In news:(E-Mail Removed),
(E-Mail Removed) <(E-Mail Removed)> stated, which I commented on
below:
> Hi all
>
> We have internal(2000) and external dns servers(2003).
> Internal dns's forward all queries to external and external dns's ask
> Root servsers.
>
> Everything is ok and all clients query any name any time.
>
> The problem is that internal dns servers wants to connect root dns
> servers "directly" although forwarders(external dnss) are entered.
>
> Also sometimes some of the clients makes udp-domain connecitons to
> root servers directly.
>
> We think that there is a problem in servers and/or clients.
>
> I search previous problems and we are not using single label domain
> and cpu/ram are ok in the internal dns servers.
>
> Is there any opinion?
>
> Thanks
>
> Devrim
Keep in mind that the forwarder will be used first before the Roots. If it
is hitting the Roots, then either the forwarder is not allowing recursion,
or the domain name is not serviced by the US registrars, such as
Asian/Pacific domains, etc. Try 4.2.2.2 and see if that works as a
forwarder. Check your firewall logs.
Also, if you are seeing client traffic accessing external DNS servers, then
that is telling me that the clients have an external DNS address in their IP
config. In an AD domain, ALL machines, including the DC, must only have the
internal DNS and never ever use an external server. An external server does
not have the internal AD domain info so a client can find your internal
domain controller. This can cause numerous other errors as well.
--
Ace
Innovative IT Concepts, Inc (IITCI)
Willow Grove, PA
This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.
Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft MVP - Directory Services
Microsoft Certified Trainer
Having difficulty reading or finding responses to your post?
Instead of the website you're using, I suggest to use OEx (Outlook Express
or any other newsreader), and configure a news account, pointing to
news.microsoft.com. This is a direct link to the Microsoft Public
Newsgroups. It is FREE and requires NO ISP's Usenet account. OEx allows you
to easily find, track threads, cross-post, sort by date, poster's name,
watched threads or subject.
It's easy:
How to Configure OEx for Internet News
http://support.microsoft.com/?id=171164
Infinite Diversities in Infinite Combinations
Assimilation Imminent. Resistance is Futile
"Very funny Scotty. Now, beam down my clothes."
The only constant in life is change...