Solved

exchange nslookup query

Posted on 2014-04-14
8
320 Views
Last Modified: 2014-04-23
hi I am currently running exchange 2003 and my firewall is isa 2006

I have inbound & outbound for smtp already set via my isa 2006

I can successfully run 'recursive' test successfully

I have the default gateway set on all my machines

my isa has 2 nics separating both internal & external but on my internal nic pointing to
my local lan I have not added a default gateway as it gets the required info through my domain dns

I have tried to do the following:

nslookup
my local dns shows here as I think expected
type=mx yahoo.com

dns request timeout etc

question 1.  how do I resolve this issue

note: I will be upgrading my exchange server but just want to know how to resolve this issue
you are changing too many settings and do not concentrate on the main problem: name resolution (dns).  as long as nslookup fails on your exchange server no mail will be sent.
0
Comment
Question by:mikey250
8 Comments
 
LVL 23

Accepted Solution

by:
Coralon earned 500 total points
Comment Utility
Did you type it in exactly as shown?
Normally, you would set the type and then do the lookup.

Here is an example copied from my own machine
C:\Windows\system32>nslookup
Default Server:  <homedns>
Address:  <homedns_ip>

> set type=MX
> yahoo.com
Server:  <homedns>
Address:  <homedns_ip>

Non-authoritative answer:
yahoo.com       MX preference = 1, mail exchanger = mta7.am0.yahoodns.net
yahoo.com       MX preference = 1, mail exchanger = mta6.am0.yahoodns.net
yahoo.com       MX preference = 1, mail exchanger = mta5.am0.yahoodns.net

Open in new window


I did try it as you typed it, and I got different results.. I got some IP addresses, and then a timeout.  My guess is that the way you are doing it is doing multiple lookups and some of it is failing.  I got similar results when I tried your format for google.com & outlook.com.

Retest it with the single line lookups and see if you still get failures.  If you do, then you need to look at your routing tables on the ISA server.  It sounds correct that your default gateway would be on the WAN side.  You would not want to add a second default gateway (big no no that Windows will let you do, but will cause problems).  

Coralon
0
 
LVL 26

Expert Comment

by:Leon Fester
Comment Utility
Does nslookup work from any other machine on your network or is it only the Exchange server that is giving problems?

If all workstations/servers are affected then check if you have DNS forwarding configured on your DNS server.

Also check your ISA firewall to see if DNS requests are being blocked by the firewall.
Did anything change recently e.g. did you change ISP's?
0
 
LVL 35

Expert Comment

by:Bembi
Comment Utility
Keep your ISA into account- What said before is correct, so take care of the right format and see if other machines can use nslookup against external targets.

ISA may block the request, bit this you can see, if you just have a look into the life monitoring of ISA to see, if some of the requests are blocked.

So make sure that either your exchange, or if exchange is using internal DNS servers yur DNS server is allowed to make DNS request on port 53 to the internet.
0
 

Author Comment

by:mikey250
Comment Utility
apologies for not getting back asap.  I will test the advice given tomorrow and respond back in the morning.

im sure when I did try it on other machines it still did not work but did work obviously on my isa 2006 firewall as it is also on the wan side, so I assumed the isa 2006 needed some firewall policy to allow this.

as for the 'forwarders' tab I have not added any new entries other than the default settings and obviously my master dc dns ip address that is automatically added.

my recursion works from my master dc/dns properties.

much appreciated
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 23

Expert Comment

by:Coralon
Comment Utility
Did you set your DNS up as a Root server, or do you have the Root Hints enabled?

Coralon
0
 

Author Comment

by:mikey250
Comment Utility
afternoon, my master dc/dns/dhcp is a root server and yes there is a 'root hints' tab that I never touch.

I also carried out your previous: nslookup example and yes I got yahoo.com results via my exchange 2003 server, win 7 laptop, master dc successfully.

so all appears ok now as far as this: nslookup goes so I can now allocate points.

much appreciated
0
 
LVL 23

Expert Comment

by:Coralon
Comment Utility
There ya go :-)  Don't forget your point allocation :-)

Coralon
0
 

Author Closing Comment

by:mikey250
Comment Utility
due to this being the 1st response and the exact requirement to resolve problem due to my syntax method it made sense to allocate all points to this expert.  much appreciated.
0

Featured Post

Don't lose your head updating email signatures!

Do your end users still have the wrong email signature? Do email signature updates bore you or fill you with a sense of dread? You can make this a whole lot easier on yourself by trusting an Exclaimer email signature management solution. Over 50 million users do...so should you!

Join & Write a Comment

OfficeMate Freezes on login or does not load after login credentials are input.
Marketers need statistics and metrics like everybody else needs oxygen. In this article we explain how to enable marketing campaign statistics for Microsoft Exchange mail.
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now