Conditional Forwarding Not Available

J

Jeff

In harmony with KB 229840 I attempted to delete the . root dns entry using
the dnscmd /ZoneDelete . /DsDel but received an error
DNS_ERROR_ZONE_DOES_NOT_EXIST 9601 (00002581)

If I look at the DNS Console I only see a . (root) entry in the cached
lookups and my regular domain is in the Forward Lookups.

When I choose properties, and click on the Forwarders tab, (which is not
grayed out) there is a message displayed that says: "Conditional Forwarding
is Not Available Because this Server is a Downlevel Server" and there is no
option to enable forwarders.

This machine connects to a Proxy Server which is behind a firewall. The
proxy server has one NIC and has three entries for DNS, one is the DNS
server mentioned above and the other two are the ISP Public DNS servers. I
am interested in removing the 2 ISP entries so that I can eliminate some
possible event errors such as 5774. But in order to do this, my clients all
point to the Proxy (client installed) so the Proxy would look to the DNS
server to resolve a name, but I don't think I have something right so that I
can enable Forwarding to ISP DNS servers.

How can I make this work.

Thanks
Jeff Smyrski
 
M

Michael Snyder [MSFT]

The existence of a .(root) zone means that this DNS server is the authority
for the entire DNS namespace (according to it).
Forwarders and Root hints point to a different server that knows more about
the DNS namespace than the local server does, and are therefore not
available when a .(root) zone exists.

If you need forwarders, delete the root zone and then you will be able to
create forwarders.
Additionally, W2k does not have the ability to create name-specific
forwarders, which is why you are getting the downlevel message.
 
M

Michael Snyder [MSFT]

I am not sure that I read you message correctly before sending my earlier
response.
Have you tried the /zonedelete command without the /DsDel option? Perhaps
your zone is file-backed instead of AD-backed?

From the KB article:
Note The /DsDel switch is required only if the zone is integrated with
Active Directory.
 
J

Joe Wu [MSFT]

Dear Jeff,

Thank you for your post.

Actually, it is normal that there is a "." zone in the Cached Lookups
folder and it does not affect the forward/root hint functions. We do not
need to delete it, if there is no "." zone in the Forward Lookups Zones
folder.

I think that you have already removed the "." zone (in the Forward Lookups
Zones) before and this is why the "DNS_ERROR_ZONE_DOES_NOT_EXIST" error
appears.

To be honest, the "Conditional Forwarding is Not Available Because this
Server is a Downlevel Server" is a bit strange because "Conditional
Forwarding" is a new feature of Windows Server 2003.

On my lab, I used Windows Server 2003 DNS Management Snap-In to connect to
another "Windows 2000" DNS server, and in the Forwarders tab, I saw the
message "Conditional Forwarding is Not Available Because this Server is a
Downlevel Server".

However, please note that I can still enable a regular forwarder, although
the sentence makes it sound like forwarding isn't available at all.

Did you configure DNS in this way? Please try to add a regular forwarder to
see if it works.

However, if you cannot add a regular DNS forwarder, please let me know more
about your network topology. For example, are you using a Windows Server
2003 domain? Is the DNS server a Windows 2000 Server? And how did you
install DNS?

If you want, please also send the following to me at (e-mail address removed):

1. A screenshot of the Forwarders tab as well as screenshots of any error
messages you encounter.
2. All related Event Logs.

Thank you and have a nice day!

Regards,
Joe Wu
Product Support Services
Microsoft Corporation

Get Secure! - www.microsoft.com/security

====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.

--------------------
|From: "Jeff" <[email protected]>
|Subject: Conditional Forwarding Not Available
|Date: Thu, 25 Sep 2003 15:34:09 -0400
|Lines: 27
|X-Priority: 3
|X-MSMail-Priority: Normal
|X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
|X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
|Message-ID: <[email protected]>
|Newsgroups: microsoft.public.win2000.dns
|NNTP-Posting-Host: bankofutica-gate-line-r.bankofutica.com 216.230.225.242
|Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!tk2msftngp13.phx.gbl
|Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.dns:26616
|X-Tomcat-NG: microsoft.public.win2000.dns
|
|In harmony with KB 229840 I attempted to delete the . root dns entry using
|the dnscmd /ZoneDelete . /DsDel but received an error
|DNS_ERROR_ZONE_DOES_NOT_EXIST 9601 (00002581)
|
|If I look at the DNS Console I only see a . (root) entry in the cached
|lookups and my regular domain is in the Forward Lookups.
|
|When I choose properties, and click on the Forwarders tab, (which is not
|grayed out) there is a message displayed that says: "Conditional Forwarding
|is Not Available Because this Server is a Downlevel Server" and there is no
|option to enable forwarders.
|
|This machine connects to a Proxy Server which is behind a firewall. The
|proxy server has one NIC and has three entries for DNS, one is the DNS
|server mentioned above and the other two are the ISP Public DNS servers. I
|am interested in removing the 2 ISP entries so that I can eliminate some
|possible event errors such as 5774. But in order to do this, my clients
all
|point to the Proxy (client installed) so the Proxy would look to the DNS
|server to resolve a name, but I don't think I have something right so that
I
|can enable Forwarding to ISP DNS servers.
|
|How can I make this work.
|
|Thanks
|Jeff Smyrski
|
|
|
 
J

Jeff Smyrski

Okay not sure who typed it, but the W2K3 thing is the issue. First off this
is a Windows 2000 domain running in mixed mode since I still have several 95
and NT clients (not servers) on the network. DNS was originally set up at
the same time that we did Active Directory, all of this was a brand new
server from scratch. The network is rather simple, single building, no
routers one domain. Ill get back to the W2K3 thing in a second...

The whole backbone is behind a managed firewall, which includes the Proxy
Server which I use currently as an additional firewall for my authenticated
users, more so to regulate ports that they are allowed to use ie POP and
NEWS for example. The Proxy runs as a Backup Controller on the network to
the Operations Manager, and is the server configured with the OM as the
first DNS server in the list, followed by 2 other DNS server IPs for the
ISPs DNS servers. My attempt is to remove the 2 ISP entries and let the OM
(DNS server) forward these requests to the ISP DNS servers. I suspect that
because of the way this is currently set up, it is causing issues of
connectivity for network and internet that is related to new XP machines
that I am introducing to the network. I read somewhere that XP now uses DNS
for logging on the Network unlike previous versions (or something like
that...I can't remember where I read it...lol)

The Operations Manager runs as the WINS server for my 95 clients, but also
the DNS server for all internal requests. The . (root) is gone, I confirmed
this by adding it back and then using the same tool I previously described
to delete it. I confirmed the DNS is AD enabled as the Primary.

NOW here is the interesting part...you can direct me where to go from
here...lol.

The machine that I work from is XP...this was the first clue with the 2003
server hint. Because I perform lots of Admin functions from my terminal ie
AD Users / Sites, DNS! I had to install the W2K3 Admin Tools.msi so that
they would work. The problem is that the DNS snap in does not know that I
am connecting to a Windows 2000 domain (this seems to be an issue in my
book, and I wonder how many other tools are not working the way they
should.) Thus I receive the "Conditional Forwarding is not available because
this server is a downlevel server" which is as someone mentioned 2003 server
ONLY. If I run terminal services and connect to my OM (DNS server) and run
the DNS snap in there, I receive the correct screen, with the check
box...Enable Forwarders.

Okay...so where to from here.

My goal first off is to get my Proxy to work properly with my internal DNS
server, and allow my DNS server to cache the external requests and fetch the
other requests that come from my Proxy Clients -> to the Proxy/ISA -> to the
DNS server internal... I am thinking this will clear up a Netlogon Error
that i am receiving 5774 as shown below.

I know this is lengthy but I hope it helps.

Event Type: Error
Event Source: NETLOGON
Event Category: None
Event ID: 5774
Date: 9/26/2003
Time: 9:15:21 AM
User: N/A
Computer: PROXY_SERVER
Description:
Registration of the DNS record
'64cd0686-8e8f-48e2-97c4-cfde410841c9._msdcs.BANKOFUTICA.COM. 600 IN CNAME
proxy_server.BANKOFUTICA.COM.' failed with the following error:
DNS RR set that ought to exist, does not exist.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 30 23 00 00 0#..
 
J

Jeff Smyrski

Additional Info:

I added the ISP DNS entries in the 2K3 Snap in, then looked at the 2K
snap in, and the checkbox was checked, and the two entries were present.
Here is what I just tried.

With the two ISP entries present as forwarders, I removed the same entries
from the DNS tab on the Proxy Server, and only left the DNS server IP
present. I then attempted from my client to resolve CNN.COM it will not go.
I did not reboot or anything, I just made the changes, do changes like this
require reboots, or DNS start stop to make not only the forwarders to be
effective but also the NIC DNS registration?

Thanks
Jeff Smyrski
 
A

Ace Fekay [MVP]

In
Jeff said:
In harmony with KB 229840 I attempted to delete the . root dns entry
using the dnscmd /ZoneDelete . /DsDel but received an error
DNS_ERROR_ZONE_DOES_NOT_EXIST 9601 (00002581)

If I look at the DNS Console I only see a . (root) entry in the cached
lookups and my regular domain is in the Forward Lookups.

Just rt-click the zone, then choose delete or select it and hit the delete
button.
When I choose properties, and click on the Forwarders tab, (which is
not grayed out) there is a message displayed that says: "Conditional
Forwarding is Not Available Because this Server is a Downlevel
Server" and there is no option to enable forwarders.

You need to raise the domain functional level to W2k3. Rt-click your domain
name in ADUC, properties, it's in there.
This machine connects to a Proxy Server which is behind a firewall.
The proxy server has one NIC and has three entries for DNS, one is
the DNS server mentioned above and the other two are the ISP Public
DNS servers. I am interested in removing the 2 ISP entries so that I
can eliminate some possible event errors such as 5774. But in order
to do this, my clients all point to the Proxy (client installed) so
the Proxy would look to the DNS server to resolve a name, but I don't
think I have something right so that I can enable Forwarding to ISP
DNS servers.

Yes, good idea to remove the ISP's. Follow what I mentioned above and see if
that helps.
How can I make this work.

Thanks
Jeff Smyrski



--
Regards,
Ace

Please direct all replies to the newsgroup so all can benefit.
This posting is provided "AS IS" with no warranties.

Ace Fekay, MCSE 2000, MCSE+I, MCSA, MCT, MVP
Microsoft Windows MVP - Active Directory
 
M

Michael Snyder [MSFT]

Changes like this do not require reboots on the DNS server, however, you may
need to:
ipconfig /flushdns on clients to flush the dns client cache
ipconfig /registerdns on clients to make them re-register their A records
nltest /dsregdns on DCs to make them re-register their SRV records

--
Michael Snyder
Active Directory Admin Tool Test

This posting is provided "AS IS" with no warranties, and confers no rights.
 
