Child Domain Cannot Ping Parent

I have a situations where we had a child DC go down and has to be rebuilt from scratch It was configured by the previous Network Admin a long time ago and there is zero info on how it was configured previously so it was lost with the system crash.  

So we have 2003dc and 2008dc let's say in the parent.com domain in the 192.168.0.x scope.  The child domain was in child.parent.com domain in the 192.170.0.x scope.  Nested in the parent.com DNS forward lookup zone I have a zone for child.parent.com with records for the child DC child.parent.com and I am able to ping the child DC.  I cannot ping either  2003dc.parent.com or 2008dc.parent.com.  The ip addresses of the two parent.com dc are in the fowarders for the child.parent.com domain but I still cannot ping or contact them either by ip or hostname.  I've tried adding a secondary zone and a stub zone but it's unable to validate the host/ip address.  Hopefully what was clear, any help would be appreciated.

Thanks,
Ronnie
nbccitAsked:
Who is Participating?

Improve company productivity with a Business Account.Sign Up

x
 
DrDave242Connect With a Mentor Commented:
The ip addresses of the two parent.com dc are in the fowarders for the child.parent.com domain but I still cannot ping or contact them either by ip or hostname.
Putting the parent DCs in the forwarders for the child DC was correct, but if you can't ping the parent DCs by IP address, nothing you do in DNS will help.  It sounds like there's a more general network connectivity issue.  Is there a firewall between the child DC and parent DCs that could be blocking the ping traffic?
0
 
AlexiosCommented:
Hello
Your first step regarding DNS is correct, you also have to add a secondary ip to your servers. An ip from the other scope

Right click on Network icon on the Taskbar and then select Status. Then in the Status window, click on Properties. You can also open the Properties window from the Control Panel and then Network Connections and right click on the network icon and select Properties.

Then select the Internet Protocol (TCP/IP) and then click on Properties button. Then in this Properties Window, click on Advanced button and then in the IP Settings tab, click on Add button under IP addresses and add the IP address whatever you want.
advanced-tcpip-settings.png
0
 
nbccitAuthor Commented:
I've added an ip from the 192.168.0.x range from the parent domain in the Advanced IP Settings on Child DC  NIC and still no go on the ping ip/host.
0
Easily Design & Build Your Next Website

Squarespace’s all-in-one platform gives you everything you need to express yourself creatively online, whether it is with a domain, website, or online store. Get started with your free trial today, and when ready, take 10% off your first purchase with offer code 'EXPERTS'.

 
ChiefITConnect With a Mentor Commented:
Is your firewall blocking Ping (ICMP echo reply)?

Ping doesn't necessarily work because of firewall blocks and ACLs on the router.
0
 
nbccitAuthor Commented:
I'll have to check in the morning but I've mirrored what the crashed dc settings where as far as I know, same child domain name, same server name, and same ip addresses.  So I would think that any firewall or router settings wouldn't be an issue.
0
 
DrDave242Connect With a Mentor Commented:
When you try to ping a parent DC from the child DC, does it simply time out or give you some other kind of error, like "Destination host unreachable" or something like that?
0
 
nbccitAuthor Commented:
It ended up being a firewall issue, we have a third party that manages our firewall and come to find out we are purposefully blocking traffic from child to parent.  Thanks for pointing me in the right direction of where to look.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.