Re: dns forward

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Hi tnx for the answear
the problem iam my own registrar and windows 2003 acts at my own name server
so everytings goes to that one
and as you can se
ns1 and ns2 is goint to extern ips
83.227.158.5
and s1 thats internal local ip
i works fine here.
and there is no router before win 2003
the win 2003 is direct connect to internet true a wan fiber thats in bridge
mode so everytthing is controled by the win 2003 as a gw

but maybe i have to separete those and make me a new dns server
but that still not resolve my internal routing problem



\









"Ace Fekay [MVP]" wrote:

In news:%23A$V1ZHkIHA.4712@xxxxxxxxxxxxxxxxxxxx,
Kevin D. Goodknecht Sr. [MVP] <admin@xxxxxxxxxxxxxx> typed:
It appears you have made the serious mistake of trying to host your
public DNS and internal DNS in the same zone on the same server. If
you're going to host your own public DNS, move the Public zone to
another DNS server, so you don't mix public and private records in
the same zone.
Here is what I get back for a type any on your domain:
opcode: Query, status: NoError, id: 42
flags: qr aa ra; QUERY: 1, ANSWER: 8, AUTHORITY: 0, ADDITIONAL: 5

QUESTION SECTION:
windata.se. IN ANY

ANSWER SECTION:
windata.se. 600 IN A 83.227.158.5
windata.se. 600 IN A 192.168.93.1<--Private
record
windata.se. 600 IN A 192.168.1.1<--Private
record windata.se. 3600 IN A 85.227.158.5
windata.se. 3600 IN NS ns2.windata.se.
windata.se. 3600 IN NS
s1.windata.se.<--Resolves to private IP
windata.se. 3600 IN NS ns1.windata.se.
windata.se. 3600 IN SOA s1.windata.se.
hostmaster.windata.se. 123 900 600 86400 3600

ADDITIONAL SECTION:
ns2.windata.se. 3600 IN A 83.227.158.5
s1.windata.se. 3600 IN A 192.168.93.1<--Private
record
s1.windata.se. 3600 IN A 192.168.1.1<--Private
record s1.windata.se. 3600 IN A 83.227.158.5
ns1.windata.se. 3600 IN A 83.227.158.5

Query time: 391 ms
Server : 192.168.201.13:53 udp (192.168.201.13)
When : 3/27/2008 8:40:47 PM
Size rcvd : 272

You should let your Registrar host the Public DNS and keep it off your
internal DNS.

I agree.

I would also like to point out to the original poster that forwarding port
80 traffic, or any other type of traffic to an internal IP is performed by
the router/NAT device. You could also create a separate website for
www2.x.x, and redirect that internally, but the problem is the external user
will never be able to get to it. Get your public DNS off the internal DNS,
host it externally, and port forward the necessary ports to their respective
internal IPs using your router's setup page.


--
Regards,
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT,
MVP Microsoft MVP - Directory Services
Microsoft Certified Trainer

For urgent issues, you may want to contact Microsoft PSS directly. Please
check http://support.microsoft.com for regional support phone numbers.

Infinite Diversities in Infinite Combinations





///

.



Relevant Pages

  • Re: Urgent! New router and big disaster
    ... The SBS DNS server, running on ... its IP it means that your problem is now DNS. ... forward ports to it reliably in the router. ... I should have been more clear about internet connection.. ...
    (microsoft.public.windows.server.sbs)
  • Re: Cannot connect to RWW from home PC
    ... DNS stuff says your mail server is responding with reply that is not MS ... When we setup this new SBS2003 setup we installed without ISA as it does ... not seeing any problems anywhere regards internet or email - we also run ...
    (microsoft.public.windows.server.sbs)
  • Re: Non-domain connection problem
    ... For some reason the DNS is persistent. ... connect new PC to the internet from the non-domain network: ... In server 2000 gpoedit.msc showed them but in SBS it is different. ...
    (microsoft.public.windows.server.sbs)
  • Re: resolve incorrect IP from RRA server.
    ... dynamic address, 10.5.101.123 from DHCP server. ... This is because the addtional DNS records that get registered cause major problems with AD functionality, especially the additional IPs registered by RRAS. ... However, if you choose to keep RRAS on the DC, then you have to force DNS to only register the internal static interface, and no others. ... If it is the internet gateway, it is recommended to purchase an inexpensive, or cable/DLS router, or even better, a Cisco or similar firewall to perform the task, which if it is compromised by an internet attacker remotely, can further compromise the rest of the internal network. ...
    (microsoft.public.windows.server.dns)
  • Re: Cannot connect to RWW from home PC
    ... DNS stuff says your mail server is responding with reply that is not MS ... When we setup this new SBS2003 setup we installed without ISA as it does ... not seeing any problems anywhere regards internet or email - we also run ...
    (microsoft.public.windows.server.sbs)