Re: DNS on new DC at new site...

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Well, I checked with nslookup and 4.2.2.2 replies fine. Is this a
sufficient test to ensure port 53 (UDP/TCP) is enabled inbound/outbound? I
check debug logs on my firewall and it says packets are allowed on port 53
between my internal DNS server and 4.2.2.2 but I still get the strange
errors in 'dcdiag /c'

TEST: Forwarders/Root hints (Forw)
Error: Forwarders list has invalid forwarder: 4.2.2.1
(<name unavailable>)
Error: Forwarders list has invalid forwarder: 4.2.2.2
(<name unavailable>)

Summary of test results for DNS servers used by the above domain
controllers:

DNS server: 4.2.2.1 (<name unavailable>)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the
1.0.0.127.in-addr.arpa. failed on the DNS server 4.2.2.1

DNS server: 4.2.2.2 (<name unavailable>)
1 test failure on this DNS server
This is not a valid DNS server. PTR record query for the
1.0.0.127.in-addr.arpa. failed on the DNS server 4.2.2.2

This is driving me crazy. I look on the internet and I haven't found much
on this error except on this page:

http://technet2.microsoft.com/WindowsServer/en/library/5237db58-a1e8-40cd-ae8a-7f52848a90f21033.mspx?mfr=true

It says:

"Forwarders configured on the DNS server have an invalid IP address or are
not a DNS server, or name resolution is not working (that is, cannot resolve
forest root domain SRV record if it is a non-root domain DC)."

I don't know what this means. It can't resolve domain.local? It isn't a
non-root domain DC so I don't know what is going on. Please decode for me.

-Steven-


"Herb Martin" <news@xxxxxxxxxxxxxx> wrote in message
news:OF3fGBJcHHA.4836@xxxxxxxxxxxxxxxxxxxxxxx

"Billingsley" <billingsley@xxxxxxxxxxxxxxxx> wrote in message
news:uEgxOUIcHHA.4176@xxxxxxxxxxxxxxxxxxxxxxx
I definitely have port 53 open outbound but should I really be allowing 53
inbound?

Yes, but be clear that I mean the MIRROR where 53 is the SOURCE
port inbound. You cannot send a request out and receive the reply
unless you allow that.

UDP and TCP.

Since my DNS servers are for internal use only it seems like this would
be some sort of security risk. Do you think I should enable port 53
inbound only for 4.2.2.2 and 4.2.2.1.

It is certainly more secure to do so ONLY for the actual external DNS
servers.

Also, you said that I shouldn't be using those for my forwarders...
should I use a couple of DNS servers provided from my ISP?

Yes, or a DNS server on your firewall/gateway which can then recurse
or (also) forward to the ISP -- this eliminates opening anything to your
internal server.

I have used my ISP's DNS servers in the past but they seem to go down (or
change) sporadically.

Then you should NOT use them -- and you should change ISP if you
have an affordable alternative. (really)

People really freak out when the internet "doesn't work." Thanks a lot
for helping me through this!

Sure

--
Herb Martin, MCSE, MVP
http://www.LearnQuick.Com
(phone on web site)



.



Relevant Pages

  • Re: Way to Increase SMTP Timeout for Delivery???
    ... Does it have any servers/IP's listed as forwarders? ... it would forward the request to the DNS server listed there. ... root servers, which will then tell you where to go. ... fixes their host so that it accepts incoming connections on port 25. ...
    (microsoft.public.exchange.admin)
  • Re: Unknown svchost.exe DNS port 53 network activity
    ... activity on my router as well as my PC LAN connection icon in the tray. ... port 53 with a remote address of my ISP's DNS server. ... No traffic can come to the machine, unless you have opened the inbound port ... Svchost allows the communication between machines in a LAN or WAN situation. ...
    (comp.security.firewalls)
  • RE: problems receiving e-mail to my server redux
    ... I installed BIND on my Linux box and set it up to start at every ... > To: Ed McCorduck ... > run a dns server if you want things to work. ... > which implies that you are trying to use port 80 for your dns server. ...
    (RedHat)
  • Re: SendPort
    ... If you want your DNS server should listen on port other than 53, ... the best way would be to have a firewall or set up NAT, ... on which the DNS servers is listening then what will you achieve with this? ...
    (microsoft.public.windows.server.dns)
  • Re: questionable access to my computer - please help
    ... > Download portref.zip from: wilders.org for a full port reference listing. ... > If the firewall is blocking internet access to that addy, ... even shows you that it _is_ a DNS server. ... The only question here is what is more stupid, this firewall simulation ...
    (comp.security.firewalls)