?
Solved

Split DNS Can't get to hosted company site

Posted on 2014-01-27
5
Medium Priority
?
284 Views
Last Modified: 2014-02-25
I'm having a problem with getting to the company website from inside the local network. I currently have DNS setup with the following:

A contoso.com (DC IP's)
A www.contoso.com (Outside IP Of hosted website)
A www.contoso.com (Seconday Outside IP Of hosted website)


I then have IIS setup on my two DC's to forward to http://www.contoso.com

Neither www.contoso.com or contoso.com work from inside the network. I followed the walkthrough here: http://msmvps.com/blogs/acefekay/archive/2009/09/04/split-zone-or-no-split-zone-can-t-access-internal-website-with-external-name.aspx

if I run NSLookup on www using my local DNS servers I get the same thing as when I use google servers.

I do not understand why at least www.contoso.com wouldn't work.

Thanks,
0
Comment
Question by:Brohodin
  • 3
  • 2
5 Comments
 
LVL 41

Accepted Solution

by:
footech earned 2000 total points
ID: 39813784
What result do you get when you try to browse there from inside your network?
Any chance the hosted provider is blocking your IP?  I've seen that before...
Have you done a network capture?
0
 

Author Comment

by:Brohodin
ID: 39814128
I'm just getting a generic "IE Cannot display this page when browsing http://www.contoso.com 

The provider isn't blocking our IP. The previous tech edited host files as a workaround.

I haven't done a network capture. I honestly wouldn't know what to look for since DNS is resolving correctly through nslookup.
0
 
LVL 41

Expert Comment

by:footech
ID: 39814391
If the page loads correctly when you have a HOSTS file entry, then I would certainly do a network capture without the entry when trying to reach the site.  Nslookup uses a different resolver than that used by the rest of Windows programs.  The capture might reveal some different information.  If the site accepts pings, you could also try pinging it by name and seeing what IP it returns.
0
 

Author Comment

by:Brohodin
ID: 39814394
Pinging resolves correctly. I'll run a capture tomorrow when I have access to more than a domain controller for poking

Thanks!
0
 

Author Comment

by:Brohodin
ID: 39886459
Finally was able to get onsite and found that it was a resolve loop between the iis servers and outside domain. Web Dev team says they can't help resolve the issue and they must have external requests to www.contoso.com forwarding to contoso.com which is of course the opposite of what I want inside so we'll likely be migrating to a new internal domain name. Can't wait! Thanks!
0

Featured Post

SMB Security Just Got a Layer Stronger

WatchGuard acquires Percipient Networks to extend protection to the DNS layer, further increasing the value of Total Security Suite.  Learn more about what this means for you and how you can improve your security with WatchGuard today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Understanding the various editions available is vital when you decide to purchase Windows Server 2012. You need to have a basic understanding of the features and limitations in each edition in order to make a well-informed decision that best suits …
A procedure for exporting installed hotfix details of remote computers using powershell
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

621 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question