AD DNS stopping problem



Hello
I have a question to ask, if someone can help. Here is the situation: we
have a Domain with 2 DC running Windows 2000 Advanced Server with SP4 for the
internal network, there is a DMZ (demilitarized zone) for the external
(internet available servers – WEB, Mail, DNS, Proxy, Firewall etc.) the in
the DMZ the DNS is a Linux machine running BIND – it handles the records for
the web sites that we are hoisting. For faster access to the web sites form
the internal network the DNS services on each DC has a record for the address
of the servers in the DMZ with there IP addresses for the local network (not
the Internet ones). Until 2 weeks everything was fine but one day the to DC
based DNS servers started to act strange – both claim that one is sending the
other packets with invalid domain name – to be exact error 5504 “The DNS
server encountered an invalid domain name in a packet from X.X.X.X. The
Packet was rejected” when that happens one of them starts to build up memory
and the used memory jumps with 1.5GB the CPU utilization levels at 100% for
all processors and after something like 10 minutes the DNS service stops. If
a stop manually the DNS service on one of the DC-s there is no problem but if
both are running after 10 minutes both start to log errors and after few
hours one of them stops. If any one can help I will be very happy, because we
have no idea what might happen to start causing the problem.

Stoil Pankov

.



Relevant Pages

  • Re: Near and far dmz (is this model secure)
    ... I think that your boss is right, the Exchange servers should be on the ... in a DMZ via VPN tunnel. ... connections from the DMZ to the internal network, ...
    (comp.security.firewalls)
  • Re: dmz question
    ... >servers in our internal network on the outside of our internal firewall ... EVEN IF IT'S IN A DMZ. ... internal firewall), and access from the DMZ to the world should be limited ... >the outside firewall exposes the internal network). ...
    (comp.security.firewalls)
  • DNS Best Practices
    ... We currently have a DMZ via one-arm routing. ... this DMZ and all are isolated from the internal network. ... best to create a Windows 2003 DNS server in our DMZ for the web servers. ...
    (microsoft.public.windows.server.general)
  • Microsoft software update server (SUS)
    ... Where is a more secured place to have the SUS installed for the servers in ... Within DMZ or in the internal network? ... If SUS is placed in the internal network, what are the ports to be opened on ... the firewall to allow the traffic? ...
    (comp.security.misc)
  • Re: Unable to join AD domain from DMZ network
    ... > the captured traffic between the server in DMZ to the DC from internal ... >> unless you lock it down to a specific port. ... >>> authentication from DMZ to 2003 AD internal network. ...
    (microsoft.public.windows.server.active_directory)

Loading