DNS Server set to forwarder randomly going out to root servers



Hi,

The problem we are having is intermittent DNS lookup failures tring to
resolve Public Internet based Web Services or Pages.

I have a W2K3 SP1 single forest single domain with integrated AD/DNS
established.

The clients (XP SP2) are set to resolve from a specific DC enabled for DNS
in the domain. (Set via DHCP Scope)

The Domain is Fred.Local

The DNS Server is configured with 1 forwarder which points to the Internal
interface of the Firewall. The DNS Server is not configured as a root server
"." The Firewall is configured as DNS proxy.

The Firewall also has a rule set that says that no internal machine may make
DNS requests to external DNS hosts.

Here is where I don't know how to configure the internal DNS server
correctly. I would like to stop the Internal DNS Server (forwarder) from
going out to the root servers for lookups. When it does this the firewall
rule blocks the request (as it should) and the request times out which
returns to the client as a failed request.

So can you stop the DNS Server from doing this? Do you want to? What am I
misunderstanding about this?

Thanks in advance!

Fred Lobmeyer
.



Relevant Pages

  • Re: Non-domain connection problem
    ... "Gregg Hill" wrote: ... You said that you "hard coded the DNS server to a known DNS on the ... Connect to Internet from external network ...
    (microsoft.public.windows.server.sbs)
  • Re: Added router, lost web site
    ... Did your ISP create a DNS record for your FQDN? ... > really have a direct connection. ... > Internet connection information: ... > Preferred DNS server: someisp DNS server address ...
    (microsoft.public.windows.server.sbs)
  • Re: Unix Bind and Windows DNS with Dynamic update issues!!!
    ... >suggest but it does NOT service internal clients directly. ... still have UNIX BIND to do the rest for host name and internet resolution. ... Windows 2003 DNS will acting as another internal DNS server like UNIX BIND? ...
    (microsoft.public.win2000.dns)
  • Re: Unix Bind and Windows DNS with Dynamic update issues!!!
    ... >> 2) All internal DNS clients NIC\IP properties must specify SOLELY ... >> we are running UNIX BIND as internal and external DNS server. ... > expose your sensitive internal information on the Internet. ... >> internal clients like Windows, Mac etc are pointing to UNIX BIND server to ...
    (microsoft.public.win2000.dns)
  • Re: Unable to join my new XP pro wkstation to the Win 2K pro server domain.
    ... You must have an internal DNS zone for each AD domain that is ... maintained separately from the Internet versions of these zone (if ... You need an INTERNAL DNS server for the zones. ... Herb Martin> tia ...
    (microsoft.public.windows.server.networking)