M

Michael Snyder [MSFT]

Regarding your question on the administration tools, all of the W2k3 AD
Admin snapins (including DNS and most other tools) can re-target to W2k just
fine, however as in the case of DNS, the display is different and may be
confusing. W2k3 has two types of forwarders, W2k only had one. You can
configure the non-conditional forwarders on a W2k server using the W2k3
snapin, it is just that the display looks a little strange. If you run into
any functionality problems with those tools, please let me know and I'll
make sure that the right person hears about it and that we fix the problem
as soon as possible.

Regarding your network configuration, yes in W2k and W2k3 the DC locator
uses DNS records instead of WINS, however XP is backwards compatible enough
to join an NT4 domain using WINS to find the DC.

I would suggest asking your proxy server questions on
microsoft.public.win2000.networking.

I hope that helps.
 
J

Jeff Smyrski

I will attempt the ipconfig and nltest commands...
Where can I verify that an SRV record has been registered. I ask
because if I look in the DNS snapin for the server, I am not seeing any SRV
records. Should there be any?

Jeff
 
J

Jeff Smyrski

ipconfig /flushdns was performed this completed...

I removed the 2 ISP DNS entries from the NIC and left only the Internal DNS
server in the list.
I bounced the DNS client service as well

I used the ipconfig /flushdns at the DNS server this completed.
The DNS has two entries in the Forwarders tab of the DNS server properties,
both are for the ISP server.

I then ran nslookup at the command prompt, it returned Default Server
127.0.0.1
I entered www.cnn.com

It timed out after 2 seconds, server could not be found.

I then tried an attempt to connect via the web, but IE just hangs looking
for a way to resolve the URL.

Please help! Arrg

BTW the nltest does not have a /DSREGDNS option only a /DSDEREGDNS option.

Jeff Smyrski
 
M

Michael Snyder [MSFT]

nltest /dsregdns was added in W2k3. In W2k a quick way to get the same
effect is: net stop netlogon & net start netlogon

Try launching nslookup, then setting server=<ip address of your DNS server>,
and then try to resolve some name.
If you can resolve records that are on the DNS server, you could try the
same thing from your DNS server, but use the IP address of your ISP to make
sure that they are resolving the name.

nslookup will default to the "dns server" as defined in your TCP/IP
settings.

Do you have a proxy server in this setup? If so, where, and how is it
configured?

--
Michael Snyder
Active Directory Admin Tool Test

This posting is provided "AS IS" with no warranties, and confers no rights.
 
J

Jeff Smyrski

I do have a Proxy Server, it is currently generating Netlogon errors evey 4
hours in the system log event id 5774. I suspect that the issue is a dns
problem. The Proxy 2.0 server is currently uni-homed, but will soon be
upgraded to ISA server with 2 NICs. In my model currently it looks like
this.

Proxy Server - Behind Firewall with an Internal Interface on my
backbone. The gateway of the Proxy is pointing to the Firewall. (As opposed
to all other machines including my internal DNS server, they are all
pointing to the Proxy as the gateway.)
Proxy's NIC is configured with 3 DNS entries, the first (top of the
list) is the internal DNS server, the next are the two ISP DNS servers.
This is where I was attempting to remove the DNS entries for the ISP and
move them to the Forwarders section of the Internal DNS server, but I can't
get my DNS server to resolve names when I do this.

The internal DNS server also has one NIC, pointing to the Proxy for a
gateway, with one DNS entry 127.0.0.1 (itself)

If I try an nslookup at my workstation using my DNS server (by default)
it looks like this.

Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\jeff smyrski>nslookup
Default Server: bofu2000.bankofutica.com
Address: 192.168.1.13
Server: bofu2000.bankofutica.com
Address: 192.168.1.13

DNS request timed out.
timeout was 2 seconds.
*** Request to bofu2000.bankofutica.com timed-out
If I go to the DNS server I get the same error, but I can tell the DNS
server to use another IP, and it seems to be able to resolve the address,
even after the ipconfig /flushdns command (just to make sure)

In the future, I want to make this model work using an ISA server
(multi-homed) behind a firewall.

ISA Server NIC#1 - Remains the same, pointing to the Firewall as its
gateway, but only has the two ISP DNS server entries in it.

ISA Server NIC#2 - (New NIC Card, with new IP, will become gateway IP
for workstations. The actual Gateway of this NIC would either be blank or
the IP of the External NIC not sure on that one)
(Only one DNS entry would be associated
with this NIC, and it would be the Internal DNS server)

DNS Server NIC - Change Gateway to be the new IP of the new ISA NIC#2
also remove the Forwarder entries in DNS.

NOTE - The Proxy server soon to be ISA server is also a DC for Active
Directory, and I will be leaving this the same.

Let me know if this will work, and / or how I can improve it?
Thanks
Jeff Smyrski
 
J

Joe Wu [MSFT]

Dear Jeff,

Thank you for your updates.

Since the gateway on the DNS server is set to point to the proxy server,
the DNS query packets cannot be routed to the external DNS servers (ISP DNS
servers). However, the DNS query packets can be sent to the external DNS
from the proxy server, as the gateway of the proxy server itself is set to
the Firewall.

This should be the reason why the DNS forward does not work. Please go to
the DNS server and change the gateway from the proxy server to the Firewall
to see if the problem can be resolved.

In the meantime, I think your ISA upgrade should work (generally, we leave
the internal NIC's "Default gateway" blank on ISA server). You can get more
information from the following Knowledge Base article:

323387 HOW TO: Connect Your Company to the Internet by Using an ISA Firewall
http://support.microsoft.com/?id=323387

Please let me know if any thing is unclear. Thanks!

Regards,
Joe Wu
Product Support Services
Microsoft Corporation

Get Secure! - www.microsoft.com/security

====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.

