Solved

Internal vs External DNS Lookup's

Posted on 2014-10-31
5
469 Views
Last Modified: 2014-11-02
I have a new Bell fibe router which apparently for "Security Reasons" does not support NAT reflection/Loopback.  In that I can no longer internally reach mail.mydomain.com which is a resolvable host NAT forwarded to one of my internal servers on mydomain.local.  To resolve this I have created a DNS entry on my internal DNS server to resolve mail.mydomain.com to the internal IP Address of mailserver.mydomain.local.  For the most part this solution works, however occassionally and seemingly randomly (mostly at initial WS startup) the mail.mydomain.com will internally resolve to the external IP.  NSlookup responds with correct IP Address of the internal host but an internal ping of mail.mydomain.com tries to ping via external IP address.  I have tried ipconfig /flushdns with same result.  This is a major nuisance as it causes Outlook to not be able to connect to our exchange server.

I have "patched" this for the time being by creating a host record on workstations pointing mail.mydomain.com to the internal IP, this solution is a bit of a wank, and obviously will not work for laptops that require access to mail.mydomain.com from both internal and external networks.

Is there a way to diagnose why it is resolving to external IP address and/or on my internal network to force the DNS to resolve to the internal IP address?

DNS search order from DHCP scope to clients is

192.168.135.15 (internal DNS server)
192.168.135.1 (bell fibe router)
8.8.8.8 (google)

Thanks
0
Comment
Question by:BMarden
  • 2
  • 2
5 Comments
 
LVL 7

Expert Comment

by:Stampel
ID: 40415527
Would it be possible to remove 8.8.8.8 from your DNS order scope ?
I guess this entry could be causing the problem and should be useless if your other DNS do the work
0
 
LVL 2

Author Comment

by:BMarden
ID: 40415589
I could as a troubleshooting step, it was added because I noticed that occasionally the router was a bit slow doing DNS request forwards, also the router is forwarding DNS requests to same 8.8.8.8 any hoo, bit I will give it a shot.

Any other feedback?

Thanks
0
 
LVL 7

Expert Comment

by:Stampel
ID: 40415597
It was my best guess i am confident but ...
Does nslookup for mail.mydomain.com respond the same for 192.168.135.15 and 192.168.135.1 dns ?
0
 
LVL 37

Accepted Solution

by:
Neil Russell earned 500 total points
ID: 40415613
You should ONLY have your internal DNS server on the clients. Then set up a forwarder on your internal DNS server to resolve unknow domains. This way your clients will never talk to anything except your internal DNS server and that knows the address of the internal IP
0
 
LVL 2

Author Closing Comment

by:BMarden
ID: 40418285
Thanks, should have thought of that
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Join & Write a Comment

Suggested Solutions

I wrote this article to explain some important DNS concepts that should be known to avoid some typical configuration errors I often see in forums. I assume that what is described here is the typical behavior of Microsoft DNS client. I don't know …
Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now