troubleshooting Question

DNS Server Errors - Zone TrustAnchors secondard, Name Servers, Forwarders

Avatar of jackbenson
jackbensonFlag for United Kingdom of Great Britain and Northern Ireland asked on
Windows Server 2012DNSAzure
7 Comments1 Solution3786 ViewsLast Modified:

I am getting a lot of errors/warnings in the Server 2012 Best Practice Tool for my DNS server.

I have 2 sites:

Local Network:
-- DC/DNS Server1 (win 2012): / fc;1234:5678:9abc::11
-- DC/DNS Server2 (win 2012): / fc;1234:5678:9abc::21
-- DC/DNS Server3 (win 2012):

The errors/warnings i am getting (and there alot):

(1) Zone TrustAnchors secondard servers must respond to queries for the zone
(2) At least one name server in the list of root hiints must respond to queries for the root zone.
(3) At Least one DNS server on the list of forwarders must respond to DNS queries

Zone TrustAnchones secondard server should respond to queries for the zone
Zone TrustAnchones secondard server should respond to queries for the zone
(plus i have this for the following IP addresses: fc00:1234:5678:9abc:a42d:8f0:d407:c572, fc00:1234:5678:9abc:3827:74d2:8c82:c2ca,  fc00:1234:5678:9abc:a157:ec04:1a5f:8b90,  fc00:1234:5678:9abc::6, fc00:1234:5678:9abc:3b32:c635:33e3:52f2,  fc00:1234:5678:9abc::11,  fc00:1234:5678:9abc::17, fc00:1234:5678:9abc::21,  fc00:1234:5678:9abc:d0d0:39d9:1db2:51b5 )

Root hint server must respond to NS queries for the root zone
(i have this for every route hint)

Forwarding server should respond to DNS queries.
(Also the same for

All my computers on my network are confiremd to use as their DNS servers - and every computer can access the internet properly.

When i go into DNS manager - into Root Hints, press edit - it fails to validate the root hint.

what am i doing wrong - the error message i get is:A timeout occured during validation.

i beleive i only have a primary DNS zone that is replicated to my 3 DNS servers.

Forward Lookup Zones

Reverse Lookup Zones: (ipv6 local network range) (ipv5 local network range) (azure network range) (DirectAccess Clients)

can anyone help me out?

many thanks

David Johnson, CD
The More I know, the more I don't know
Join our community to see this answer!
Unlock 1 Answer and 7 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 7 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros