Re: DCPROMO FAILED
- From: stosti <stosti@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Sun, 18 Mar 2007 17:42:07 -0700
My firewall is open on port 53.
On my corperate network I forward all requests to my IPS's caching only
server... Again this is a test network.
Thanks
"Herb Martin" wrote:
.
"stosti" <stosti@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:3D036B57-1BB4-4C73-844C-BD9DD3BCCA27@xxxxxxxxxxxxxxxx
The DNS was setup by Microsoft. If it is setup incorrectly I want my
money
back! What on the firewall could stop the root servers from accessing the
internet?
YOU don't have "root servers" you are trying to access them through
the firewall. Filters on TCP and UDP port 53 outbound requests
and/or response would stop it.
How are we resolving internet IP addresses with no access to root
servers?
By forwarding to a (caching only) DNS server which can do that.
Usually such are located at the firewall/DMZ or at the ISP but the
later isn't as safe and doesn't solve the problem when YOUR firewalls
prevent internal servers from recursing the Internet.
Do you really want your internal (very sensitive) DNS Servers, which
are frequently on DCs, visiting the entire Internet, including places like
dns1.EvilHackersRUs.com???
"stosti" <stosti@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:A3F23B52-97E4-4E0A-9868-D24E83777DF9@xxxxxxxxxxxxxxxx
Hi,
Your suggesting to use forwarders for all DNS lookups to the internet?
Yes, it is generally safer and you seem to have some current problem with
"root hints" (i.e., direct recursion) anyway. Perhaps a firewall or some
routing problem is preventing the root hints from testing correctly.
This DCN is setup correctly. It was setup by Microsoft in 2003.
What is a DCN? And having it set up by "Microsoft" (especially over
four
years ago) is no guarantee it is correct.
Even if you paid to have a problem resolved they generally just "fix the
problem"
and don't review and correct inherent design issues.
--
Herb Martin, MCSE, MVP
http://www.LearnQuick.Com
(phone on web site)
- Follow-Ups:
- Re: DCPROMO FAILED
- From: Herb Martin
- Re: DCPROMO FAILED
- References:
- Re: DCPROMO FAILED
- From: Herb Martin
- Re: DCPROMO FAILED
- From: stosti
- Re: DCPROMO FAILED
- From: Herb Martin
- Re: DCPROMO FAILED
- From: Herb Martin
- Re: DCPROMO FAILED
- From: Herb Martin
- Re: DCPROMO FAILED
- Prev by Date: Re: DCPROMO FAILED
- Next by Date: How do I list all the machine accounts created by a specific user in A/D ?
- Previous by thread: Re: DCPROMO FAILED
- Next by thread: Re: DCPROMO FAILED
- Index(es):
Relevant Pages
|