--------------------
|From: "Jeff Smyrski" <[email protected]>
|References: <[email protected]>
<dhuumP#[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
|Subject: Re: Conditional Forwarding Not Available
|Date: Tue, 30 Sep 2003 08:56:31 -0400
|Lines: 337
|X-Priority: 3
|X-MSMail-Priority: Normal
|X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
|X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
|Message-ID: <[email protected]>
|Newsgroups: microsoft.public.win2000.dns
|NNTP-Posting-Host: bankofutica-gate-line-r.bankofutica.com 216.230.225.242
|Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP11.phx.gbl
|Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.dns:26915
|X-Tomcat-NG: microsoft.public.win2000.dns
|
|I do have a Proxy Server, it is currently generating Netlogon errors evey 4
|hours in the system log event id 5774. I suspect that the issue is a dns
|problem. The Proxy 2.0 server is currently uni-homed, but will soon be
|upgraded to ISA server with 2 NICs. In my model currently it looks like
|this.
|
| Proxy Server - Behind Firewall with an Internal Interface on my
|backbone. The gateway of the Proxy is pointing to the Firewall. (As
opposed
|to all other machines including my internal DNS server, they are all
|pointing to the Proxy as the gateway.)
| Proxy's NIC is configured with 3 DNS entries, the first (top of the
|list) is the internal DNS server, the next are the two ISP DNS servers.
|This is where I was attempting to remove the DNS entries for the ISP and
|move them to the Forwarders section of the Internal DNS server, but I can't
|get my DNS server to resolve names when I do this.
|
| The internal DNS server also has one NIC, pointing to the Proxy for a
|gateway, with one DNS entry 127.0.0.1 (itself)
|
| If I try an nslookup at my workstation using my DNS server (by default)
|it looks like this.
|
|Microsoft Windows XP [Version 5.1.2600]
|(C) Copyright 1985-2001 Microsoft Corp.
|
|C:\Documents and Settings\jeff smyrski>nslookup
|Default Server: bofu2000.bankofutica.com
|Address: 192.168.1.13
|
|> www.cnn.com
|Server: bofu2000.bankofutica.com
|Address: 192.168.1.13
|
|DNS request timed out.
| timeout was 2 seconds.
|*** Request to bofu2000.bankofutica.com timed-out
|>
|
| If I go to the DNS server I get the same error, but I can tell the DNS
|server to use another IP, and it seems to be able to resolve the address,
|even after the ipconfig /flushdns command (just to make sure)
|
|In the future, I want to make this model work using an ISA server
|(multi-homed) behind a firewall.
|
| ISA Server NIC#1 - Remains the same, pointing to the Firewall as its
|gateway, but only has the two ISP DNS server entries in it.
|
| ISA Server NIC#2 - (New NIC Card, with new IP, will become gateway IP
|for workstations. The actual Gateway of this NIC would either be blank or
|the IP of the External NIC not sure on that one)
| (Only one DNS entry would be
associated
|with this NIC, and it would be the Internal DNS server)
|
| DNS Server NIC - Change Gateway to be the new IP of the new ISA NIC#2
|also remove the Forwarder entries in DNS.
|
|NOTE - The Proxy server soon to be ISA server is also a DC for Active
|Directory, and I will be leaving this the same.
|
|Let me know if this will work, and / or how I can improve it?
|Thanks
|Jeff Smyrski
|
|
||> nltest /dsregdns was added in W2k3. In W2k a quick way to get the same
|> effect is: net stop netlogon & net start netlogon
|>
|> Try launching nslookup, then setting server=<ip address of your DNS
|server>,
|> and then try to resolve some name.
|> If you can resolve records that are on the DNS server, you could try the
|> same thing from your DNS server, but use the IP address of your ISP to
|make
|> sure that they are resolving the name.
|>
|> nslookup will default to the "dns server" as defined in your TCP/IP
|> settings.
|>
|> Do you have a proxy server in this setup? If so, where, and how is it
|> configured?
|>
|> --
|> Michael Snyder
|> Active Directory Admin Tool Test
|>
|> This posting is provided "AS IS" with no warranties, and confers no
|rights.
|>
|> |> > ipconfig /flushdns was performed this completed...
|> >
|> > I removed the 2 ISP DNS entries from the NIC and left only the Internal
|> DNS
|> > server in the list.
|> > I bounced the DNS client service as well
|> >
|> > I used the ipconfig /flushdns at the DNS server this completed.
|> > The DNS has two entries in the Forwarders tab of the DNS server
|> properties,
|> > both are for the ISP server.
|> >
|> > I then ran nslookup at the command prompt, it returned Default Server
|> > 127.0.0.1
|> > I entered www.cnn.com
|> >
|> > It timed out after 2 seconds, server could not be found.
|> >
|> > I then tried an attempt to connect via the web, but IE just hangs
|looking
|> > for a way to resolve the URL.
|> >
|> > Please help! Arrg
|> >
|> > BTW the nltest does not have a /DSREGDNS option only a /DSDEREGDNS
|option.
|> >
|> > Jeff Smyrski
|> >
|> > |> > > Changes like this do not require reboots on the DNS server, however,
|you
|> > may
|> > > need to:
|> > > ipconfig /flushdns on clients to flush the dns client cache
|> > > ipconfig /registerdns on clients to make them re-register their A
|> records
|> > > nltest /dsregdns on DCs to make them re-register their SRV records
|> > >
|> > > --
|> > > Michael Snyder
|> > > Active Directory Admin Tool Test
|> > >
|> > > This posting is provided "AS IS" with no warranties, and confers no
|> > rights.
|> > >
|> > > |> > > > Additional Info:
|> > > >
|> > > > I added the ISP DNS entries in the 2K3 Snap in, then looked at
|the
|> > 2K
|> > > > snap in, and the checkbox was checked, and the two entries were
|> present.
|> > > > Here is what I just tried.
|> > > >
|> > > > With the two ISP entries present as forwarders, I removed the same
|> > entries
|> > > > from the DNS tab on the Proxy Server, and only left the DNS server
|IP
|> > > > present. I then attempted from my client to resolve CNN.COM it
will
|> not
|> > > go.
|> > > > I did not reboot or anything, I just made the changes, do changes
|like
|> > > this
|> > > > require reboots, or DNS start stop to make not only the forwarders
|to
|> be
|> > > > effective but also the NIC DNS registration?
|> > > >
|> > > > Thanks
|> > > > Jeff Smyrski
|> > > >
|> > > > |> > > > > Dear Jeff,
|> > > > >
|> > > > > Thank you for your post.
|> > > > >
|> > > > > Actually, it is normal that there is a "." zone in the Cached
|> Lookups
|> > > > > folder and it does not affect the forward/root hint functions. We
|do
|> > not
|> > > > > need to delete it, if there is no "." zone in the Forward Lookups
|> > Zones
|> > > > > folder.
|> > > > >
|> > > > > I think that you have already removed the "." zone (in the
Forward
|> > > Lookups
|> > > > > Zones) before and this is why the "DNS_ERROR_ZONE_DOES_NOT_EXIST"
|> > error
|> > > > > appears.
|> > > > >
|> > > > > To be honest, the "Conditional Forwarding is Not Available
Because
|> > this
|> > > > > Server is a Downlevel Server" is a bit strange because
|"Conditional
|> > > > > Forwarding" is a new feature of Windows Server 2003.
|> > > > >
|> > > > > On my lab, I used Windows Server 2003 DNS Management Snap-In to
|> > connect
|> > > to
|> > > > > another "Windows 2000" DNS server, and in the Forwarders tab, I
|saw
|> > the
|> > > > > message "Conditional Forwarding is Not Available Because this
|Server
|> > is
|> > > a
|> > > > > Downlevel Server".
|> > > > >
|> > > > > However, please note that I can still enable a regular forwarder,
|> > > although
|> > > > > the sentence makes it sound like forwarding isn't available at
|all.
|> > > > >
|> > > > > Did you configure DNS in this way? Please try to add a regular
|> > forwarder
|> > > > to
|> > > > > see if it works.
|> > > > >
|> > > > > However, if you cannot add a regular DNS forwarder, please let me
|> know
|> > > > more
|> > > > > about your network topology. For example, are you using a Windows
|> > Server
|> > > > > 2003 domain? Is the DNS server a Windows 2000 Server? And how did
|> you
|> > > > > install DNS?
|> > > > >
|> > > > > If you want, please also send the following to me at
|> > > (e-mail address removed):
|> > > > >
|> > > > > 1. A screenshot of the Forwarders tab as well as screenshots of
|any
|> > > error
|> > > > > messages you encounter.
|> > > > > 2. All related Event Logs.
|> > > > >
|> > > > > Thank you and have a nice day!
|> > > > >
|> > > > > Regards,
|> > > > > Joe Wu
|> > > > > Product Support Services
|> > > > > Microsoft Corporation
|> > > > >
|> > > > > Get Secure! - www.microsoft.com/security
|> > > > >
|> > > > > ====================================================
|> > > > > When responding to posts, please "Reply to Group" via your
|> newsreader
|> > so
|> > > > > that others may learn and benefit from your issue.
|> > > > > ====================================================
|> > > > > This posting is provided "AS IS" with no warranties, and confers
|no
|> > > > rights.
|> > > > >
|> > > > > --------------------
|> > > > > |From: "Jeff" <[email protected]>
|> > > > > |Subject: Conditional Forwarding Not Available
|> > > > > |Date: Thu, 25 Sep 2003 15:34:09 -0400
|> > > > > |Lines: 27
|> > > > > |X-Priority: 3
|> > > > > |X-MSMail-Priority: Normal
|> > > > > |X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
|> > > > > |X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
|> > > > > |Message-ID: <[email protected]>
|> > > > > |Newsgroups: microsoft.public.win2000.dns
|> > > > > |NNTP-Posting-Host: bankofutica-gate-line-r.bankofutica.com
|> > > > 216.230.225.242
|> > > > > |Path:
|> cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!tk2msftngp13.phx.gbl
|> > > > > |Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.dns:26616
|> > > > > |X-Tomcat-NG: microsoft.public.win2000.dns
|> > > > > |
|> > > > > |In harmony with KB 229840 I attempted to delete the . root dns
|> entry
|> > > > using
|> > > > > |the dnscmd /ZoneDelete . /DsDel but received an error
|> > > > > |DNS_ERROR_ZONE_DOES_NOT_EXIST 9601 (00002581)
|> > > > > |
|> > > > > |If I look at the DNS Console I only see a . (root) entry in the
|> > cached
|> > > > > |lookups and my regular domain is in the Forward Lookups.
|> > > > > |
|> > > > > |When I choose properties, and click on the Forwarders tab,
(which
|> is
|> > > not
|> > > > > |grayed out) there is a message displayed that says: "Conditional
|> > > > Forwarding
|> > > > > |is Not Available Because this Server is a Downlevel Server" and
|> there
|> > > is
|> > > > no
|> > > > > |option to enable forwarders.
|> > > > > |
|> > > > > |This machine connects to a Proxy Server which is behind a
|firewall.
|> > > The
|> > > > > |proxy server has one NIC and has three entries for DNS, one is
|the
|> > DNS
|> > > > > |server mentioned above and the other two are the ISP Public DNS
|> > > servers.
|> > > > I
|> > > > > |am interested in removing the 2 ISP entries so that I can
|eliminate
|> > > some
|> > > > > |possible event errors such as 5774. But in order to do this, my
|> > > clients
|> > > > > all
|> > > > > |point to the Proxy (client installed) so the Proxy would look to
|> the
|> > > DNS
|> > > > > |server to resolve a name, but I don't think I have something
|right
|> so
|> > > > that
|> > > > > I
|> > > > > |can enable Forwarding to ISP DNS servers.
|> > > > > |
|> > > > > |How can I make this work.
|> > > > > |
|> > > > > |Thanks
|> > > > > |Jeff Smyrski
|> > > > > |
|> > > > > |
|> > > > > |
|> > > > >
|> > > >
|> > > >
|> > >
|> > >
|> >
|> >
|>
|>
|
|
|
 
J

Jeff Smyrski

I made the change you suggested, and made the gateway of the DNS server to
be the Firewall IP. I left Proxy as is, since this should not matter. Keep
in mind that the DNS server does have the Proxy Client installed on it, so
that it can go out the Proxy for web related matters such as Windows Update.
The Proxy does not have Proxy Client installed on it...for obvious reasons.

The DNS server, is only allowed to go out I think it is port 53 UDP not TCP.
Only the Proxy Server has the rights in the firewall rules to go out for all
other defined ports.

After doing all of that, the DNS server still can not resolve a DNS name
outside of the domain, using the NSLOOKUP when it defaults to the localhost
127.0.0.1 address.

If I type server at the nslookup prompt, and enter 216.238.0.10 the IP of
the ISP DNS server, I can resolve all I want, it even returns the name of
the server, no prob.

I MUST be missing something with these forwarders...it should work but does
not!

Do you know, or are you sure that the NSLOOKUP is using UDP where as the
Forwarders are using TCP?

Please let me know.

Jeff Smyrski

Joe Wu said:
Dear Jeff,

Thank you for your updates.

Since the gateway on the DNS server is set to point to the proxy server,
the DNS query packets cannot be routed to the external DNS servers (ISP DNS
servers). However, the DNS query packets can be sent to the external DNS
from the proxy server, as the gateway of the proxy server itself is set to
the Firewall.

This should be the reason why the DNS forward does not work. Please go to
the DNS server and change the gateway from the proxy server to the Firewall
to see if the problem can be resolved.

In the meantime, I think your ISA upgrade should work (generally, we leave
the internal NIC's "Default gateway" blank on ISA server). You can get more
information from the following Knowledge Base article:

323387 HOW TO: Connect Your Company to the Internet by Using an ISA Firewall
http://support.microsoft.com/?id=323387

Please let me know if any thing is unclear. Thanks!

Regards,
Joe Wu
Product Support Services
Microsoft Corporation

Get Secure! - www.microsoft.com/security

====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.

