to point to Google's 8.8.8.8 DNS server and that seemed to fix the problem at the client, but I am worried about the server.  

I ran virus scans on the client and server and did not find any viruses.  SBS 2011 is the DNS server for the network, so I am concerned that something is wrong there.  What steps can I take to fix the DNS settings on the server?
0
Comment
Question by:dtervo
3 Comments
 
LVL 7

Expert Comment

by:BelushiLomax
ID: 37840040
First-off, dont point a DC to a public DNS server. It opens you to dns exploits which you may have.

Clean that up to where it only points to your isp or another inter Non-AD Integrated DNS server and restart the dns services and ipconfig /flushdns. Then consider a tool like hijackthis to get some insight to your bho's etc. Also, check your hosts file and make sure it's ok.

run a dcdiag /c /v /f:dcdiag.txt and search for and copy/paste the Error and Warning items
0
 
LVL 57

Accepted Solution

by:
Cliff Galiher earned 500 total points
ID: 37840077
I suspect your server is fine, but you have some DNS poisoning going on.

First thing is first. Client PC's should *always* only point at AD domain controllers for DNS. Otherwise things like security memberships and group policies will begin to fail. So undo the changes you made. If SBS is your only server then it should be the only DNS listing on the client (SBS's DHCP scopes set this up by default, so if you changed from DHCP to manual, simply switch back.)

Secondly, on the SBS server, open the DNS Server snap-in (under Administrative tools) and set up DNS forwarders. Use known "trusted" servers. Google DNS is not a bad choice, nor is OpenDNS. This is where I suspect the problem came from. You likely have ISP DNS servers now, and not all ISPs are good about protecting from poisoning.

Finally, flush the server's DNS cache once you've made the change and retest a known "bad" site from a client machine. If the problem appears resolved then your server was not the issue, but your DNS forwarders (ISP, etc) were and you've taken them out of the loop.

Good luck.

-Cliff
0
 
LVL 9

Expert Comment

by:Geodash
ID: 37840080
What are your DNS forwarders pointed to?
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I've often see, or have been asked, the question about the difference between the Exchange 2010 SP1 version, available as part of Small Business Server (SBS) 2011, and the “normal” Exchange 2010 SP1 Standard. The answer to the question is relativ…
I’m often asked about newer and larger USB drives connected to SBS2008 and 2011 failing Windows Server Backup vs the older USB drives not failing. As disk space continues to grow and drive technology change SBS2008 and some SBS2011 end up with the f…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
In an interesting question (https://www.experts-exchange.com/questions/29008360/) here at Experts Exchange, a member asked how to split a single image into multiple images. The primary usage for this is to place many photographs on a flatbed scanner…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question