Re: Problem with DNS Publishing

From: J.C. Hornbeck [MSFT] (jchornbe_at_online.microsoft.com)
Date: 03/19/04

  • Next message: Bloopy: "Re: Problem with DNS Publishing"
    Date: Fri, 19 Mar 2004 09:08:22 -0600
    
    

    Hi Ryan, one thing you might try if you haven't already is the UDP specific
    site and content rule mentioned in this article:

    301351 - Server Publishing Rules May Not Permit Inbound UDP Packets Through
    to Published Server (http://support.microsoft.com/?id=301351).

    Also check out:

    331065 - MS03-009: A Problem in the ISA Server DNS Intrusion Detection
    Filter May Cause Denial of Service
    (http://support.microsoft.com/?id=331065).

    As always, make sure you're on SP1 and feature pack 1. Lastly, make sure
    that ISA server is not running DNS itself while also trying to publish an
    internal DNS. That can give you inconsistent results similar to what you're
    seeing.

    -- 
    J.C. Hornbeck, MCSE
    Microsoft Product Support
    NOTE: Please reply to the newsgroup and not directly to me. This allows
    others to add to and benefit from these threads and also helps to ensure a
    more timely response. Thank you!
    This posting is provided "AS IS" without warranty either expressed or
    implied, including, but not limited to, the implied warranties of
    merchantability or fitness for a particular purpose.
    "Ryan Gregg" <ryan@ryangregg.com> wrote in message
    news:ODJLPYUDEHA.3568@tk2msftngp13.phx.gbl...
    > I'm running into all sorts of problems with DNS publishing, and I'm hoping
    > someone here can help me.
    >
    > I've got ISA 2000 w/ SP1&FP1 running on a Windows 2003 Server box, dual
    > homed with three external IP addresses. The primary address on the box is
    > .81. I have publishing rules configured to allow DNS Query Server and DNS
    > Zone Transfer both using the .81 address for the external, and the IP of
    the
    > DNS server for the internal addresses (a separate box from the ISA
    server).
    >
    > I also have setup IP Packet filter rules to allow DNS query and domain
    > transfer packets in either direction.
    >
    > When I first set everything up, I wasn't have any problems. From outside
    the
    > ISA server I could do an nslookup of a domain on the DNS server using the
    > .81 address, and it would return the results. However, after letting it
    run
    > overnight, in the morning I was unable to query the DNS server. If I
    fiddle
    > with the connection some more, not really changing anything, then I can
    get
    > it to work again for a short period of time, but it always reverts back to
    > not working. I'm really stuck on the issue, and I can't figure out what's
    > going on.
    >
    > The packet filter log files don't indicate that DNS packets are being
    > blocked, and I can't seem to find any other source of error.
    >
    > I've looked at KB article 810559, "FIX: Slow responses and failures when
    you
    > use server publishing UDP protocols", but I don't seem to meet all of the
    > symptoms (I don't have any deny rules in the site and content rule
    settings,
    > and I do have an Allow All rule configured).
    >
    > Any help would be greatly appreciated.
    >
    > Ryan Gregg
    >
    >
    

  • Next message: Bloopy: "Re: Problem with DNS Publishing"

    Relevant Pages

    • RE: ICW Problem Error 0x80072581 Deleting the DNS record external NIC
      ... Make sure your SBS internal and external network interface DNS is ... Do you have any site hosted in the SBS server other than the four ... Check if the PUBLISHING record in DNS is an A record. ... check to see if there is a name record 'publishing'. ...
      (microsoft.public.windows.server.sbs)
    • Re: SBS 2003 ICW and RPC over HTTP
      ... > Error 0x80005006 returned from call to Committing Web publishing rules(). ... > Ethernet adapter Server Local Area Connection: ... > Call to Changing startup type for DNS returned ok. ... > Call to Reading in the local domain name returned ok. ...
      (microsoft.public.backoffice.smallbiz2000)
    • RE: Firewall Rule Set not allowing access to DNS servers?
      ... I changed the DNS rules as you suggested, and the firewall works perfectly - ... > # Allow out access to my ISP's Domain name server. ... > so your udp packets never match this rule and default to ...
      (freebsd-questions)
    • Re: SBS 2003 ICW and RPC over HTTP
      ... Use a workstation or use OWA from the server if you must. ... >> calling CValidatePropertyUtil.ValidatePropertyInteger. ... >> Call to Changing startup type for DNS returned ok. ... >> Call to Reading web publishing selection returned ok. ...
      (microsoft.public.backoffice.smallbiz2000)
    • Windows 9X clients can change password in Windows 2003 PDC Emulator
      ... I've desinstalled the WINS Server of the Windows 2000 and now, ... The DNS, WINS and AD replication are OK (Windows 2003 is Primary DNS+WINS ... Gathering NetBT configuration information. ... Packets Received: 36169 ...
      (microsoft.public.windows.server.migration)

    Loading