--------------------
|From: "Jeff Smyrski" <[email protected]>
|References: <[email protected]>
<dhuumP#[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
|Subject: Re: Conditional Forwarding Not Available
|Date: Tue, 30 Sep 2003 08:56:31 -0400
|Lines: 337
|X-Priority: 3
|X-MSMail-Priority: Normal
|X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
|X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
|Message-ID: <[email protected]>
|Newsgroups: microsoft.public.win2000.dns
|NNTP-Posting-Host: bankofutica-gate-line-r.bankofutica.com 216.230.225.242
|Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP11.phx.gbl
|Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.dns:26915
|X-Tomcat-NG: microsoft.public.win2000.dns
|
|I do have a Proxy Server, it is currently generating Netlogon errors evey 4
|hours in the system log event id 5774. I suspect that the issue is a dns
|problem. The Proxy 2.0 server is currently uni-homed, but will soon be
|upgraded to ISA server with 2 NICs. In my model currently it looks like
|this.
|
| Proxy Server - Behind Firewall with an Internal Interface on my
|backbone. The gateway of the Proxy is pointing to the Firewall. (As
opposed
|to all other machines including my internal DNS server, they are all
|pointing to the Proxy as the gateway.)
| Proxy's NIC is configured with 3 DNS entries, the first (top of the
|list) is the internal DNS server, the next are the two ISP DNS servers.
|This is where I was attempting to remove the DNS entries for the ISP and
|move them to the Forwarders section of the Internal DNS server, but I can't
|get my DNS server to resolve names when I do this.
|
| The internal DNS server also has one NIC, pointing to the Proxy for a
|gateway, with one DNS entry 127.0.0.1 (itself)
|
| If I try an nslookup at my workstation using my DNS server (by default)
|it looks like this.
|
|Microsoft Windows XP [Version 5.1.2600]
|(C) Copyright 1985-2001 Microsoft Corp.
|
|C:\Documents and Settings\jeff smyrski>nslookup
|Default Server: bofu2000.bankofutica.com
|Address: 192.168.1.13
|
|> www.cnn.com
|Server: bofu2000.bankofutica.com
|Address: 192.168.1.13
|
|DNS request timed out.
| timeout was 2 seconds.
|*** Request to bofu2000.bankofutica.com timed-out
|>
|
| If I go to the DNS server I get the same error, but I can tell the DNS
|server to use another IP, and it seems to be able to resolve the address,
|even after the ipconfig /flushdns command (just to make sure)
|
|In the future, I want to make this model work using an ISA server
|(multi-homed) behind a firewall.
|
| ISA Server NIC#1 - Remains the same, pointing to the Firewall as its
|gateway, but only has the two ISP DNS server entries in it.
|
| ISA Server NIC#2 - (New NIC Card, with new IP, will become gateway IP
|for workstations. The actual Gateway of this NIC would either be blank or
|the IP of the External NIC not sure on that one)
| (Only one DNS entry would be
associated
|with this NIC, and it would be the Internal DNS server)
|
| DNS Server NIC - Change Gateway to be the new IP of the new ISA NIC#2
|also remove the Forwarder entries in DNS.
|
|NOTE - The Proxy server soon to be ISA server is also a DC for Active
|Directory, and I will be leaving this the same.
|
|Let me know if this will work, and / or how I can improve it?
|Thanks
|Jeff Smyrski
|
|
||> nltest /dsregdns was added in W2k3. In W2k a quick way to get the same
|> effect is: net stop netlogon & net start netlogon
|>
|> Try launching nslookup, then setting server=<ip address of your DNS
|server>,
|> and then try to resolve some name.
|> If you can resolve records that are on the DNS server, you could try the
|> same thing from your DNS server, but use the IP address of your ISP to
|make
|> sure that they are resolving the name.
|>
|> nslookup will default to the "dns server" as defined in your TCP/IP
|> settings.
|>
|> Do you have a proxy server in this setup? If so, where, and how is it
|> configured?
|>
|> --
|> Michael Snyder
|> Active Directory Admin Tool Test
|>
|> This posting is provided "AS IS" with no warranties, and confers no
|rights.
|>
|> |> > ipconfig /flushdns was performed this completed...
|> >
|> > I removed the 2 ISP DNS entries from the NIC and left only the Internal
|> DNS
|> > server in the list.
|> > I bounced the DNS client service as well
|> >
|> > I used the ipconfig /flushdns at the DNS server this completed.
|> > The DNS has two entries in the Forwarders tab of the DNS server
|> properties,
|> > both are for the ISP server.
|> >
|> > I then ran nslookup at the command prompt, it returned Default Server
|> > 127.0.0.1
|> > I entered www.cnn.com
|> >
|> > It timed out after 2 seconds, server could not be found.
|> >
|> > I then tried an attempt to connect via the web, but IE just hangs
|looking
|> > for a way to resolve the URL.
|> >
|> > Please help! Arrg
|> >
|> > BTW the nltest does not have a /DSREGDNS option only a /DSDEREGDNS
|option.
|> >
|> > Jeff Smyrski
|> >
|> > |> > > Changes like this do not require reboots on the DNS server, however,
|you
|> > may
|> > > need to:
|> > > ipconfig /flushdns on clients to flush the dns client cache
|> > > ipconfig /registerdns on clients to make them re-register their A
|> records
|> > > nltest /dsregdns on DCs to make them re-register their SRV records
|> > >
|> > > --
|> > > Michael Snyder
|> > > Active Directory Admin Tool Test
|> > >
|> > > This posting is provided "AS IS" with no warranties, and confers no
|> > rights.
|> > >
|> > > |> > > > Additional Info:
|> > > >
|> > > > I added the ISP DNS entries in the 2K3 Snap in, then looked at
|the
|> > 2K
|> > > > snap in, and the checkbox was checked, and the two entries were
|> present.
|> > > > Here is what I just tried.
|> > > >
|> > > > With the two ISP entries present as forwarders, I removed the same
|> > entries
|> > > > from the DNS tab on the Proxy Server, and only left the DNS server
|IP
|> > > > present. I then attempted from my client to resolve CNN.COM it
will
|> not
|> > > go.
|> > > > I did not reboot or anything, I just made the changes, do changes
|like
|> > > this
|> > > > require reboots, or DNS start stop to make not only the forwarders
|to
|> be
|> > > > effective but also the NIC DNS registration?
|> > > >
|> > > > Thanks
|> > > > Jeff Smyrski
|> > > >
|> > > > |> > > > > Dear Jeff,
|> > > > >
|> > > > > Thank you for your post.
|> > > > >
|> > > > > Actually, it is normal that there is a "." zone in the Cached
|> Lookups
|> > > > > folder and it does not affect the forward/root hint functions. We
|do
|> > not
|> > > > > need to delete it, if there is no "." zone in the Forward Lookups
|> > Zones
|> > > > > folder.
|> > > > >
|> > > > > I think that you have already removed the "." zone (in the
Forward
|> > > Lookups
|> > > > > Zones) before and this is why the "DNS_ERROR_ZONE_DOES_NOT_EXIST"
|> > error
|> > > > > appears.
|> > > > >
|> > > > > To be honest, the "Conditional Forwarding is Not Available
Because
|> > this
|> > > > > Server is a Downlevel Server" is a bit strange because
|"Conditional
|> > > > > Forwarding" is a new feature of Windows Server 2003.
|> > > > >
|> > > > > On my lab, I used Windows Server 2003 DNS Management Snap-In to
|> > connect
|> > > to
|> > > > > another "Windows 2000" DNS server, and in the Forwarders tab, I
|saw
|> > the
|> > > > > message "Conditional Forwarding is Not Available Because this
|Server
|> > is
|> > > a
|> > > > > Downlevel Server".
|> > > > >
|> > > > > However, please note that I can still enable a regular forwarder,
|> > > although
|> > > > > the sentence makes it sound like forwarding isn't available at
|all.
|> > > > >
|> > > > > Did you configure DNS in this way? Please try to add a regular
|> > forwarder
|> > > > to
|> > > > > see if it works.
|> > > > >
|> > > > > However, if you cannot add a regular DNS forwarder, please let me
|> know
|> > > > more
|> > > > > about your network topology. For example, are you using a Windows
|> > Server
|> > > > > 2003 domain? Is the DNS server a Windows 2000 Server? And how did
|> you
|> > > > > install DNS?
|> > > > >
|> > > > > If you want, please also send the following to me at
|> > > (e-mail address removed):
|> > > > >
|> > > > > 1. A screenshot of the Forwarders tab as well as screenshots of
|any
|> > > error
|> > > > > messages you encounter.
|> > > > > 2. All related Event Logs.
|> > > > >
|> > > > > Thank you and have a nice day!
|> > > > >
|> > > > > Regards,
|> > > > > Joe Wu
|> > > > > Product Support Services
|> > > > > Microsoft Corporation
|> > > > >
|> > > > > Get Secure! - www.microsoft.com/security
|> > > > >
|> > > > > ====================================================
|> > > > > When responding to posts, please "Reply to Group" via your
|> newsreader
|> > so
|> > > > > that others may learn and benefit from your issue.
|> > > > > ====================================================
|> > > > > This posting is provided "AS IS" with no warranties, and confers
|no
|> > > > rights.
|> > > > >
|> > > > > --------------------
|> > > > > |From: "Jeff" <[email protected]>
|> > > > > |Subject: Conditional Forwarding Not Available
|> > > > > |Date: Thu, 25 Sep 2003 15:34:09 -0400
|> > > > > |Lines: 27
|> > > > > |X-Priority: 3
|> > > > > |X-MSMail-Priority: Normal
|> > > > > |X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
|> > > > > |X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
|> > > > > |Message-ID: <[email protected]>
|> > > > > |Newsgroups: microsoft.public.win2000.dns
|> > > > > |NNTP-Posting-Host: bankofutica-gate-line-r.bankofutica.com
|> > > > 216.230.225.242
|> > > > > |Path:
|> cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!tk2msftngp13.phx.gbl
|> > > > > |Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.dns:26616
|> > > > > |X-Tomcat-NG: microsoft.public.win2000.dns
|> > > > > |
|> > > > > |In harmony with KB 229840 I attempted to delete the . root dns
|> entry
|> > > > using
|> > > > > |the dnscmd /ZoneDelete . /DsDel but received an error
|> > > > > |DNS_ERROR_ZONE_DOES_NOT_EXIST 9601 (00002581)
|> > > > > |
|> > > > > |If I look at the DNS Console I only see a . (root) entry in the
|> > cached
|> > > > > |lookups and my regular domain is in the Forward Lookups.
|> > > > > |
|> > > > > |When I choose properties, and click on the Forwarders tab,
(which
|> is
|> > > not
|> > > > > |grayed out) there is a message displayed that says: "Conditional
|> > > > Forwarding
|> > > > > |is Not Available Because this Server is a Downlevel Server" and
|> there
|> > > is
|> > > > no
|> > > > > |option to enable forwarders.
|> > > > > |
|> > > > > |This machine connects to a Proxy Server which is behind a
|firewall.
|> > > The
|> > > > > |proxy server has one NIC and has three entries for DNS, one is
|the
|> > DNS
|> > > > > |server mentioned above and the other two are the ISP Public DNS
|> > > servers.
|> > > > I
|> > > > > |am interested in removing the 2 ISP entries so that I can
|eliminate
|> > > some
|> > > > > |possible event errors such as 5774. But in order to do this, my
|> > > clients
|> > > > > all
|> > > > > |point to the Proxy (client installed) so the Proxy would look to
|> the
|> > > DNS
|> > > > > |server to resolve a name, but I don't think I have something
|right
|> so
|> > > > that
|> > > > > I
|> > > > > |can enable Forwarding to ISP DNS servers.
|> > > > > |
|> > > > > |How can I make this work.
|> > > > > |
|> > > > > |Thanks
|> > > > > |Jeff Smyrski
|> > > > > |
|> > > > > |
|> > > > > |
|> > > > >
|> > > >
|> > > >
|> > >
|> > >
|> >
|> >
|>
|>
|
|
|
 
J

Joe Wu [MSFT]

Dear Jeff,

Thank you for your reply.

