Solved

DNS Best Practices Analyzer error

Posted on 2013-05-29
5
4,643 Views
Last Modified: 2017-04-25
Hi Experts,

I have installed two Windows Server 2012 DCs in a new forest, single domain. Both are configured as DNS servers (AD-integrated).

On one of the servers, the DNS BPA reports the following:


Warning     DNS: Zone TrustAnchors secondary server 192.168.1.123 should respond to queries for the zone.
The secondary DNS server 192.168.1.123 does not respond to queries for the zone TrustAnchors.

Error     DNS: Zone TrustAnchors secondary servers must respond to queries for the zone.
None of the secondary servers configured for zone TrustAnchors are responding.


Can anyone tell me what this error means and how we can resolve it?

DNS appears to be working perfectly fine on both servers but I would like a clean BPA result.

Thanks,
James
0
Comment
Question by:failed
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 14

Expert Comment

by:Ben Hart
ID: 39204355
0
 
LVL 19

Expert Comment

by:Kash
ID: 39204358
looks like you have some configuration issues >>> http://technet.microsoft.com/en-us/library/ff807384%28v=ws.10%29.aspx

go to zone transfers tab on both the server mainly the primary one and make sure the IP address of the secondary server is right to start with and troubleshoot accordingly
0
 

Author Comment

by:failed
ID: 39204400
Hi ubadmin,

I went through that article but it did not resolve my problem.

Hi innocentdevil,

I don't have any IP addresses in Zone Transfers therefore that article does not help I'm afraid. These are AD-integrated DNS servers and therefore do not require permission to transfer zones as far as I am aware.
0
 
LVL 26

Accepted Solution

by:
DrDave242 earned 500 total points
ID: 39205233
Are you using DNSSEC in any way?  If not, the TrustAnchors zone isn't used for anything, and the BPA result can be ignored.
0
 

Author Comment

by:failed
ID: 39206951
Hi DrDave242,

We are not using DNSSEC, and what you've said there supports what I've read during my research in to the issue, so I'm going to ignore it since DNS appears to be working normally.

Cheers,
James
0

Featured Post

What Is Transaction Monitoring and who needs it?

Synthetic Transaction Monitoring that you need for the day to day, which ensures your business website keeps running optimally, and that there is no downtime to impact your customer experience.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Group policies can be applied selectively to specific devices with the help of groups. Utilising this, it is possible to phase-in group policies, over a period of time, by randomly adding non-members user or computers at a set interval, to a group f…
After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
In this Micro Tutorial viewers will learn how they can get their files copied out from their unbootable system without need to use recovery services. As an example non-bootable Windows 2012R2 installation is used which has boot problems.
In this Micro Tutorial viewers will learn how to use Boot Corrector from Paragon Rescue Kit Free to identify and fix the boot problems of Windows 7/8/2012R2 etc. As an example is used Windows 2012R2 which lost its active partition flag (often happen…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question