Problem with DNS Publishing
From: Ryan Gregg (ryan_at_ryangregg.com)
Date: 03/19/04
- Previous message: Akhil: "Login problem"
- Next in thread: J.C. Hornbeck [MSFT]: "Re: Problem with DNS Publishing"
- Reply: J.C. Hornbeck [MSFT]: "Re: Problem with DNS Publishing"
- Messages sorted by: [ date ] [ thread ]
Date: Thu, 18 Mar 2004 18:06:51 -0600
I'm running into all sorts of problems with DNS publishing, and I'm hoping
someone here can help me.
I've got ISA 2000 w/ SP1&FP1 running on a Windows 2003 Server box, dual
homed with three external IP addresses. The primary address on the box is
.81. I have publishing rules configured to allow DNS Query Server and DNS
Zone Transfer both using the .81 address for the external, and the IP of the
DNS server for the internal addresses (a separate box from the ISA server).
I also have setup IP Packet filter rules to allow DNS query and domain
transfer packets in either direction.
When I first set everything up, I wasn't have any problems. From outside the
ISA server I could do an nslookup of a domain on the DNS server using the
.81 address, and it would return the results. However, after letting it run
overnight, in the morning I was unable to query the DNS server. If I fiddle
with the connection some more, not really changing anything, then I can get
it to work again for a short period of time, but it always reverts back to
not working. I'm really stuck on the issue, and I can't figure out what's
going on.
The packet filter log files don't indicate that DNS packets are being
blocked, and I can't seem to find any other source of error.
I've looked at KB article 810559, "FIX: Slow responses and failures when you
use server publishing UDP protocols", but I don't seem to meet all of the
symptoms (I don't have any deny rules in the site and content rule settings,
and I do have an Allow All rule configured).
Any help would be greatly appreciated.
Ryan Gregg
- Previous message: Akhil: "Login problem"
- Next in thread: J.C. Hornbeck [MSFT]: "Re: Problem with DNS Publishing"
- Reply: J.C. Hornbeck [MSFT]: "Re: Problem with DNS Publishing"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|