Solved

Windows 2008 DNS recursive failure

Posted on 2013-11-21
11
510 Views
Last Modified: 2014-04-10
Simple query passes while recursive fails. seems that DNS CAN be resolved, just refuses to show in DNS properties monitoring tab

tried with and without forwarders. nslookup from server works when using local server DNS and google's public DNS.

when using local server DNS nslookup to www.microsoft.com regularly fails on first attempt

when recursion is disabled monitoring on the server is responding to both simple and recursive.

windows small business server 2011 standard sp1
0
Comment
Question by:tetrauk
  • 5
  • 3
  • 2
  • +1
11 Comments
 
LVL 35

Expert Comment

by:Cris Hanna
ID: 39668129
Do you have DNS forwarders set up or using root hints?
There is a known issue if you only use root hints
0
 
LVL 45

Expert Comment

by:Craig Beck
ID: 39668158
Yes if you only use root hints you'll see this behaviour.  Similarly if your DNS server uses external forwarders but a firewall is blocking traffic, for example, you'll also experience recursive failures.
0
 
LVL 1

Author Comment

by:tetrauk
ID: 39668307
We have tried with forwarders and with Root hints.

Both have the same issue, It cant be a Firewall issue as i can nslookup to 8.8.8.8 fine.
0
 
LVL 45

Expert Comment

by:Craig Beck
ID: 39668561
It may be a firewall issue even if you can nslookup to 8.8.8.8.

DNS Server uses TCP ports as well as UDP ports.  Client lookups generally only use UDP.  Therefore if your firewall is only allowing UDP port 53 outbound, but blocking TCP port 53, you'll fail recursive lookups.
0
 
LVL 1

Author Comment

by:tetrauk
ID: 39669128
we have no blocking of any outbound connections on the router/firewall (draytek 2830)
0
What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

 
LVL 45

Expert Comment

by:Craig Beck
ID: 39669163
What about the firewall on the server itself?
0
 
LVL 1

Author Comment

by:tetrauk
ID: 39669353
No. the firewall on the server is deactivated.
0
 
LVL 1

Expert Comment

by:superjohnbarnes
ID: 39802663
Did you manage to solve this?  I have a similar issue on windows server 2008 with Draytek router.
0
 
LVL 1

Author Comment

by:tetrauk
ID: 39881961
Still having this issue, we also use draytek routers and i'm wondering if this is an issue with draytek i have had previous issues with draytek and dns
0
 
LVL 1

Accepted Solution

by:
superjohnbarnes earned 500 total points
ID: 39881980
I think that the draytek is the main contender for DNS issues.  We use them heavily across our infrastructure and the DNS often falls over.  A reboot of the router works most times.

We are looking to move away from Draytek routers in the near future.
0
 
LVL 1

Author Closing Comment

by:tetrauk
ID: 39991120
*
0

Featured Post

Too many email signature changes to deal with?

Are you constantly being asked to update your organization's email signatures? Do they take up too much of your time? Wouldn't you love to be able to manage all signatures from one central location, easily design them and deploy them quickly to users. Well, you can!

Join & Write a Comment

I've written instructions for one router type, but this principle may be useful for others of the same brand and even other brands of router. Problem: I had an issue especially with mobile devices that refused to use DNS information supplied via…
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now