Re: DNS Server set to forwarder randomly going out to root servers
- From: "Ace Fekay [MVP]" <PleaseSubstituteMyActualFirstName&LastNameHere@xxxxxxxxxxx>
- Date: Thu, 21 Jul 2005 07:11:22 -0400
In news:46AF4F11-FBCA-4E08-92CF-4C11145E450A@xxxxxxxxxxxxx,
Fred L <FredL@xxxxxxxxxxxxxxxxxxxxxxxxx> stated, which I then commented on
below:
> We implemented the EDNS0 change to no avail.
>
> The firewall is actually acting as a caching DNS server. It has rules
> specifically to block all port 53 traffic from traversing the firewall
> regardless if it is UDP or TCP. It is meant to service the request
> of the forwarder.
>
> What I am really trying to understand is if the 2003 Server has a
> forwarder set why does it also randomly try and go to the root
> servers. What happens then is the firewall sees this attempt and
> purposely drops the traffic because of the rules we have set.
>
> Again what I don't understand is why the 2003 Server attempts to
> bypass the forwarder that is set and go to the root to traverse down
> the DNS tree. Can you stop this behaviour? I would prefer the DNS
> query just fail and then deal with the problem of why the Firewall as
> a Caching DNS server is not correctly servicing it's downstream
> clients.
>
> Thanks for your advise.
>
> Fred Lobmeyer
As I previously mentioned, DNS WILL use the forwarder first. If it doesn't
work, THEN IT GOES to the Root HInts. FolowKevin's suggestions on how to
disable that. If you disable that and it still doesn't work, then maybe the
DNS server you have configured your firewall to forward to is not responding
or working. Have you tested that server out? Or do you have rules blocking
the return traffic from it?
Ace
.
- References:
- DNS Server set to forwarder randomly going out to root servers
- From: Fred L
- Re: DNS Server set to forwarder randomly going out to root servers
- From: Ace Fekay [MVP]
- Re: DNS Server set to forwarder randomly going out to root servers
- From: Fred L
- DNS Server set to forwarder randomly going out to root servers
- Prev by Date: Re: nslookup error
- Next by Date: Adding DNS servef
- Previous by thread: Re: DNS Server set to forwarder randomly going out to root servers
- Next by thread: DNS Issues during Migration
- Index(es):
Relevant Pages
|