Solved

Internal vs External DNS Lookup's

Posted on 2014-10-31
5
483 Views
Last Modified: 2014-11-02
I have a new Bell fibe router which apparently for "Security Reasons" does not support NAT reflection/Loopback.  In that I can no longer internally reach mail.mydomain.com which is a resolvable host NAT forwarded to one of my internal servers on mydomain.local.  To resolve this I have created a DNS entry on my internal DNS server to resolve mail.mydomain.com to the internal IP Address of mailserver.mydomain.local.  For the most part this solution works, however occassionally and seemingly randomly (mostly at initial WS startup) the mail.mydomain.com will internally resolve to the external IP.  NSlookup responds with correct IP Address of the internal host but an internal ping of mail.mydomain.com tries to ping via external IP address.  I have tried ipconfig /flushdns with same result.  This is a major nuisance as it causes Outlook to not be able to connect to our exchange server.

I have "patched" this for the time being by creating a host record on workstations pointing mail.mydomain.com to the internal IP, this solution is a bit of a wank, and obviously will not work for laptops that require access to mail.mydomain.com from both internal and external networks.

Is there a way to diagnose why it is resolving to external IP address and/or on my internal network to force the DNS to resolve to the internal IP address?

DNS search order from DHCP scope to clients is

192.168.135.15 (internal DNS server)
192.168.135.1 (bell fibe router)
8.8.8.8 (google)

Thanks
0
Comment
Question by:BMarden
  • 2
  • 2
5 Comments
 
LVL 7

Expert Comment

by:Stampel
ID: 40415527
Would it be possible to remove 8.8.8.8 from your DNS order scope ?
I guess this entry could be causing the problem and should be useless if your other DNS do the work
0
 
LVL 2

Author Comment

by:BMarden
ID: 40415589
I could as a troubleshooting step, it was added because I noticed that occasionally the router was a bit slow doing DNS request forwards, also the router is forwarding DNS requests to same 8.8.8.8 any hoo, bit I will give it a shot.

Any other feedback?

Thanks
0
 
LVL 7

Expert Comment

by:Stampel
ID: 40415597
It was my best guess i am confident but ...
Does nslookup for mail.mydomain.com respond the same for 192.168.135.15 and 192.168.135.1 dns ?
0
 
LVL 37

Accepted Solution

by:
Neil Russell earned 500 total points
ID: 40415613
You should ONLY have your internal DNS server on the clients. Then set up a forwarder on your internal DNS server to resolve unknow domains. This way your clients will never talk to anything except your internal DNS server and that knows the address of the internal IP
0
 
LVL 2

Author Closing Comment

by:BMarden
ID: 40418285
Thanks, should have thought of that
0

Featured Post

Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Macbook Sierra OS OpenVPN issue 13 113
DNS Settings for Domain controllers 22 133
Cisco ASA dns and browsing 20 48
Need help on Windows Firewall blocking program 7 46
One of the most often confused topics in the area DNS is the idea of GLUE records. Specifically, what they are, when they are needed, when they are provided, and how they are created. First, WHAT IS GLUE? To understand GLUE, you must first under…
The Need In an Active Directory enviroment, the PDC emulator provide time synchronization for the domain. This is important since Active Directory uses Kerberos for authentication.  By default, if the time difference between systems is off by more …
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

831 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question