By default, the DNS server sends queries to other DNS servers using User
Datagram Protocol (UDP) port 53. However, this can be customized by
adjusting registry entries.

To narrow down the problem's scope, please check the following:

1. Please install DNS and configure a zone for the domain on your proxy
server. Add the ISP DNS servers to the proxy server's forwarder and then
change the local TCP/IP settings to only use itself as the Preferred DNS.
Check if the forwarder works on this server.

If the problem still occurs on this server, I think we need to check the
firewall settings to check if the DNS query packets are blocked.

2. Please check if the following registry entries exist on the two servers:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters
Value Name: SendPort
Value type: REG_DWORD

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters
Value Name: SendOnNonDnsPort
Data Type : REG_DWORD

Thank you for your time and efforts!

Regards,
Joe Wu
Product Support Services
Microsoft Corporation

Get Secure! - www.microsoft.com/security

====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.

--------------------
|From: "Jeff Smyrski" <[email protected]>
|References: <[email protected]>
<dhuumP#[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
|Subject: Re: Conditional Forwarding Not Available
|Date: Wed, 1 Oct 2003 16:01:02 -0400
|Lines: 468
|X-Priority: 3
|X-MSMail-Priority: Normal
|X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
|X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
|Message-ID: <[email protected]>
|Newsgroups: microsoft.public.win2000.dns
|NNTP-Posting-Host: bankofutica-gate-line-r.bankofutica.com 216.230.225.242
|Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP09.phx.gbl
|Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.dns:27054
|X-Tomcat-NG: microsoft.public.win2000.dns
|
|I made the change you suggested, and made the gateway of the DNS server to
|be the Firewall IP. I left Proxy as is, since this should not matter.
Keep
|in mind that the DNS server does have the Proxy Client installed on it, so
|that it can go out the Proxy for web related matters such as Windows
Update.
|The Proxy does not have Proxy Client installed on it...for obvious reasons.
|
|The DNS server, is only allowed to go out I think it is port 53 UDP not
TCP.
|Only the Proxy Server has the rights in the firewall rules to go out for
all
|other defined ports.
|
|After doing all of that, the DNS server still can not resolve a DNS name
|outside of the domain, using the NSLOOKUP when it defaults to the localhost
|127.0.0.1 address.
|
|If I type server at the nslookup prompt, and enter 216.238.0.10 the IP of
|the ISP DNS server, I can resolve all I want, it even returns the name of
|the server, no prob.
|
|I MUST be missing something with these forwarders...it should work but does
|not!
|
|Do you know, or are you sure that the NSLOOKUP is using UDP where as the
|Forwarders are using TCP?
|
|Please let me know.
|
|Jeff Smyrski
|
||> Dear Jeff,
|>
|> Thank you for your updates.
|>
|> Since the gateway on the DNS server is set to point to the proxy server,
|> the DNS query packets cannot be routed to the external DNS servers (ISP
|DNS
|> servers). However, the DNS query packets can be sent to the external DNS
|> from the proxy server, as the gateway of the proxy server itself is set
to
|> the Firewall.
|>
|> This should be the reason why the DNS forward does not work. Please go to
|> the DNS server and change the gateway from the proxy server to the
|Firewall
|> to see if the problem can be resolved.
|>
|> In the meantime, I think your ISA upgrade should work (generally, we
leave
|> the internal NIC's "Default gateway" blank on ISA server). You can get
|more
|> information from the following Knowledge Base article:
|>
|> 323387 HOW TO: Connect Your Company to the Internet by Using an ISA
|Firewall
|> http://support.microsoft.com/?id=323387
|>
|> Please let me know if any thing is unclear. Thanks!
|>
|> Regards,
|> Joe Wu
|> Product Support Services
|> Microsoft Corporation
|>
|> Get Secure! - www.microsoft.com/security
|>
|> ====================================================
|> When responding to posts, please "Reply to Group" via your newsreader so
|> that others may learn and benefit from your issue.
|> ====================================================
|> This posting is provided "AS IS" with no warranties, and confers no
|rights.
|>
|> --------------------
|> |From: "Jeff Smyrski" <[email protected]>
|> |References: <[email protected]>
|> <dhuumP#[email protected]>
|> <[email protected]>
|> <[email protected]>
|> <[email protected]>
|> <[email protected]>
|> |Subject: Re: Conditional Forwarding Not Available
|> |Date: Tue, 30 Sep 2003 08:56:31 -0400
|> |Lines: 337
|> |X-Priority: 3
|> |X-MSMail-Priority: Normal
|> |X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
|> |X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
|> |Message-ID: <[email protected]>
|> |Newsgroups: microsoft.public.win2000.dns
|> |NNTP-Posting-Host: bankofutica-gate-line-r.bankofutica.com
|216.230.225.242
|> |Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP11.phx.gbl
|> |Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.dns:26915
|> |X-Tomcat-NG: microsoft.public.win2000.dns
|> |
|> |I do have a Proxy Server, it is currently generating Netlogon errors
evey
|4
|> |hours in the system log event id 5774. I suspect that the issue is a
dns
|> |problem. The Proxy 2.0 server is currently uni-homed, but will soon be
|> |upgraded to ISA server with 2 NICs. In my model currently it looks like
|> |this.
|> |
|> | Proxy Server - Behind Firewall with an Internal Interface on my
|> |backbone. The gateway of the Proxy is pointing to the Firewall. (As
|> opposed
|> |to all other machines including my internal DNS server, they are all
|> |pointing to the Proxy as the gateway.)
|> | Proxy's NIC is configured with 3 DNS entries, the first (top of the
|> |list) is the internal DNS server, the next are the two ISP DNS servers.
|> |This is where I was attempting to remove the DNS entries for the ISP and
|> |move them to the Forwarders section of the Internal DNS server, but I
|can't
|> |get my DNS server to resolve names when I do this.
|> |
|> | The internal DNS server also has one NIC, pointing to the Proxy for
a
|> |gateway, with one DNS entry 127.0.0.1 (itself)
|> |
|> | If I try an nslookup at my workstation using my DNS server (by
|default)
|> |it looks like this.
|> |
|> |Microsoft Windows XP [Version 5.1.2600]
|> |(C) Copyright 1985-2001 Microsoft Corp.
|> |
|> |C:\Documents and Settings\jeff smyrski>nslookup
|> |Default Server: bofu2000.bankofutica.com
|> |Address: 192.168.1.13
|> |
|> |> www.cnn.com
|> |Server: bofu2000.bankofutica.com
|> |Address: 192.168.1.13
|> |
|> |DNS request timed out.
|> | timeout was 2 seconds.
|> |*** Request to bofu2000.bankofutica.com timed-out
|> |>
|> |
|> | If I go to the DNS server I get the same error, but I can tell the
|DNS
|> |server to use another IP, and it seems to be able to resolve the
address,
|> |even after the ipconfig /flushdns command (just to make sure)
|> |
|> |In the future, I want to make this model work using an ISA server
|> |(multi-homed) behind a firewall.
|> |
|> | ISA Server NIC#1 - Remains the same, pointing to the Firewall as its
|> |gateway, but only has the two ISP DNS server entries in it.
|> |
|> | ISA Server NIC#2 - (New NIC Card, with new IP, will become gateway
IP
|> |for workstations. The actual Gateway of this NIC would either be blank
|or
|> |the IP of the External NIC not sure on that one)
|> | (Only one DNS entry would be
|> associated
|> |with this NIC, and it would be the Internal DNS server)
|> |
|> | DNS Server NIC - Change Gateway to be the new IP of the new ISA
NIC#2
|> |also remove the Forwarder entries in DNS.
|> |
|> |NOTE - The Proxy server soon to be ISA server is also a DC for Active
|> |Directory, and I will be leaving this the same.
|> |
|> |Let me know if this will work, and / or how I can improve it?
|> |Thanks
|> |Jeff Smyrski
|> |
|> |
|> ||> |> nltest /dsregdns was added in W2k3. In W2k a quick way to get the
same
|> |> effect is: net stop netlogon & net start netlogon
|> |>
|> |> Try launching nslookup, then setting server=<ip address of your DNS
|> |server>,
|> |> and then try to resolve some name.
|> |> If you can resolve records that are on the DNS server, you could try
|the
|> |> same thing from your DNS server, but use the IP address of your ISP to
|> |make
|> |> sure that they are resolving the name.
|> |>
|> |> nslookup will default to the "dns server" as defined in your TCP/IP
|> |> settings.
|> |>
|> |> Do you have a proxy server in this setup? If so, where, and how is it
|> |> configured?
|> |>
|> |> --
|> |> Michael Snyder
|> |> Active Directory Admin Tool Test
|> |>
|> |> This posting is provided "AS IS" with no warranties, and confers no
|> |rights.
|> |>
|> |> |> |> > ipconfig /flushdns was performed this completed...
|> |> >
|> |> > I removed the 2 ISP DNS entries from the NIC and left only the
|Internal
|> |> DNS
|> |> > server in the list.
|> |> > I bounced the DNS client service as well
|> |> >
|> |> > I used the ipconfig /flushdns at the DNS server this completed.
|> |> > The DNS has two entries in the Forwarders tab of the DNS server
|> |> properties,
|> |> > both are for the ISP server.
|> |> >
|> |> > I then ran nslookup at the command prompt, it returned Default
Server
|> |> > 127.0.0.1
|> |> > I entered www.cnn.com
|> |> >
|> |> > It timed out after 2 seconds, server could not be found.
|> |> >
|> |> > I then tried an attempt to connect via the web, but IE just hangs
|> |looking
|> |> > for a way to resolve the URL.
|> |> >
|> |> > Please help! Arrg
|> |> >
|> |> > BTW the nltest does not have a /DSREGDNS option only a /DSDEREGDNS
|> |option.
|> |> >
|> |> > Jeff Smyrski
|> |> >
|message
|> |> > |> |> > > Changes like this do not require reboots on the DNS server,
|however,
|> |you
|> |> > may
|> |> > > need to:
|> |> > > ipconfig /flushdns on clients to flush the dns client cache
|> |> > > ipconfig /registerdns on clients to make them re-register their A
|> |> records
|> |> > > nltest /dsregdns on DCs to make them re-register their SRV records
|> |> > >
|> |> > > --
|> |> > > Michael Snyder
|> |> > > Active Directory Admin Tool Test
|> |> > >
|> |> > > This posting is provided "AS IS" with no warranties, and confers
no
|> |> > rights.
|> |> > >
|> |> > > |> |> > > > Additional Info:
|> |> > > >
|> |> > > > I added the ISP DNS entries in the 2K3 Snap in, then looked
|at
|> |the
|> |> > 2K
|> |> > > > snap in, and the checkbox was checked, and the two entries were
|> |> present.
|> |> > > > Here is what I just tried.
|> |> > > >
|> |> > > > With the two ISP entries present as forwarders, I removed the
|same
|> |> > entries
|> |> > > > from the DNS tab on the Proxy Server, and only left the DNS
|server
|> |IP
|> |> > > > present. I then attempted from my client to resolve CNN.COM it
|> will
|> |> not
|> |> > > go.
|> |> > > > I did not reboot or anything, I just made the changes, do
changes
|> |like
|> |> > > this
|> |> > > > require reboots, or DNS start stop to make not only the
|forwarders
|> |to
|> |> be
|> |> > > > effective but also the NIC DNS registration?
|> |> > > >
|> |> > > > Thanks
|> |> > > > Jeff Smyrski
|> |> > > >
|> |> > > > |> |> > > > > Dear Jeff,
|> |> > > > >
|> |> > > > > Thank you for your post.
|> |> > > > >
|> |> > > > > Actually, it is normal that there is a "." zone in the Cached
|> |> Lookups
|> |> > > > > folder and it does not affect the forward/root hint functions.
|We
|> |do
|> |> > not
|> |> > > > > need to delete it, if there is no "." zone in the Forward
|Lookups
|> |> > Zones
|> |> > > > > folder.
|> |> > > > >
|> |> > > > > I think that you have already removed the "." zone (in the
|> Forward
|> |> > > Lookups
|> |> > > > > Zones) before and this is why the
|"DNS_ERROR_ZONE_DOES_NOT_EXIST"
|> |> > error
|> |> > > > > appears.
|> |> > > > >
|> |> > > > > To be honest, the "Conditional Forwarding is Not Available
|> Because
|> |> > this
|> |> > > > > Server is a Downlevel Server" is a bit strange because
|> |"Conditional
|> |> > > > > Forwarding" is a new feature of Windows Server 2003.
|> |> > > > >
|> |> > > > > On my lab, I used Windows Server 2003 DNS Management Snap-In
to
|> |> > connect
|> |> > > to
|> |> > > > > another "Windows 2000" DNS server, and in the Forwarders tab,
I
|> |saw
|> |> > the
|> |> > > > > message "Conditional Forwarding is Not Available Because this
|> |Server
|> |> > is
|> |> > > a
|> |> > > > > Downlevel Server".
|> |> > > > >
|> |> > > > > However, please note that I can still enable a regular
|forwarder,
|> |> > > although
|> |> > > > > the sentence makes it sound like forwarding isn't available at
|> |all.
|> |> > > > >
|> |> > > > > Did you configure DNS in this way? Please try to add a regular
|> |> > forwarder
|> |> > > > to
|> |> > > > > see if it works.
|> |> > > > >
|> |> > > > > However, if you cannot add a regular DNS forwarder, please let
|me
|> |> know
|> |> > > > more
|> |> > > > > about your network topology. For example, are you using a
|Windows
|> |> > Server
|> |> > > > > 2003 domain? Is the DNS server a Windows 2000 Server? And how
|did
|> |> you
|> |> > > > > install DNS?
|> |> > > > >
|> |> > > > > If you want, please also send the following to me at
|> |> > > (e-mail address removed):
|> |> > > > >
|> |> > > > > 1. A screenshot of the Forwarders tab as well as screenshots
of
|> |any
|> |> > > error
|> |> > > > > messages you encounter.
|> |> > > > > 2. All related Event Logs.
|> |> > > > >
|> |> > > > > Thank you and have a nice day!
|> |> > > > >
|> |> > > > > Regards,
|> |> > > > > Joe Wu
|> |> > > > > Product Support Services
|> |> > > > > Microsoft Corporation
|> |> > > > >
|> |> > > > > Get Secure! - www.microsoft.com/security
|> |> > > > >
|> |> > > > > ====================================================
|> |> > > > > When responding to posts, please "Reply to Group" via your
|> |> newsreader
|> |> > so
|> |> > > > > that others may learn and benefit from your issue.
|> |> > > > > ====================================================
|> |> > > > > This posting is provided "AS IS" with no warranties, and
|confers
|> |no
|> |> > > > rights.
|> |> > > > >
|> |> > > > > --------------------
|> |> > > > > |From: "Jeff" <[email protected]>
|> |> > > > > |Subject: Conditional Forwarding Not Available
|> |> > > > > |Date: Thu, 25 Sep 2003 15:34:09 -0400
|> |> > > > > |Lines: 27
|> |> > > > > |X-Priority: 3
|> |> > > > > |X-MSMail-Priority: Normal
|> |> > > > > |X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
|> |> > > > > |X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
|> |> > > > > |Message-ID: <[email protected]>
|> |> > > > > |Newsgroups: microsoft.public.win2000.dns
|> |> > > > > |NNTP-Posting-Host: bankofutica-gate-line-r.bankofutica.com
|> |> > > > 216.230.225.242
|> |> > > > > |Path:
|> |> cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!tk2msftngp13.phx.gbl
|> |> > > > > |Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.dns:26616
|> |> > > > > |X-Tomcat-NG: microsoft.public.win2000.dns
|> |> > > > > |
|> |> > > > > |In harmony with KB 229840 I attempted to delete the . root
dns
|> |> entry
|> |> > > > using
|> |> > > > > |the dnscmd /ZoneDelete . /DsDel but received an error
|> |> > > > > |DNS_ERROR_ZONE_DOES_NOT_EXIST 9601 (00002581)
|> |> > > > > |
|> |> > > > > |If I look at the DNS Console I only see a . (root) entry in
|the
|> |> > cached
|> |> > > > > |lookups and my regular domain is in the Forward Lookups.
|> |> > > > > |
|> |> > > > > |When I choose properties, and click on the Forwarders tab,
|> (which
|> |> is
|> |> > > not
|> |> > > > > |grayed out) there is a message displayed that says:
|"Conditional
|> |> > > > Forwarding
|> |> > > > > |is Not Available Because this Server is a Downlevel Server"
|and
|> |> there
|> |> > > is
|> |> > > > no
|> |> > > > > |option to enable forwarders.
|> |> > > > > |
|> |> > > > > |This machine connects to a Proxy Server which is behind a
|> |firewall.
|> |> > > The
|> |> > > > > |proxy server has one NIC and has three entries for DNS, one
is
|> |the
|> |> > DNS
|> |> > > > > |server mentioned above and the other two are the ISP Public
|DNS
|> |> > > servers.
|> |> > > > I
|> |> > > > > |am interested in removing the 2 ISP entries so that I can
|> |eliminate
|> |> > > some
|> |> > > > > |possible event errors such as 5774. But in order to do this,
|my
|> |> > > clients
|> |> > > > > all
|> |> > > > > |point to the Proxy (client installed) so the Proxy would look
|to
|> |> the
|> |> > > DNS
|> |> > > > > |server to resolve a name, but I don't think I have something
|> |right
|> |> so
|> |> > > > that
|> |> > > > > I
|> |> > > > > |can enable Forwarding to ISP DNS servers.
|> |> > > > > |
|> |> > > > > |How can I make this work.
|> |> > > > > |
|> |> > > > > |Thanks
|> |> > > > > |Jeff Smyrski
|> |> > > > > |
|> |> > > > > |
|> |> > > > > |
|> |> > > > >
|> |> > > >
|> |> > > >
|> |> > >
|> |> > >
|> |> >
|> |> >
|> |>
|> |>
|> |
|> |
|> |
|>
|
|
|
 
