Re: problems with KB951746



Both on the server and on the clients. On the server even if I bypass the
hardware router and ISA.

--

GaryK


"Cliff Galiher" <cgaliher@xxxxxxxxx> wrote in message
news:vKqdnQgHzczspzvVnZ2dnUVZ_oDinZ2d@xxxxxxxxxxxxxx
Is DNS lookup slow *on the server* when the patch is applied and system is
under load? Or does this appear to strictly be a client issue using SBS?

-Cliff

"Gary Karasik" <gkarasik@xxxxxxx> wrote in message
news:eNSlmW0$IHA.3556@xxxxxxxxxxxxxxxxxxxxxxx
So this is where I'd start....look at your network perimeter and see if
you can verify there is a firewall issue.
Then, if you are CONFIDENT that you are okay there and the speed issue
remains, reconfigure SBS (CEICW) and point it to another DNS server that
is known to be patched and working (openDNS is a good option here).


Problem still exists if I bypass the hardware firewall and if I bypass
ISA.

I've tried all sorts of forwarders and root hints and DNS servers. The
only thing that makes a difference in performance is removing 951746.

Let me know if that helps,

-Cliff

I'm fairly confident you'll be able to fix the issue from there.
"Gary Karasik" <gkarasik@xxxxxxx> wrote in message
news:%236rvj2y$IHA.5660@xxxxxxxxxxxxxxxxxxxxxxx
Hi,

I can't decide how to proceed with getting this problem solved. Wien
the server-side DNS-vulnerability patch (951746) is installed, all my
SBS2K3 systems are exhibiting the same problem: extremely show internet
access when the system is under load, meaning when three or more
clients are trying to access the internet at once.

With the patch uninstalled everything returns to normal. This is not
resolved by reserving ports as one fix suggests.

The problem seems to be that DNS can't resolve quickly when the patch
is installed. Sometimes it is so slow that the system times out. I've
tried different forwarders, different DNS servers, and root hints only.
If the patch is installed, nothing helps.

Someone has posted a message about this in the SBS private forum, but
he isn't getting much help.

My indecision stems from the fact that no symptoms show if there is no
load, so if I call CSS after hours I can't show them any symptoms, and
I don't want to load the patch during a work day because access is so
slow that client work slows to a virtual standstill, the remote
branches connections to Exchange server stop responding, and local
clients can't do any work that involves the internet.

I think I'm just going to have to live with this and hope that MS comes
up with a fix for someone else and I hear about it.

Maybe someone here can suggest an approach, because I'm stumped as to
how to proceed.

--

GaryK









.



Relevant Pages

  • Re: AD, Win 2000, and new 2007 Daylight savings time
    ... You need to do it on every machine that you locally want displaying the proper time. ... An Exchange server that runs server side scripts could have an issue though if the scripts work in localtime instead of UTC. ... Will we need to patch our clients are will the time be ok Since we are using authoritative time server manage the time. ...
    (microsoft.public.win2000.active_directory)
  • Re: Domain Admins in local admin group
    ... need it in pre SP 2 clients. ... the behavior is different in XP than on the server OS but ... >benefit from the 810076 patch. ... >> to add domain admins to the local admin group of all ...
    (microsoft.public.win2000.active_directory)
  • RE: Users Cant Access Documents on Server
    ... Thanks for using the SBS newsgroup. ... As well as we know, if a workstation would not access network shares, then ... Leave the Default Gateway of the internal NIC blank of the server box. ... Clients That Require SMB Signing ...
    (microsoft.public.windows.server.sbs)
  • Re: Users Cant Access Documents on Server
    ... my computer to the network on the server. ... Connection Wizard none of the computers were listed. ... The Mac clients can not communicate with the server box. ... > Error Messages When You Open or Copy Network Files on Windows XP SP1 ...
    (microsoft.public.windows.server.sbs)
  • Re: [SLE] SMTP authentication
    ... So eventhough my local SMTP server dials up to the internet with a certain username and password, that same username and password would not be used as authentication between my local SMTP server and the ISP's one, should it be used as a relay? ... either defer all outgoing mails until you connect to the internet, then flush out all the mails in the queue. ... Your local server would use an external program like fetchmail to poll the mailserver of your ISP, download the mails and feed them to Postfix. ... The test does NOT say "All clients must be in mynetworks, ...
    (SuSE)