Re: Deploy Design Question

From: Kevin D. Goodknecht Sr. [MVP] (admin_at_nospam.WFTX.US)
Date: 07/02/04


Date: Fri, 2 Jul 2004 04:48:45 -0500

In news:24aee01c45fe6$51aa0430$a301280a@phx.gbl,
April <anonymous@discussions.microsoft.com> posted a question
Then Kevin replied below:
> Is this true? What does the event description say?
Actually, there are two events 40960 and 40961 it is not per se' because it
is trying to do a reverse lookup. Win2k3 cannot make a secure connection to
the DNS or LDAP server noted in the event. It simply is letting you know
that a secure connection cannot be made.
It does not mean that it needs a reverse lookup zone or PTR it just wants to
make a secure connection to the server so it can register its addresses.

> The reverse records, are needed for mail servers and
> other apps to verify the authenticity of the requesting
> names...so they have their merit to exist.

Yes some mail servers do make a reverse lookup on the IP of the connecting
server. But beware, in the case of public IP addresses, just because you
created a reverse lookup zone on your DNS server does not mean it will get
used. Just like any other DNS name, and it is a name, it must be delegated
to the DNS server it is on before other DNS servers will know it exists.
In fact an improper reverse lookup zone on a DNS server that is directly
being used by your mail server can do more harm than good because the zone
covers more IP addresses than it is Authoritative for. This may cause your
mail server to reject mail based on the lack of a proper PTR because it is
looking at the wrong DNS. It is very important that any reverse lookup for a
public IP address you create be delegated to you and that you create it
exactly as it is delegated to you.
You usually cannot create a public reverse zone as you would a private
reverse zone. You can create a reverse lookup for a private zone that covers
an entire subnet such as 192.168.in-addr.arpa. If you do that for a public
IP /29 subnet the zone covers 65534 IP addresses when you only own 8 and can
only use 5.

-- 
Best regards,
Kevin D4 Dad Goodknecht Sr. [MVP]
Hope This Helps
============================
-- 
When responding to posts, please "Reply to Group"  via your
newsreader so that others may learn and benefit from your issue.
To respond directly to me remove the nospam. from my email.
==========================================
 http://www.lonestaramerica.com/
==========================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
 http://home.in.tum.de/~jain/software/oe-quotefix/
==========================================
Keep a back up of your OE settings and folders with
OEBackup:
 http://www.oehelp.com/OEBackup/Default.aspx
==========================================


Relevant Pages

  • Re: Tickets Kerberos
    ... A reverse lookup is not required for proper AD function. ... However, without a reverse lookup zone and PTRs, you may see 40960 and 40961 events due to Win2k3 and WinXP trying to make a secure PTR registration at the External DNS that is Authoritative over the reverse lookup of the IP on the machine's local interface. ... If it's a private address it will say cannot establish a secured connection with the server prisoner.iana.org. ... By creating a Reverse lookup zone you solve that error, also make sure that you have all clients NIC preferred DNS server pointing to their local DNS server. ...
    (microsoft.public.windows.server.active_directory)
  • Re: SPNEGO 40960 errors
    ... A reverse lookup is not required for proper AD function. ... establish a secured connection with the server prisoner.iana.org. ... These servers own the public PTR records for the 192.168.x.x zones. ... On the local DNS Server, create a Reverse Lookup Zone, and enter a ...
    (microsoft.public.windows.server.active_directory)
  • Re: System Log Error
    ... the DNS server doesn't have a Reverse Lookup Zone Configured. ... Active Directory doesn't need Reverse Lookup Zone to function, ... the OS tries to make a secure PTR ...
    (microsoft.public.windows.server.dns)
  • Re: This event makes me nervous...
    ... Configure the reverse lookup zone and it will go away. ... Our DNS server is at our ISP and I'm thinking this is ... > probably the result of some kind of negotiating going between our DS and ...
    (microsoft.public.windows.server.sbs)
  • Re: Setup External DNS Server
    ... > but want to use my own DNS server for external ... The reverse lookup is on the IP not the mail server. ... Some won't host the reverse lookup unless ...
    (microsoft.public.windows.server.dns)