J

Jeff Smyrski

Well, Before trying these steps, the forwarders began to work. I am not
really sure, why, but I did change the Gateway to be the firewall, although
this did not seem to matter, last night.

This morning, I was able to perform a NSLOOKUP using the local DNS server,
and it forwarded the request as expected.

I then removed the ISP's DNS entries in the Proxy's NIC that points to the
firewall. So that the only entry that remains is my internal DNS server
entry.

Everything seems to be working fine now, and the Netlogon 5774 error at the
Proxy has not shown up in 7 hours...so this is good.

HOWEVER - On my new XP machines I am still getting the following errors of
which I thought might be solved with this DNS error, as if it can't find
the server, the path does exist, but it seems to be related the the Proxy
Client that is installed on the machine. By the way I posted on the
ISA.Configuration board 3 days ago and nobody has replied...I thought as a
technet subscriber, I am guaranteed a response. Thanks.

Jeff Smyrski

Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1058
Date: 10/2/2003
Time: 10:20:07 AM
User: NT AUTHORITY\SYSTEM
Computer: STATION_120
Description:
Windows cannot access the file gpt.ini for GPO
CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=BANKOFUTI
CA,DC=COM. The file must be present at the location
<\\BANKOFUTICA.COM\sysvol\BANKOFUTICA.COM\Policies\{31B2F340-016D-11D2-945F-
00C04FB984F9}\gpt.ini>. (The network path was not found. ). Group Policy
processing aborted.






Joe Wu said:
Dear Jeff,

Thank you for your reply.

By default, the DNS server sends queries to other DNS servers using User
Datagram Protocol (UDP) port 53. However, this can be customized by
adjusting registry entries.

To narrow down the problem's scope, please check the following:

1. Please install DNS and configure a zone for the domain on your proxy
server. Add the ISP DNS servers to the proxy server's forwarder and then
change the local TCP/IP settings to only use itself as the Preferred DNS.
Check if the forwarder works on this server.

If the problem still occurs on this server, I think we need to check the
firewall settings to check if the DNS query packets are blocked.

2. Please check if the following registry entries exist on the two servers:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters
Value Name: SendPort
Value type: REG_DWORD

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters
Value Name: SendOnNonDnsPort
Data Type : REG_DWORD

Thank you for your time and efforts!

Regards,
Joe Wu
Product Support Services
Microsoft Corporation

Get Secure! - www.microsoft.com/security

====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.

