PC Review


Reply
Thread Tools Rate Thread

How to delete root-servers?

 
 
Stefan Kirch
Guest
Posts: n/a
 
      31st Jan 2004
Hi!

I want to set up my win2k-Server as a dns-server which resolves the
ip's from the lan (Active Directory) and forwards all other questions
to another dns-server (linux).
For security reason, I want to disable all other dns-traffic from
win2k despite from the linux-pc, so I tried to delete all root-servers
(cause win2k seems to connect several times to them - but this traffic
is completly firewalled).

But: After I delete all root-server, it takes some hour/days
(reboot?), and suddenly all root-servers appears in the dns-settings
and I one again have the dns-traffic from win2k to the root servers.

Is there a way to completely delete the root-servers, so that they
never appears again? Or is there a reason, why I MUSt have
root-servers, which I don't recognized?!?

Best regards

Steff
 
Reply With Quote
 
 
 
 
phoenix
Guest
Posts: n/a
 
      31st Jan 2004
On 31 Jan 2004 07:00:55 -0800, Stefan Kirch wrote:

> Hi!
>
> I want to set up my win2k-Server as a dns-server which resolves the
> ip's from the lan (Active Directory) and forwards all other questions
> to another dns-server (linux).
> For security reason, I want to disable all other dns-traffic from
> win2k despite from the linux-pc, so I tried to delete all root-servers
> (cause win2k seems to connect several times to them - but this traffic
> is completly firewalled).
>
> But: After I delete all root-server, it takes some hour/days
> (reboot?), and suddenly all root-servers appears in the dns-settings
> and I one again have the dns-traffic from win2k to the root servers.
>
> Is there a way to completely delete the root-servers, so that they
> never appears again? Or is there a reason, why I MUSt have
> root-servers, which I don't recognized?!?
>
> Best regards
>
> Steff


Hi

You don't delete the root servers themselves you just delete the "." (no
quotes) domain and set the forwarders tab to the IP address of your Linux
DNS box.

Regards

Bill
 
Reply With Quote
 
Marc Reynolds [MSFT]
Guest
Posts: n/a
 
      31st Jan 2004
See 298148 HOWTO: Remove the Root Zone (Dot Zone)
http://support.microsoft.com/?id=298148

--

Thanks,
Marc Reynolds
Microsoft Technical Support

This posting is provided "AS IS" with no warranties, and confers no rights.


"Stefan Kirch" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Hi!
>
> I want to set up my win2k-Server as a dns-server which resolves the
> ip's from the lan (Active Directory) and forwards all other questions
> to another dns-server (linux).
> For security reason, I want to disable all other dns-traffic from
> win2k despite from the linux-pc, so I tried to delete all root-servers
> (cause win2k seems to connect several times to them - but this traffic
> is completly firewalled).
>
> But: After I delete all root-server, it takes some hour/days
> (reboot?), and suddenly all root-servers appears in the dns-settings
> and I one again have the dns-traffic from win2k to the root servers.
>
> Is there a way to completely delete the root-servers, so that they
> never appears again? Or is there a reason, why I MUSt have
> root-servers, which I don't recognized?!?
>
> Best regards
>
> Steff



 
Reply With Quote
 
Kevin D. Goodknecht [MVP]
Guest
Posts: n/a
 
      1st Feb 2004
In news:(E-Mail Removed),
Stefan Kirch <(E-Mail Removed)> posted a question
Then Kevin replied below:
: Hi!
:
: I want to set up my win2k-Server as a dns-server which resolves the
: ip's from the lan (Active Directory) and forwards all other questions
: to another dns-server (linux).
: For security reason, I want to disable all other dns-traffic from
: win2k despite from the linux-pc, so I tried to delete all root-servers
: (cause win2k seems to connect several times to them - but this traffic
: is completly firewalled).
:
: But: After I delete all root-server, it takes some hour/days
: (reboot?), and suddenly all root-servers appears in the dns-settings
: and I one again have the dns-traffic from win2k to the root servers.
:
: Is there a way to completely delete the root-servers, so that they
: never appears again? Or is there a reason, why I MUSt have
: root-servers, which I don't recognized?!?
:
: Best regards
:
: Steff

You don't need to delete anything, on the Forwarders tab, check the box "Do
not use recursion" that will force your DNS to use the Linux as a forwarder
and basically disables the root hints, although they will still be there,
they will not be used.

