Re: Event ID 5504 - Windows 2003 DNS



Kunal <Kunal@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
> On our recently deployed WIndows 2003 Server, DNS log is filling up
> with Event iD 5504: DNS encountered an invalid domain name in a
> packet from xxx.xxx.xxx.xxx (different IP addresses).
>
> Though there is no apparent problem on the network, is there a way to
> stop these messages from appearing? Do these message indicate any
> kind of issues on the network or the server itself?
>
> Thanks!


http://www.eventid.net/display.asp?eventid=5504&eventno=642&source=DNS&phase=1

Use a packet sniffer to see what is in these rejected packets.
I have seen a case where a machine was sending a query for localhost to DNS
which causes these events. I'm not sure why the machine was sending a query
for localhost to DNS, but creating a localhost zone stopped the event.

--
Best regards,
Kevin D4 Dad Goodknecht Sr. [MVP]
Hope This Helps
===================================
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
===================================
http://www.lonestaramerica.com/
===================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
===================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
===================================


.



Relevant Pages

  • Re: [Full-Disclosure] Fw: [NTBUGTRAQ] Win 2003 DNS requests makes replies over 512 byte PIX limit
    ... Back when the maximum usable MTU in the Arpanet was 584, the DNS protocol ... and retry the query as TCP". ... don't use any other extensions provides a convenient way of saying "Use UDP ... if the packet is under 1280 ...
    (Full-Disclosure)
  • Re: DNS Event ID error 5504
    ... >> Event Source: DNS ... The packet is rejected. ... >> error is caused by a DNS packet request from my server that is asking ... > I have found that if you query DNS for the name "localhost." ...
    (microsoft.public.windows.server.dns)
  • Re: Strange DNS packets
    ... Yes I query several DNSRBL but incoming mail is handled by another SMTP ... The packet in provided log are destined to the outgoing SMTP server. ... >> DNS packet directed to the IP address of our mail server. ...
    (comp.os.linux.security)
  • Re: We have lots of users with SonicWalls for VPN connectivity in to FW-1, possible major security h
    ... A faster processor in the current Sonicwall firewalls has helped ... DNS name resolution on the fly was enabled for Logging. ... >to pass from the LAN to the WAN. ... >why is my internal server responding to this packet as a "Destination ...
    (Incidents)
  • Re: Bad packets and invalid domain names Please help
    ... At any rate, it isn't clear whether these errors, or DNS at all, has anything to do with your issues. ... > Source DNS ... > The DNS server has encountered numerous run-time events. ... > The DNS server encountered a bad packet from X.X.X.X. ...
    (microsoft.public.win2000.dns)