?
Solved

Random DNS issues

Posted on 2014-03-06
12
Medium Priority
?
276 Views
Last Modified: 2014-04-04
We started experiencing some DNS issues in the last couple of weeks.  certain traveling websites will not  come up. The site name resolves but at times it comes up and other times it does not.
We are also not able to ping 4.2.2.2 or do NSLookup.
 Ping and nslookups worked fine until recently.
We recently migrated from one ISP to another and everything worked fine for two weeks after that move.
There no entries on the DC Logs related to dns. Windows firewall has not changed either .
Any suggestions on how to address this issue?
0
Comment
Question by:tips54
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
  • 3
  • +1
12 Comments
 
LVL 13

Expert Comment

by:Santosh Gupta
ID: 39910074
hi, unable to ping the IP 4.2.2.2 mean something wrong with network config or ISP.

1. are you able to ping other DNS IPs like 8.8.8.8 ?
2.  is nslookup working fine for local ips.
3. check your DNS forwarders.
4. check if you are able to access any website.
5. Check your root hints server
0
 
LVL 3

Expert Comment

by:wlacroix
ID: 39910075
I would never use a public dns server unless your out on a public network or wifi. Just my prefrence though.

As for your issue.
If you cant ping 4.2.2.2 try a tracert or monitor it with something like ping plotter.
This is an underlying network issue.

As for DNS, lets get into that:
What is a traveling website? Please be more specific here with URLS if you can.

If your using a local DNS server on your server, it needs to be able to query the outside, check for forwarders on your DNS server. You might have a forwarder for your old ISPs dns there.
I would remove forwarders all together if you have any, they are not necessary in most cases.

I would get your ISPs dns servers and monitor the new line to them, these are "inside" the ISPs network.
Monitor the link between you and your gateway as well.

Lets say you query from your workstation www.myhouse.com
this request goes to your local dns, if your local dns cant resolve it, it has to go upstream, this is very very common. If there is a forwarder that fails, it will most likely time out before it gets a root hint.

If you dont have forwarders and your dns server cant get a root hint it cant resolve the query and will fail.

No there wont be any DNS logs to show this, because its not a server issue, its a query issue and it does not log query issues in most cases, there would be a million entries.


I re-read your whole post, and you say "The site name resolves but at times it comes up and other times it does not"
Does this mean that myhouse.com will always resolve to the IP? Does almost every single site you query come up with the IP every time?

If YES, then you dont have a DNS issue, its something else.

Can you ping routers outside your network by IP?
Can you ping 8.8.8.8?
0
 
LVL 3

Expert Comment

by:wlacroix
ID: 39910092
Oh, on our dns servers I had to reduce scavenging of stale records to 6 hours.
0
Get MongoDB database support online, now!

At Percona’s web store you can order your MongoDB database support needs in minutes. No hassles, no fuss, just pick and click. Pay online with a credit card. Handle your MongoDB database support now!

 

Author Comment

by:tips54
ID: 39910169
Thank you both for the replies.  
I can't ping 8.8.8.8 either.  
wlacroix,

If I enter Avis.com in the we address the tab resolves the name but the site does not come up 90% of the time.
If I ping the site it resolves but no replies.
I do have to forwarders , They are pointing to OpenDNS  which we doe use.  We are not blocking travel category.  I did not enter any DNS information anywhere from the new ISP.
0
 
LVL 13

Expert Comment

by:Santosh Gupta
ID: 39910185
Hi,

you are trying to ping the IP of sites and DNS. To ping with IP doesnot require DNS. what i am thinking may be your firewall/router or ISP is blocking the ping.

please RUN pathping 4.2.2.2 and see where it blocked.
0
 
LVL 3

Expert Comment

by:wlacroix
ID: 39910189
lots of sites wont reply to a ping its normal, be more concerned with the resolution.

If you cant ping 8.8.8.8 that is bad, I would start here and skp the DNS stuff for now.

Grab ping plotter or another software that shows you the visual route.

you can also do a tracert from a command prompt. It will give you an idea where it fails.

8.8.8.8 is public and responds from every site I have ever been on, around the globe.
SO does 4.2.2.2.

Your ISP should also be able to help you.
Can you do a tracert to 8.8.8.8 and post it for me?

Mine looks like this:

See attached
Google-ping-plotter.jpg
0
 
LVL 3

Expert Comment

by:wlacroix
ID: 39910196
You might have huge packet loss on pings, in some cases pings (an ICMP echo) are blocked and you will never get a reply.

If your ISP has one router that is set not to respond it may disrupt every ping downstream of it.
0
 
LVL 3

Expert Comment

by:wlacroix
ID: 39910197
ICMP echos are the very last type of packet to be transmitted by an overloaded router.

Which is funny because they are used so very commonly to tell if a device is active.
0
 

Author Comment

by:tips54
ID: 39910289
ICMP works  on the users networks times out But not on the servers network.  I have the two segmented.
0
 
LVL 13

Expert Comment

by:Santosh Gupta
ID: 39910316
so, where do you face the issue, on server or PCs
0
 
LVL 30

Accepted Solution

by:
masnrock earned 1500 total points
ID: 39914722
Have you checked to see whether your internet connection is working properly? Also try doing a traceroute when you're NOT able to access websites. If it seems to be failing as soon as things leave your network, that is one possibility. If it is failing at your firewall/router, that is another thing you might need to analyze.
0
 

Author Closing Comment

by:tips54
ID: 39979100
This appear to have been an issue with a defective Cisco firewall.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article is a collection of issues that people face from time to time and possible solutions to those issues. I hope you enjoy reading it.
This program is used to assist in finding and resolving common problems with wireless connections.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…
Suggested Courses

800 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question