Solved

DNS stub zones Windows server 2008 and 2003, constant event id 6522 but nothing loads

Posted on 2014-11-03
11
624 Views
Last Modified: 2014-11-06
I am going through a email hosting setup.  I've been having problems with them and currently we are in the classic "its you" debate.  They require us to allow them access to our AD/DNS so they can create a Stub Zone.  Since we are back and forth I've started to duplicate their steps in hope I can find where the issue is.  There are a few questions and maybe they are all related.  At least I hope.  

I've setup my home router to allow all DNS traffic 53 (udp/tcp) to my home environment (dubbed home.local domain which is a 2008 Server R2).  I created a stub zone in the work environment (dubbed work.local domain which is a 2003 Server) and I am able see my home.local and all NS records via the DNS mmc in the work environment.  However I cannot ping the FQDN of my home.local AD/DNS server from work.local.   I can see the DNS records of a stub zone in the DNS mmc but no ping resolve to the FQDN of the home.local AD/DNS in my work.local domain.  Any ideas?  

Now on the other side of the testing the reason I'm going through all this, I tried the reverse and I was able to create a stub zone of my work.local in my home.local AD/DNS BUT I never get the stub zone to load the records of the work.local AD/DNS domain even in the mmc.  Event logs keep saying 6522 "new zone work.local found" "transferring zones" but it's been saying that for hours now and the event 6522 keeps being recorded and piling up.  Any ideas?

steps I've tried to resolve this;
I've went through adsi edit already to remove any CNF.
I've allowed zone transfers on both side; single and any
0
Comment
Question by:jo80ge121
  • 6
  • 5
11 Comments
 
LVL 39

Expert Comment

by:footech
ID: 40421306
In the stub zone home.local what are the records like?  Do they point to public IPs?
I suggest you test with nslookup to verify that the records are resolving correctly.  Then you can use ping, but keep in mind that ICMP traffic has to be allowed as well.

Just troubleshoot one side to avoid confusion.

Zone transfers are not required for stub zones, only for secondary.  But as I said, let's just focus on the other side.

I can't imagine a hosting scenario where they need access to your internal DNS.  Maybe you should just describe the root problem that you're trying to solve.
0
 

Author Comment

by:jo80ge121
ID: 40421842
Ok. lets keep the focus on one side.  A stub zone will not load work.local on my home AD/DNS home.local.  

In the stub zone of my work.local in my home.local AD/DNS I have nothing but an Error saying "Zone Not Loaded by DNS Server"  I was getting event 6522 all day yesterday with nothing to show for it on my DNS mmc now I'm seeing a event 6523 "Zone work.local failed zone refresh check" from late last night till early morning.  

NSlookup fails when I try to query NS records in my home.local domain of the stub zone work.local
I've done this;

nslookup
set type=ns
work.local

then I get error outs.  cannot find.  

The root problem I'm having is our hosting site requires access to our NS records via stub zone(for what I'm not sure) and cannot continue with out it.
0
 
LVL 39

Expert Comment

by:footech
ID: 40424859
It'll be easier to focus on the other side (your work domain where you have a home.local stub), as this appears to already be set up.
In the stub zone home.local what are the records like?  Do they point to public IPs?

Your hosting site should be able to clearly explain why they need access.  It is unusual for a third-party company to need access to internal records, or maybe I am misunderstanding their request.  Do they want you to create a stub zone on your DNS that points at their name servers, or do they want to create a stub zone on their own DNS which pulls from your name servers?
0
 

Author Comment

by:jo80ge121
ID: 40424901
from the stub zone home.local in the work domain I see NS records that point to my internal IP's of my home domain.  No public.  

I will ask my hosting site why they need access.  They want to create a stub zone on their own DNS which pulls from my work.local name servers.
0
 
LVL 39

Expert Comment

by:footech
ID: 40426726
Make sense.  I assume that when you were creating the stub zone that you had to put in the public IP of your home network as the master server.
Can you try an nslookup command for a record which should be in the home.local DNS?  This should work.
But unless you have something like a direct VPN tunnel between the networks with appropriate routing, you won't be able to ping those private addresses from your work network.
0
Too many email signature changes to deal with?

Are you constantly being asked to update your organization's email signatures? Do they take up too much of your time? Wouldn't you love to be able to manage all signatures from one central location, easily design them and deploy them quickly to users. Well, you can!

 

Author Comment

by:jo80ge121
ID: 40426784
Yes I used one available public IP that I NAT'd to my home AD/DNS server but I'm not able to successfully test nslookup in my work.local to a record in the home.local even though the stubzone appeared to load correctly.  Not sure why.  

nslookup
set type=ns
home.local
0
 
LVL 39

Expert Comment

by:footech
ID: 40427138
You might try setting debug mode in nslookup (set debug), and also using a trailing dot for queries of a FQDN (complete name).
Other that, I would do a network capture and look at DNS traffic. That's about all I can suggest.
0
 

Author Comment

by:jo80ge121
ID: 40427268
Footech - don't give up on me yet :)

I made some headway which now created another question.  During the test I opened ports 53, 389 and 3268 both TCP/UDP from the home.local firewall to the internal AD/DNS and I was having these issues.  When I opened ALL ports to my home AD/DNS and reloaded my stub zone I am now able to query the home.local stub zone from my work domain.   NSLOOKUP worked.  Other than 53 is there any other ports I should consider to allow for stub zone to work across the internet?
0
 
LVL 39

Accepted Solution

by:
footech earned 500 total points
ID: 40427581
You should only need UDP and TCP port 53.  Typically DNS queries are made using UDP 53, and can fall back to TCP 53 if unsuccessful.  Zone tranfers are made with TCP 53, and so are the queries to populate a stub zone.  Failure to populate a stub zone I think would most likely be due to blocking TCP 53.

Perhaps it's a matter of your home firewall/router not behaving as it should.  I know I've encountered that before (not matching this scenario though).
0
 
LVL 39

Expert Comment

by:footech
ID: 40427598
One more thing, you might try the following (from the work network).
nslookup
set vc
          <-- this will force nslookup to use TCP
server x.x.x.x   <--use the public IP of your home
whatever.home.local.
See if the query is successful (should be with your latest success).  Then if you set the home firewall back to just allow TCP and UDP 53, perform the steps again and observe the results.
0
 

Author Closing Comment

by:jo80ge121
ID: 40427760
Thank you for the time.  It must be the settings in the work.local firewall/router.  I am able to successfully connect via stub dns from my work.local to my home.local (home.local firewall is a basic Cisco RV small business model) but not through the 2911 cisco series at the business hub site.  I'm going to get a second opinion on my firewall/router settings.
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

Suggested Solutions

OfficeMate Freezes on login or does not load after login credentials are input.
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now