Re: Resolver issue

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Ace Fekay [MVP] (PleaseSubstituteMyActualFirstName&LastNameHere_at_hotmail.com)
Date: 07/15/04


Date: Thu, 15 Jul 2004 17:09:01 -0400

In news:cd6jt1$2cn6$1@newsreader2.mclink.it,
Massimo <barone@mclink.it> asked for help and I offered my suggestions
below:
> "Ace Fekay [MVP]"
> <PleaseSubstituteMyActualFirstName&LastNameHere@hotmail.com> ha
> scritto nel messaggio news:u322mKiaEHA.3764@TK2MSFTNGP10.phx.gbl
>
>> I agree it appears that the ISP's servers are in IP properties for
>> it to behave this way. An ipconfig /all can help clear it up. If
>> this is the case, maybe we don't have to configure the STMP virtual
>> server to use an external. Usually this is done to offload DNS
>> lookups from the internal DNS, especially if Exchange is in the DMZ.
>
> No, that's wrong.
> All of the machines, including the Exchange server, use the internal
> DNS servers, running on the two DCs. These DNS are configured to be
> authoritative for the Windows domain, but they also resolve external
> names, allowing clients to reach the Internat through the NAT gateway.
> The problem arises when the internal DNSs send queries to Libero's
> ones in order to resolve hostnames about the domain libero.it; the
> Windows DNS server apparently uses the same algorithm as the system
> resolver, so it sends out recursive queries appending the local
> domain suffix to them, and only when these query fail it tries the
> "right" queries (i.e., as they were asked initially).
>
> Massimo

I apologize I was wrong. I've seen it do this with misconfigured DNS clients
and just wanted to point that out. Besides, you've been testing this with
nslookup and not ping. They both work differently whereas ping will try the
fqdn first then suffix it without an answer, but nslookup suffixes it first
then if no answer, tries it without it.

I'm assuming you are NOT using a forwarder? I believe that will eliminate
this issue altogether.

-- 
Regards,
Ace
Please direct all replies ONLY to the Microsoft public newsgroups
so all can benefit.
This posting is provided "AS-IS" with no warranties or guarantees
and confers no rights.
Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft Windows MVP - Active Directory
HAM AND EGGS: A day's work for a chicken;
A lifetime commitment for a pig.
-- 
=================================


Relevant Pages

  • Issues migrating SBS 2003 domain to Server 2008 Standard
    ... We are stuck migrating our SBS 2003 domain to Server 2008. ... Fatal Error:DsGetDcName (SRV-EXCH) call failed, ... Verify your Domain Name Sysytem (DNS) is ... network connectivity to a domain controller. ...
    (microsoft.public.windows.server.sbs)
  • Re: AD management snap in cannot find DC (netdiag /v workstation)
    ... The name.local entries are used by my apache server to implement ... change button, more button, the "Primary DNS suffix of this ... Attr: subschemaSubentry ... Owner of the binding path: ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD management snap in cannot find DC (netdiag /v workstation)
    ... button, more button, the "Primary DNS suffix of this computer", it should ... The Security System could not establish a secured connection with the server ... Attr: subschemaSubentry ... Owner of the binding path: ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD management snap in cannot find DC (netdiag /v workstation)
    ... DNS Host Name: tonyb-pc.imageproc.imageproc.com ... Testing IpConfig - pinging the DHCP Server... ... Attr: subschemaSubentry ... Owner of the binding path: ...
    (microsoft.public.windows.server.active_directory)
  • Re: Issues migrating SBS 2003 domain to Server 2008 Standard
    ... Since you have migrated to standard server 2008 you would be better served posting in a Standard server NG. ... Event String: ... Verify your Domain Name Sysytem (DNS) is ... network connectivity to a domain controller. ...
    (microsoft.public.windows.server.sbs)