DNS Cache Corrupt for individual zone
- From: Michael Iams <michael.iams@xxxxxxxxx>
- Date: Sun, 19 Jul 2009 01:51:14 -0700 (PDT)
We have Windows 2003 DNS servers in our internal network (behind
checkpoint firewall, using BIND DNS servers on our external network
for authoritative DNS of external hosts).
We have a frustrating issue where the zone for one particular zone
(nasa.gov) gets corrupted in the cache consistently (every few
days). Everything within the nasa.gov zone becomes unable to resolve
when the cache is in this state.
The issue is easy to resolve. If you delete this zone in the MMC, the
problem clears immediately and subsequent queries resolve correctly.
Another couple of facts.
1) I know it is not a transient network issue, as NSLOOKUP and DIG
can resolve correctly when using the authoritative name servers. Also
our BIND servers never experience a problem resolving.
2) I don't believe it is a cache pollution issue. Our WIndows 2003
DNS servers are only accessible in our internal DNS network.
3) I don't believe it is a EDNS0 / Checkpoint issue since clearly it
resolves correctly sometimes. Unless the EDNS0 issue is somehow an
intermittent problem, that could result in a corrupt cache.
4) I could have a script clear the DNS cache on a regular basis, or
even better, clear the cache when this zone is unable to resolve, but
that's a bit of a sledgehammer when what is required is a scalpel. I
can't find anyway to programmatically delete this particular zone from
the cache. I don't want to delete the entire cache everytime this
zone has an issue.
5) We have multiple WIndows 2003 DNS servers inside our network and I
see the same problem on all of them.
6) This is the only zone with this problem. We do a lot of work with
NASA so perhaps we do more DNS lookups in this zone than typical.
Any help would be appreciated.
.
- Follow-Ups:
- Re: DNS Cache Corrupt for individual zone
- From: Ace Fekay [MCT]
- Re: DNS Cache Corrupt for individual zone
- From: Chris Dent
- Re: DNS Cache Corrupt for individual zone
- Prev by Date: Re: How do my server 2003 (DNS) know the Internet?
- Next by Date: Re: DNS Cache Corrupt for individual zone
- Previous by thread: Is This Normal DNS Behavior on a Server2003 SP2 Domain Controller
- Next by thread: Re: DNS Cache Corrupt for individual zone
- Index(es):
Relevant Pages
|