• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 412
  • Last Modified:

Outgoing DNS not resolving

I have a system where none of the windows servers can resolve dns. I've turned off the firewall completely. I am helping out a friend who has just taken over IT for this company.

I added a windows 2008 R2 to the domain but after I ran dcpromo it could no longer resolve ip addresses. Internal DNS server is started but it can't see root servers or forwarders.

I can't find a group policy that has anything to do with dns on the domain. I'm wondering if some how someone changed the outoing dns port but only on the servers. The workstations all resolve names just fine.

I icon in the systray for a network connection shows a yellow exclamation point because it can't get the net. nslookup doesn't work either. It shows the local dns server but it won't resolve anything. I can ping IPs on the net.
0
jasonslogan
Asked:
jasonslogan
  • 4
  • 3
  • 2
  • +2
1 Solution
 
bartsmitCommented:
Open a command prompt and type:

nslookup www.google.com. 8.8.8.8

That should come back with a handful of IP addresses.

If not, check the Internet firewall and make sure that both TCP port 53 and UDP port 53 are allowed out.
0
 
Mike KlineCommented:
Are you using forwaders or root hints to resolve internet queries?  What do you mean it can't see forwarders?  

Thanks

Mike
0
 
jasonsloganAuthor Commented:
nslookup doesn't resolve any dns from localhost or an external dns server like the ones that I use as forwarders. I tried googles and opendns'.

It's as if the udp port 53 is not really what it's trying to connect to. 53 is not being blocked because, as I said before, the firewall is off.
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell┬« is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
ktaczalaCommented:
are you able to ping external IP's?  what does ipconfig /all show?
0
 
jasonsloganAuthor Commented:
ipconfig /all shows everything normal including the dns servers.  I am able to ping any ip just not connect on port 53 on dns servers.

This is ridiculous. There is nothing blocking anything. I know it started when I promoted it so I think it's a group policy but I can't find that either in the list.
0
 
Netman66Commented:
Do you have the root zone in your DNS (the ".")?  If so, remove that.

What the root zone does it tell DNS you are authoritative for all DNS resolution.  Not even forwarders or root hints will work.
0
 
jasonsloganAuthor Commented:
I don't have the . root zone. I've done that before 14 years ago and learned that lesson.
0
 
Netman66Commented:
Lol, I think we all have been caught at some point.

Do any of the tests from the DNS console work?  Recursive, non-recursive?
0
 
ktaczalaCommented:
try this:
On the server: open cmd prompt as administrator

first:
On the server: netstat -an |find /i "listening"
is port 53 listed?

Second:
from a workstation: open cmd prompt as administrator
Telnet servername  53
you should get cursor in upper left corner nothing else if port 53 is getting to the server.
Telnet 8.8.8.8 53
you should get cursor in upper left corner nothing else if port 53 is getting out to the internet.

Third:
From the server: open cmd prompt as administrator
Telnet 8.8.8.8 53
you should get cursor in upper left corner nothing else if server port 53 is getting out to the internet.
If you get can't connect then yes something is blocking port 53.
0
 
jasonsloganAuthor Commented:
None of this worked so it led me to the switches but they weren't blocking port 53. Which led me to the router/firewall. It was blocking 53 outgoing.
0
 
ktaczalaCommented:
Super.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

  • 4
  • 3
  • 2
  • +2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now