Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

NSLOOKUP works but pinging FQDN does not on WIndows 7 machines

Posted on 2013-10-31
6
2,148 Views
Last Modified: 2013-12-03
Hi All

I have a few machines with strange DNS issues that are also intermittent

Issue

Accessing an internal system jira.mydomain.com normally works OK however on occasions some users reports it fails, if we then try and ping jira.mydomain.com from the users machine it says unable to resolve, if I do an nslookup it resolves fine. If you leave it a while it just starts working again.

My own machine has never had an issue yet we are on the same VLAN and have same DNS servers configured

Steps I have checked so far

DNS servers they get are correct
DNS search suffixes are configured
Firewall is disabled
No obvious errors on DNS servers ( AD integrated Zones )

iconfig /flushdns does not fix


Anyone got any ideas, I see a lot of people report the same issue but cant seem to find a conclusive post with a fix
0
Comment
Question by:ncomper
  • 3
  • 2
6 Comments
 
LVL 24

Expert Comment

by:Sandeshdubey
ID: 39614956
Ensure correct dns setting is set as this http://abhijitw.wordpress.com/2012/03/03/best-practices-for-dns-client-settings-on-domain-controller/

Check the health of DCs by dcdiag /q and repadmin /replsum.When the issue occur check the event log on workstation and server too for any errors and warning and post the same.

I you have antivirus installed disable the same temporarly.
0
 
LVL 39

Accepted Solution

by:
footech earned 500 total points
ID: 39619311
For intermittent issues like this it is almost always due to different DNS servers being used (i.e. it works when one server is queried, but doesn't when another one is queried).  This can happen when a client is configured to use a DNS server inside the network as preferred, and an ISP's or other public DNS server as alternate.  Or if the client is using internal DNS servers for both preferred and alternate, if both servers don't have the same records because there is a problem with replication (assuming the use of AD integrated zones like you mentioned you have), or in different environments with zone transfers, etc.  A network capture when the problem is occurring could tell you exactly which DNS server is being queried.  When you did your nslookup queries, did you try multiple servers?
0
 
LVL 5

Author Comment

by:ncomper
ID: 39638687
Thanks

I have been doing some research and it appears that its a client side issue with the DNS resolver, when doing an nslookup the query is always sent to the DNS server (Which works)

When pinging by fqdn it uses the hosts local cache first and this is where I believe its failing and the request never makes it to the DNS server
0
Resolve Critical IT Incidents Fast

If your data, services or processes become compromised, your organization can suffer damage in just minutes and how fast you communicate during a major IT incident is everything. Learn how to immediately identify incidents & best practices to resolve them quickly and effectively.

 
LVL 39

Expert Comment

by:footech
ID: 39639147
It's true that nslookup uses its own resolver.
Did you do a network capture during a period when the name can't be resolved?
0
 
LVL 5

Author Comment

by:ncomper
ID: 39659698
No that's my next step thanks
0
 
LVL 5

Author Closing Comment

by:ncomper
ID: 39693879
Thanks, after all that it turned out there was a legacy efficient IP box that some users where querying that was missing some A records
0

Featured Post

Back Up Your Microsoft Windows Server®

Back up all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Logon script fails 23 45
AD architecture diagram 5 30
PHP website on Linux - server DNS address could not be found. 18 38
Public DNS  Vs BGP 20 20
Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
This article describes my battle tested process for setting up delegation. I use this process anywhere that I need to setup delegation. In the article I will show how it applies to Active Directory
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

791 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question