Re: problems with KB951746



Also, if this were a firewall issue, I think it would be there all the time,
not just when the system is under load.

--

GaryK


"Cliff Galiher" <cgaliher@xxxxxxxxx> wrote in message
news:I5OdnRWuYKkGijvVnZ2dnUVZ_uqdnZ2d@xxxxxxxxxxxxxx
Gary,

I doubt the patch, or SBS, is the problem here. What I suspect is
happening is that the patch is doing what it is supposed to do. But one
of the things the patch does is cause the source port to be randomized.
If your firewall is not configured to allow DNS traffic from a random
source port then your recursive DNS requests are being stopped at the
firewall...and you'll get the symptoms you describe. It is also possible,
but less likely, that your ISP's DNS servers are misconfigured and are
unable to reply on odd source ports.

So this is where I'd start....look at your network perimeter and see if
you can verify there is a firewall issue.
Then, if you are CONFIDENT that you are okay there and the speed issue
remains, reconfigure SBS (CEICW) and point it to another DNS server that
is known to be patched and working (openDNS is a good option here).

Let me know if that helps,

-Cliff

I'm fairly confident you'll be able to fix the issue from there.
"Gary Karasik" <gkarasik@xxxxxxx> wrote in message
news:%236rvj2y$IHA.5660@xxxxxxxxxxxxxxxxxxxxxxx
Hi,

I can't decide how to proceed with getting this problem solved. Wien the
server-side DNS-vulnerability patch (951746) is installed, all my SBS2K3
systems are exhibiting the same problem: extremely show internet access
when the system is under load, meaning when three or more clients are
trying to access the internet at once.

With the patch uninstalled everything returns to normal. This is not
resolved by reserving ports as one fix suggests.

The problem seems to be that DNS can't resolve quickly when the patch is
installed. Sometimes it is so slow that the system times out. I've tried
different forwarders, different DNS servers, and root hints only. If the
patch is installed, nothing helps.

Someone has posted a message about this in the SBS private forum, but he
isn't getting much help.

My indecision stems from the fact that no symptoms show if there is no
load, so if I call CSS after hours I can't show them any symptoms, and I
don't want to load the patch during a work day because access is so slow
that client work slows to a virtual standstill, the remote branches
connections to Exchange server stop responding, and local clients can't
do any work that involves the internet.

I think I'm just going to have to live with this and hope that MS comes
up with a fix for someone else and I hear about it.

Maybe someone here can suggest an approach, because I'm stumped as to how
to proceed.

--

GaryK






.



Relevant Pages

  • Re: problems with KB951746
    ... Blocking legitimate IP addresses responding on ports the ... using the net will cause the firewall to block IPs more rapidly. ... I doubt the patch, or SBS, is the problem here. ... tried different forwarders, different DNS servers, and root hints only. ...
    (microsoft.public.windows.server.sbs)
  • Re: problems with KB951746
    ... Blocking legitimate IP addresses responding on ports the firewall doesn't expect will cause problems. ... What I suspect is happening is that the patch is doing what it is supposed to do. ... It is also possible, but less likely, that your ISP's DNS servers are misconfigured and are unable to reply on odd source ports. ...
    (microsoft.public.windows.server.sbs)
  • Re: Problems with the On Lisp development model ...
    ... > separately, and installed into some known directory, with gcl, maxima, ... > Or should there be a one time process which runs on patch installation ... You could treat maxima as a single application, and load it independently ... This means that there is a start up cost to load the patches each time. ...
    (comp.lang.lisp)
  • Re: [rfc][patch] sched: remove smpnice
    ... appended patch) too but was n't much bothered as active load balance ... And the reason is the code still assumes that a unit load is ... I've mistakenly assumed that busiest ... int local_group; ...
    (Linux-Kernel)
  • Re: problems with KB951746
    ... I don't run ISA on SBS and haven't for many years although I run it standalone in front of SBS quite a bit. ... What I suspect is happening is that the patch is doing what it is supposed to do. ... If your firewall is not configured to allow DNS traffic from a random source port then your recursive DNS requests are being stopped at the firewall...and you'll get the symptoms you describe. ... It is also possible, but less likely, that your ISP's DNS servers are misconfigured and are unable to reply on odd source ports. ...
    (microsoft.public.windows.server.sbs)