--
Best regards,
Kevin D4 Dad Goodknecht Sr. [MVP]
Hope This Helps
============================
--
When responding to posts, please "Reply to Group" via your
newsreader so that others may learn and benefit from your issue.
To respond directly to me remove the nospam. from my email.
==========================================
http://www.lonestaramerica.com/
==========================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
==========================================
Keep a back up of your OE settings and folders with
OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
==========================================


 
Reply With Quote
 
Stefan Kirch
Guest
Posts: n/a
 
      2nd Feb 2004
"Kevin D. Goodknecht [MVP]" <(E-Mail Removed)> wrote in message news:<(E-Mail Removed)>...

> You don't need to delete anything, on the Forwarders tab, check the box "Do
> not use recursion" that will force your DNS to use the Linux as a forwarder
> and basically disables the root hints, although they will still be there,
> they will not be used.


But this leads to the situation, that NO hostnames are resolved.

What I want is, that for ANY resolving, the forwarder is used (despite
for the ActiveDirectory-Domain). I just tried to delete the
default-root-servers and add my forwarder-ip in the hint for
root-servers area - let's hope, this will help.

Or is there any other way to solve the problem?
Is my idea really so strange, to only use a forwarder for any
dns-traffic?

Steff
 
Reply With Quote
 
Stefan Kirch
Guest
Posts: n/a
 
      2nd Feb 2004
"Marc Reynolds [MSFT]" <(E-Mail Removed)> wrote in message news:<(E-Mail Removed)>...
> See 298148 HOWTO: Remove the Root Zone (Dot Zone)
> http://support.microsoft.com/?id=298148


I already deleted the dot-zone some month ago.

What I want is:
* use the Win2K-DNS ONLY for the local ActiveDirectory-Domain
* for any other dns-traffic, use the forwarder, i.e. the linux-bind-server
* DON'T use any root-server

Any other idea?

Steff
 
Reply With Quote
 
Kevin D. Goodknecht [MVP]
Guest
Posts: n/a
 
      2nd Feb 2004
In news:(E-Mail Removed),
Stefan Kirch <(E-Mail Removed)> posted a question
Then Kevin replied below:
: "Kevin D. Goodknecht [MVP]" <(E-Mail Removed)> wrote in message
: news:<(E-Mail Removed)>...
:
:: You don't need to delete anything, on the Forwarders tab, check the
:: box "Do not use recursion" that will force your DNS to use the Linux
:: as a forwarder and basically disables the root hints, although they
:: will still be there, they will not be used.
:
: But this leads to the situation, that NO hostnames are resolved.
:
: What I want is, that for ANY resolving, the forwarder is used (despite
: for the ActiveDirectory-Domain). I just tried to delete the
: default-root-servers and add my forwarder-ip in the hint for
: root-servers area - let's hope, this will help.
:
: Or is there any other way to solve the problem?
: Is my idea really so strange, to only use a forwarder for any
: dns-traffic?
:
: Steff

If you did what I said and it caused you to loose DNS resolution then the
DNS on the Linux is not doing recursive lookups. DO NOT confuse "Do not use
recursion" on the Forwarders tab with "Disable recursion" on the Advanced
tab. They are not the same.
"Do not use recursion" on the Forwarder tab prevents your DNS server from
using its Root Hints.
"Disable recursion" on the Advanced tab prevents your DNS server from
resolving any name not in its zones.

If you check "Do not use recursion" on the Forwarders tab and it stopped
resolution, then the forwarder has Recursion disabled. In this case it is
the DNS on the Linux. If you run dig against the Linux you can see if the ra
bit is disabled. In the Dig query you will see a Flags section If you see an
RD followed by an RA then it has recusion available, if you have only a RD
not followed by an RA then recursion is disabled.



--
Best regards,
Kevin D4 Dad Goodknecht Sr. [MVP]
Hope This Helps
============================
--
When responding to posts, please "Reply to Group" via your
newsreader so that others may learn and benefit from your issue.
To respond directly to me remove the nospam. from my email.
==========================================
http://www.lonestaramerica.com/
==========================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
==========================================
Keep a back up of your OE settings and folders with
OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
==========================================


 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
OT: Nine Root Servers? Doug Kanter Windows XP General 5 16th Mar 2006 11:30 PM
address of root name servers? Ben Microsoft Windows 2000 DNS 4 22nd May 2005 06:38 PM
root-servers.net in my Netstat info, why are the root servers always there? Derek Microsoft Windows 2000 1 6th May 2005 02:08 PM
How to delete root-servers? Stefan Kirch Microsoft Windows 2000 Networking 2 31st Jan 2004 06:05 PM
DNS root servers =?Utf-8?B?RG9taW5paw==?= Microsoft Windows 2000 DNS 12 11th Jan 2004 09:51 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 06:54 PM.