--------------------
|From: "Jeff Smyrski" <[email protected]>
|References: <[email protected]>
<dhuumP#[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
|Subject: Re: Conditional Forwarding Not Available
|Date: Wed, 1 Oct 2003 16:01:02 -0400
|Lines: 468
|X-Priority: 3
|X-MSMail-Priority: Normal
|X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
|X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
|Message-ID: <[email protected]>
|Newsgroups: microsoft.public.win2000.dns
|NNTP-Posting-Host: bankofutica-gate-line-r.bankofutica.com 216.230.225.242
|Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP09.phx.gbl
|Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.dns:27054
|X-Tomcat-NG: microsoft.public.win2000.dns
|
|I made the change you suggested, and made the gateway of the DNS server to
|be the Firewall IP. I left Proxy as is, since this should not matter.
Keep
|in mind that the DNS server does have the Proxy Client installed on it, so
|that it can go out the Proxy for web related matters such as Windows
Update.
|The Proxy does not have Proxy Client installed on it...for obvious reasons.
|
|The DNS server, is only allowed to go out I think it is port 53 UDP not
TCP.
|Only the Proxy Server has the rights in the firewall rules to go out for
all
|other defined ports.
|
|After doing all of that, the DNS server still can not resolve a DNS name
|outside of the domain, using the NSLOOKUP when it defaults to the localhost
|127.0.0.1 address.
|
|If I type server at the nslookup prompt, and enter 216.238.0.10 the IP of
|the ISP DNS server, I can resolve all I want, it even returns the name of
|the server, no prob.
|
|I MUST be missing something with these forwarders...it should work but does
|not!
|
|Do you know, or are you sure that the NSLOOKUP is using UDP where as the
|Forwarders are using TCP?
|
|Please let me know.
|
|Jeff Smyrski
|
||> Dear Jeff,
|>
|> Thank you for your updates.
|>
|> Since the gateway on the DNS server is set to point to the proxy server,
|> the DNS query packets cannot be routed to the external DNS servers (ISP
|DNS
|> servers). However, the DNS query packets can be sent to the external DNS
|> from the proxy server, as the gateway of the proxy server itself is set
to
|> the Firewall.
|>
|> This should be the reason why the DNS forward does not work. Please go to
|> the DNS server and change the gateway from the proxy server to the
|Firewall
|> to see if the problem can be resolved.
|>
|> In the meantime, I think your ISA upgrade should work (generally, we
leave
|> the internal NIC's "Default gateway" blank on ISA server). You can get
|more
|> information from the following Knowledge Base article:
|>
|> 323387 HOW TO: Connect Your Company to the Internet by Using an ISA
|Firewall
|> http://support.microsoft.com/?id=323387
|>
|> Please let me know if any thing is unclear. Thanks!
|>
|> Regards,
|> Joe Wu
|> Product Support Services
|> Microsoft Corporation
|>
|> Get Secure! - www.microsoft.com/security
|>
|> ====================================================
|> When responding to posts, please "Reply to Group" via your newsreader so
|> that others may learn and benefit from your issue.
|> ====================================================
|> This posting is provided "AS IS" with no warranties, and confers no
|rights.
|>
|> --------------------
|> |From: "Jeff Smyrski" <[email protected]>
|> |References: <[email protected]>
|> <dhuumP#[email protected]>
|> <[email protected]>
|> <[email protected]>
|> <[email protected]>
|> <[email protected]>
|> |Subject: Re: Conditional Forwarding Not Available
|> |Date: Tue, 30 Sep 2003 08:56:31 -0400
|> |Lines: 337
|> |X-Priority: 3
|> |X-MSMail-Priority: Normal
|> |X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
|> |X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
|> |Message-ID: <[email protected]>
|> |Newsgroups: microsoft.public.win2000.dns
|> |NNTP-Posting-Host: bankofutica-gate-line-r.bankofutica.com
|216.230.225.242
|> |Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP11.phx.gbl
|> |Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.dns:26915
|> |X-Tomcat-NG: microsoft.public.win2000.dns
|> |
|> |I do have a Proxy Server, it is currently generating Netlogon errors
evey
|4
|> |hours in the system log event id 5774. I suspect that the issue is a
dns
|> |problem. The Proxy 2.0 server is currently uni-homed, but will soon be
|> |upgraded to ISA server with 2 NICs. In my model currently it looks like
|> |this.
|> |
|> | Proxy Server - Behind Firewall with an Internal Interface on my
|> |backbone. The gateway of the Proxy is pointing to the Firewall. (As
|> opposed
|> |to all other machines including my internal DNS server, they are all
|> |pointing to the Proxy as the gateway.)
|> | Proxy's NIC is configured with 3 DNS entries, the first (top of the
|> |list) is the internal DNS server, the next are the two ISP DNS servers.
|> |This is where I was attempting to remove the DNS entries for the ISP and
|> |move them to the Forwarders section of the Internal DNS server, but I
|can't
|> |get my DNS server to resolve names when I do this.
|> |
|> | The internal DNS server also has one NIC, pointing to the Proxy for
a
|> |gateway, with one DNS entry 127.0.0.1 (itself)
|> |
|> | If I try an nslookup at my workstation using my DNS server (by
|default)
|> |it looks like this.
|> |
|> |Microsoft Windows XP [Version 5.1.2600]
|> |(C) Copyright 1985-2001 Microsoft Corp.
|> |
|> |C:\Documents and Settings\jeff smyrski>nslookup
|> |Default Server: bofu2000.bankofutica.com
|> |Address: 192.168.1.13
|> |
|> |> www.cnn.com
|> |Server: bofu2000.bankofutica.com
|> |Address: 192.168.1.13
|> |
|> |DNS request timed out.
|> | timeout was 2 seconds.
|> |*** Request to bofu2000.bankofutica.com timed-out
|> |>
|> |
|> | If I go to the DNS server I get the same error, but I can tell the
|DNS
|> |server to use another IP, and it seems to be able to resolve the
address,
|> |even after the ipconfig /flushdns command (just to make sure)
|> |
|> |In the future, I want to make this model work using an ISA server
|> |(multi-homed) behind a firewall.
|> |
|> | ISA Server NIC#1 - Remains the same, pointing to the Firewall as its
|> |gateway, but only has the two ISP DNS server entries in it.
|> |
|> | ISA Server NIC#2 - (New NIC Card, with new IP, will become gateway
IP
|> |for workstations. The actual Gateway of this NIC would either be blank
|or
|> |the IP of the External NIC not sure on that one)
|> | (Only one DNS entry would be
|> associated
|> |with this NIC, and it would be the Internal DNS server)
|> |
|> | DNS Server NIC - Change Gateway to be the new IP of the new ISA
NIC#2
|> |also remove the Forwarder entries in DNS.
|> |
|> |NOTE - The Proxy server soon to be ISA server is also a DC for Active
|> |Directory, and I will be leaving this the same.
|> |
|> |Let me know if this will work, and / or how I can improve it?
|> |Thanks
|> |Jeff Smyrski
|> |
|> |
|> ||> |> nltest /dsregdns was added in W2k3. In W2k a quick way to get the
same
|> |> effect is: net stop netlogon & net start netlogon
|> |>
|> |> Try launching nslookup, then setting server=<ip address of your DNS
|> |server>,
|> |> and then try to resolve some name.
|> |> If you can resolve records that are on the DNS server, you could try
|the
|> |> same thing from your DNS server, but use the IP address of your ISP to
|> |make
|> |> sure that they are resolving the name.
|> |>
|> |> nslookup will default to the "dns server" as defined in your TCP/IP
|> |> settings.
|> |>
|> |> Do you have a proxy server in this setup? If so, where, and how is it
|> |> configured?
|> |>
|> |> --
|> |> Michael Snyder
|> |> Active Directory Admin Tool Test
|> |>
|> |> This posting is provided "AS IS" with no warranties, and confers no
|> |rights.
|> |>
|> |> |> |> > ipconfig /flushdns was performed this completed...
|> |> >
|> |> > I removed the 2 ISP DNS entries from the NIC and left only the
|Internal
|> |> DNS
|> |> > server in the list.
|> |> > I bounced the DNS client service as well
|> |> >
|> |> > I used the ipconfig /flushdns at the DNS server this completed.
|> |> > The DNS has two entries in the Forwarders tab of the DNS server
|> |> properties,
|> |> > both are for the ISP server.
|> |> >
|> |> > I then ran nslookup at the command prompt, it returned Default
Server
|> |> > 127.0.0.1
|> |> > I entered www.cnn.com
|> |> >
|> |> > It timed out after 2 seconds, server could not be found.
|> |> >
|> |> > I then tried an attempt to connect via the web, but IE just hangs
|> |looking
|> |> > for a way to resolve the URL.
|> |> >
|> |> > Please help! Arrg
|> |> >
|> |> > BTW the nltest does not have a /DSREGDNS option only a /DSDEREGDNS
|> |option.
|> |> >
|> |> > Jeff Smyrski
|> |> >
|message
|> |> > |> |> > > Changes like this do not require reboots on the DNS server,
|however,
|> |you
|> |> > may
|> |> > > need to:
|> |> > > ipconfig /flushdns on clients to flush the dns client cache
|> |> > > ipconfig /registerdns on clients to make them re-register their A
|> |> records
|> |> > > nltest /dsregdns on DCs to make them re-register their SRV records
|> |> > >
|> |> > > --
|> |> > > Michael Snyder
|> |> > > Active Directory Admin Tool Test
|> |> > >
|> |> > > This posting is provided "AS IS" with no warranties, and confers
no
|> |> > rights.
|> |> > >
|> |> > > |> |> > > > Additional Info:
|> |> > > >
|> |> > > > I added the ISP DNS entries in the 2K3 Snap in, then looked
|at
|> |the
|> |> > 2K
|> |> > > > snap in, and the checkbox was checked, and the two entries were
|> |> present.
|> |> > > > Here is what I just tried.
|> |> > > >
|> |> > > > With the two ISP entries present as forwarders, I removed the
|same
|> |> > entries
|> |> > > > from the DNS tab on the Proxy Server, and only left the DNS
|server
|> |IP
|> |> > > > present. I then attempted from my client to resolve CNN.COM it
|> will
|> |> not
|> |> > > go.
|> |> > > > I did not reboot or anything, I just made the changes, do
changes
|> |like
|> |> > > this
|> |> > > > require reboots, or DNS start stop to make not only the
|forwarders
|> |to
|> |> be
|> |> > > > effective but also the NIC DNS registration?
|> |> > > >
|> |> > > > Thanks
|> |> > > > Jeff Smyrski
|> |> > > >
|> |> > > > |> |> > > > > Dear Jeff,
|> |> > > > >
|> |> > > > > Thank you for your post.
|> |> > > > >
|> |> > > > > Actually, it is normal that there is a "." zone in the Cached
|> |> Lookups
|> |> > > > > folder and it does not affect the forward/root hint functions.
|We
|> |do
|> |> > not
|> |> > > > > need to delete it, if there is no "." zone in the Forward
|Lookups
|> |> > Zones
|> |> > > > > folder.
|> |> > > > >
|> |> > > > > I think that you have already removed the "." zone (in the
|> Forward
|> |> > > Lookups
|> |> > > > > Zones) before and this is why the
|"DNS_ERROR_ZONE_DOES_NOT_EXIST"
|> |> > error
|> |> > > > > appears.
|> |> > > > >
|> |> > > > > To be honest, the "Conditional Forwarding is Not Available
|> Because
|> |> > this
|> |> > > > > Server is a Downlevel Server" is a bit strange because
|> |"Conditional
|> |> > > > > Forwarding" is a new feature of Windows Server 2003.
|> |> > > > >
|> |> > > > > On my lab, I used Windows Server 2003 DNS Management Snap-In
to
|> |> > connect
|> |> > > to
|> |> > > > > another "Windows 2000" DNS server, and in the Forwarders tab,
I
|> |saw
|> |> > the
|> |> > > > > message "Conditional Forwarding is Not Available Because this
|> |Server
|> |> > is
|> |> > > a
|> |> > > > > Downlevel Server".
|> |> > > > >
|> |> > > > > However, please note that I can still enable a regular
|forwarder,
|> |> > > although
|> |> > > > > the sentence makes it sound like forwarding isn't available at
|> |all.
|> |> > > > >
|> |> > > > > Did you configure DNS in this way? Please try to add a regular
|> |> > forwarder
|> |> > > > to
|> |> > > > > see if it works.
|> |> > > > >
|> |> > > > > However, if you cannot add a regular DNS forwarder, please let
|me
|> |> know
|> |> > > > more
|> |> > > > > about your network topology. For example, are you using a
|Windows
|> |> > Server
|> |> > > > > 2003 domain? Is the DNS server a Windows 2000 Server? And how
|did
|> |> you
|> |> > > > > install DNS?
|> |> > > > >
|> |> > > > > If you want, please also send the following to me at
|> |> > > (e-mail address removed):
|> |> > > > >
|> |> > > > > 1. A screenshot of the Forwarders tab as well as screenshots
of
|> |any
|> |> > > error
|> |> > > > > messages you encounter.
|> |> > > > > 2. All related Event Logs.
|> |> > > > >
|> |> > > > > Thank you and have a nice day!
|> |> > > > >
|> |> > > > > Regards,
|> |> > > > > Joe Wu
|> |> > > > > Product Support Services
|> |> > > > > Microsoft Corporation
|> |> > > > >
|> |> > > > > Get Secure! - www.microsoft.com/security
|> |> > > > >
|> |> > > > > ====================================================
|> |> > > > > When responding to posts, please "Reply to Group" via your
|> |> newsreader
|> |> > so
|> |> > > > > that others may learn and benefit from your issue.
|> |> > > > > ====================================================
|> |> > > > > This posting is provided "AS IS" with no warranties, and
|confers
|> |no
|> |> > > > rights.
|> |> > > > >
|> |> > > > > --------------------
|> |> > > > > |From: "Jeff" <[email protected]>
|> |> > > > > |Subject: Conditional Forwarding Not Available
|> |> > > > > |Date: Thu, 25 Sep 2003 15:34:09 -0400
|> |> > > > > |Lines: 27
|> |> > > > > |X-Priority: 3
|> |> > > > > |X-MSMail-Priority: Normal
|> |> > > > > |X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
|> |> > > > > |X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
|> |> > > > > |Message-ID: <[email protected]>
|> |> > > > > |Newsgroups: microsoft.public.win2000.dns
|> |> > > > > |NNTP-Posting-Host: bankofutica-gate-line-r.bankofutica.com
|> |> > > > 216.230.225.242
|> |> > > > > |Path:
|> |> cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!tk2msftngp13.phx.gbl
|> |> > > > > |Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.dns:26616
|> |> > > > > |X-Tomcat-NG: microsoft.public.win2000.dns
|> |> > > > > |
|> |> > > > > |In harmony with KB 229840 I attempted to delete the . root
dns
|> |> entry
|> |> > > > using
|> |> > > > > |the dnscmd /ZoneDelete . /DsDel but received an error
|> |> > > > > |DNS_ERROR_ZONE_DOES_NOT_EXIST 9601 (00002581)
|> |> > > > > |
|> |> > > > > |If I look at the DNS Console I only see a . (root) entry in
|the
|> |> > cached
|> |> > > > > |lookups and my regular domain is in the Forward Lookups.
|> |> > > > > |
|> |> > > > > |When I choose properties, and click on the Forwarders tab,
|> (which
|> |> is
|> |> > > not
|> |> > > > > |grayed out) there is a message displayed that says:
|"Conditional
|> |> > > > Forwarding
|> |> > > > > |is Not Available Because this Server is a Downlevel Server"
|and
|> |> there
|> |> > > is
|> |> > > > no
|> |> > > > > |option to enable forwarders.
|> |> > > > > |
|> |> > > > > |This machine connects to a Proxy Server which is behind a
|> |firewall.
|> |> > > The
|> |> > > > > |proxy server has one NIC and has three entries for DNS, one
is
|> |the
|> |> > DNS
|> |> > > > > |server mentioned above and the other two are the ISP Public
|DNS
|> |> > > servers.
|> |> > > > I
|> |> > > > > |am interested in removing the 2 ISP entries so that I can
|> |eliminate
|> |> > > some
|> |> > > > > |possible event errors such as 5774. But in order to do this,
|my
|> |> > > clients
|> |> > > > > all
|> |> > > > > |point to the Proxy (client installed) so the Proxy would look
|to
|> |> the
|> |> > > DNS
|> |> > > > > |server to resolve a name, but I don't think I have something
|> |right
|> |> so
|> |> > > > that
|> |> > > > > I
|> |> > > > > |can enable Forwarding to ISP DNS servers.
|> |> > > > > |
|> |> > > > > |How can I make this work.
|> |> > > > > |
|> |> > > > > |Thanks
|> |> > > > > |Jeff Smyrski
|> |> > > > > |
|> |> > > > > |
|> |> > > > > |
|> |> > > > >
|> |> > > >
|> |> > > >
|> |> > >
|> |> > >
|> |> >
|> |> >
|> |>
|> |>
|> |
|> |
|> |
|>
|
|
|
 
