Solved

LAN Clients being blocked from one site only

Posted on 2015-01-07
10
177 Views
Last Modified: 2015-01-13
We have one particular website that our client computers that are inside our network are now being blocked from(Which is to say that they just won't load - No error codes). The site has always loaded but suddenly stopped. This site can be accessed via other networks outside of our LAN with no issue. It's just one site but it's a webhosting site so we cannot login from the office to manage our websites so it's important to us. There were no changes on any server or firewall. We can get to all other websites but this one.



Environment:
DNS Server: Small Business Server 2008 - This is the only DNS server and is the only computer that can still access the site in question
steps taken:
-Checked DNS Config - using forwarders to the ISP DNS servers. It's been working for over 5 years
-Cleared DNS Cache
-Restarted DNS Service
-Restarted Server
-Ran the "fix my network" wizard from the SBS console but it didn't find anything to fix

Clients: Windows 7 Pro and MAC OSX
steps taken:
-Configured properly to the local DNS Server via DHCP or Manually configured IP but no go
-DHCP working properly
-Flushed DNS
-Checked Windows firewall - configured for DNS
-Uninstalled Antivirus

ISP
steps taken:
-Opened a ticket and they checked their end out and it was clear
-Unplugged our firewall appliance from the ISP equipment and replaced it with just a laptop configured with the ISP addressing and the site worked.

Gateway(Firewall Appliance Sonicwall NSA)
steps taken:
-Verified that the DNS server itself which has the same addressing as the clients can access the site and it does.
-Checked logs - no indication of the site being blocked. These servers are in the USA and we don't content filter anything from the USA but went ahead and made this site a safe site but still no go.
-Went ahead and made a rule to allow traffic to this domains address but still no go

: It seems to be an issue with the DNS server service itself but I cannot find anything wrong. The clients can get to all other websites but only the DNS server itself can get to this one website(netjelly.com)

Any insight would be appreciated.
0
Comment
Question by:PapaLuciani
  • 4
  • 4
  • 2
10 Comments
 
LVL 77

Expert Comment

by:arnold
ID: 40537176
Here is the difficulty in answering your question.
Without the site ...


What you need to look on your router is to trace the route to the host?
Is this site accessible off site?

Use external traceroute.org to see if it can see the path.
Any changes on your ISP external connection prior to when this issue began, I.e. Your router has a routing policy to send requests for this site via a route that no longer exists. Your IPP changed and access is IP based.

Look at your routers routing table to make sure there is no issues there.
If this is a secure site, you may have packet size that fragments which is not ssl compliant in some cases,
Packet capture to see whether responses are received but the issue is with the web browser not being able to display an updated version.........
0
 

Author Comment

by:PapaLuciani
ID: 40537206
Arnold, thanks for the info. The website(Netjelly.com) works fine outside of our network. from inside our network the site will load from one node and that's the DNS server itself. All the clients that look to that server for DNS can no longer load the website. I can nslookup from both the clients and the dns server and get the right info. The tracert is over 30 hops but like I said the DNS server itself can still load this site. I can take my laptop from work home or another network and the page will load fine. It's just inside our LAN it seems to be a problem.
0
 
LVL 77

Expert Comment

by:arnold
ID: 40537214
Compare the traceroute from the working server to the ones that do not.

Do you have a single or multiple external connections?
Whatismyip.com from DNS sever and one of the non-working systems.
Do you have a proxy server through which all workstations go but the DNS server goes out directly?
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 20

Expert Comment

by:carlmd
ID: 40537646
Are you using the SPAM service or RBL's on the Sonicwall?
0
 

Author Comment

by:PapaLuciani
ID: 40537887
We only have one external IP for WAN traffic. The DNS server that can load the site has the same configuration for network addressing that the clients(which cannot load this site) do. Traffic goes straight to the firewall and out the WAN interface via the same external IP. Not using the SPAM service on the FW. RBLs we do filter out some sites but not this one.
0
 
LVL 77

Expert Comment

by:arnold
ID: 40537959
The issue is not inside the LAN since you say the DNS server which is presumably on your LAN is not having this issue.

Could you double check the browser configuration on the workstations for users and the one on the DNS server to make sure one does not go through a proxy or is more restrictive than the other.
Presumably your DNS server has a static IP on the LAN, your LAN,firewall, proxy might exempt the statically assigned IP block (servers, etc.) from the DHCP assigned user space which is the only possible thing I can see at this time.

One WAN, single LAN space, one DNS server has no issue accessing site, all workstations can not access/display site.

If you want to try the IP check, have one workstation that can not access site, use a static IP within the same range as one used by the DNS server. and see if the issue clears up. If it does, you need to look at your proxy or firewall rules to see the rule that matches this domain or the Ip range.

See if you can browse to a site dvl.com within the same IP space as netjelly.com one is 233 the other is 234.
If the issue DNS can, workstations can't your issue is likely IP range restrictions.
presumably your LAN ips do not use 216.245.199.0/24 IP space.
Try accessing by IP .233 for netjelly.
0
 
LVL 20

Expert Comment

by:carlmd
ID: 40537969
When the site won't load from a client using the URL, have you tried loading it using the ip address (216.245.199.133)?

Also, as an exercise when it is not loading from a client using your internal dns server, change the dns setting to google public dns servers (8.8.8.8 and 8.8.4.4) and see what happens.

Post back with the results.
0
 

Accepted Solution

by:
PapaLuciani earned 0 total points
ID: 40539088
Thank you for your efforts. I took a shot and asked the web team to open a ticket with that site's support team and their FW was stopping us from getting to the webservers. Chalk one up to Tracert. Thanks Again
0
 
LVL 77

Expert Comment

by:arnold
ID: 40539164
I believe you received assistance to get to the point reaching out. Ref. DNS server and non working System inquiry about IPs. As well as traceroutes.
0
 

Author Closing Comment

by:PapaLuciani
ID: 40546218
We resoled this issue internally
0

Featured Post

3 Use Cases for Connected Systems

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, testing some more, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Small Business Server 2012 Essentials 5 56
Query Computer names and description using dns 14 29
Expanding Subnet Mask 20 105
Exchange 2010 Autodiscover for iOS devices 4 42
One of the most often confused topics in the area DNS is the idea of GLUE records. Specifically, what they are, when they are needed, when they are provided, and how they are created. First, WHAT IS GLUE? To understand GLUE, you must first under…
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
This Micro Tutorial demonstrates using Microsoft Excel pivot tables, how to reverse engineer competitors' marketing strategies through backlinks.
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question