DNS Root Hints / NSLookup

From: TJ (atgisolutions_at_yahoo.com)
Date: 02/09/04


Date: Mon, 9 Feb 2004 11:48:05 -0800

I have a test lab connected inside another's domain. My
W2K3 Root Domain Controller is using ICS with NAT,
therefore two network cards are present. One network card
DHCP's to the other network while the second card is for
the systems in the lab.

My concern is the continued inability to verify my name
server when connected to the other network.

When I isolated my Root DC from the other network...the NS
works just fine as expected and I'm able to verify my Root
DC, but when I'm connected to the outside network, I've
noticed 2 new Root Hints are added with their server names
and IP address's. After this, the NSLookup resolves to
their servers and fails to my server.

I'm not sure how this is happening or how I can keep their
NS from appearing in my Root Hints.

I'd like to have WWW access through there network, but am
unable to validate my Root DC when doing so.

Any assistance is appreciated....An up front "Thank You"
for your time and reply....TJ



Relevant Pages

  • Re: server is being hacked
    ... then between 1 and 3 months a new hack is on my server. ... Can any one help to find the root of this issue. ... o remove teh box from the network ... forensic analysis of the box. ...
    (comp.security.misc)
  • Re: DNS Root Hints / NSLookup
    ... > W2K3 Root Domain Controller is using ICS with NAT, ... > therefore two network cards are present. ... > server when connected to the other network. ...
    (microsoft.public.windows.server.dns)
  • Re: Documenting a server conf
    ... Server doesn't have network connectivity and I cannot get root access. ... Look at network config, log files, GSM hardware logs, sudo config ...
    (comp.unix.admin)
  • Re: Isolation of the Root CA
    ... Best Practices for implementing Windows Server 2003 PKI: ... If you run a network that is going to have a three tier hierarchy of>Certificate Authorities with maybe six or eight issuing CA's for various>tasks that are going to issue thousands of certificates then it makes sense>to secure the CA's that only issue certificates to other CA's to minimize>the damage that can be done to the PKI. ... You would have to start with a> standalone root CA and use it to issue a certificate for an Enterprise CA ...
    (microsoft.public.win2000.security)
  • Distributed File System question -
    ... I'm going to be rolling out a Server 2003 network and I am ... attempting to get DFS working. ... child domain of the root. ...
    (microsoft.public.windows.server.general)