J

Joe Wu [MSFT]

Dear Jeff,

Thank you for your reply.

I am glad to hear that the DNS forwarder issue has been resolved. Regarding
the 1058 Event on the Windows XP client, it seems it is not a DNS problem.
You may try the solution mentioned in the following Knowledge Base article
first to see if it works:

314494 Group Policies Are Not Applied The Way You Expect; "Event ID 1058"
and
http://support.microsoft.com/?id=314494

By the way, I have check the ISA thread you mentioned. Currently an
engineer is performing researching on that issue and will get back to you
soon.

If you have any other concerns, please feel free to let me know. I will do
my best to help you.

Thanks!

Regards,
Joe Wu
Product Support Services
Microsoft Corporation

Get Secure! - www.microsoft.com/security

====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.

--------------------
|From: "Jeff Smyrski" <[email protected]>
|References: <[email protected]>
<dhuumP#[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
|Subject: Re: Conditional Forwarding Not Available
|Date: Thu, 2 Oct 2003 16:26:21 -0400
|Lines: 646
|X-Priority: 3
|X-MSMail-Priority: Normal
|X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
|X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
|Message-ID: <[email protected]>
|Newsgroups: microsoft.public.win2000.dns
|NNTP-Posting-Host: bankofutica-gate-line-r.bankofutica.com 216.230.225.242
|Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP09.phx.gbl
|Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.dns:27101
|X-Tomcat-NG: microsoft.public.win2000.dns
|
|Well, Before trying these steps, the forwarders began to work. I am not
|really sure, why, but I did change the Gateway to be the firewall, although
|this did not seem to matter, last night.
|
|This morning, I was able to perform a NSLOOKUP using the local DNS server,
|and it forwarded the request as expected.
|
|I then removed the ISP's DNS entries in the Proxy's NIC that points to the
|firewall. So that the only entry that remains is my internal DNS server
|entry.
|
|Everything seems to be working fine now, and the Netlogon 5774 error at the
|Proxy has not shown up in 7 hours...so this is good.
|
|HOWEVER - On my new XP machines I am still getting the following errors of
|which I thought might be solved with this DNS error, as if it can't find
|the server, the path does exist, but it seems to be related the the Proxy
|Client that is installed on the machine. By the way I posted on the
|ISA.Configuration board 3 days ago and nobody has replied...I thought as a
|technet subscriber, I am guaranteed a response. Thanks.
|
|Jeff Smyrski
|
| Event Type: Error
|Event Source: Userenv
|Event Category: None
|Event ID: 1058
|Date: 10/2/2003
|Time: 10:20:07 AM
|User: NT AUTHORITY\SYSTEM
|Computer: STATION_120
|Description:
|Windows cannot access the file gpt.ini for GPO
|CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=BANKOFUT
I
|CA,DC=COM. The file must be present at the location
|<\\BANKOFUTICA.COM\sysvol\BANKOFUTICA.COM\Policies\{31B2F340-016D-11D2-945F
-
|00C04FB984F9}\gpt.ini>. (The network path was not found. ). Group Policy
|processing aborted.
|
|
|
|
|
|
||> Dear Jeff,
|>
|> Thank you for your reply.
|>
|> By default, the DNS server sends queries to other DNS servers using User
|> Datagram Protocol (UDP) port 53. However, this can be customized by
|> adjusting registry entries.
|>
|> To narrow down the problem's scope, please check the following:
|>
|> 1. Please install DNS and configure a zone for the domain on your proxy
|> server. Add the ISP DNS servers to the proxy server's forwarder and then
|> change the local TCP/IP settings to only use itself as the Preferred DNS.
|> Check if the forwarder works on this server.
|>
|> If the problem still occurs on this server, I think we need to check the
|> firewall settings to check if the DNS query packets are blocked.
|>
|> 2. Please check if the following registry entries exist on the two
|servers:
|>
|> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters
|> Value Name: SendPort
|> Value type: REG_DWORD
|>
|> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters
|> Value Name: SendOnNonDnsPort
|> Data Type : REG_DWORD
|>
|> Thank you for your time and efforts!
|>
|> Regards,
|> Joe Wu
|> Product Support Services
|> Microsoft Corporation
|>
|> Get Secure! - www.microsoft.com/security
|>
|> ====================================================
|> When responding to posts, please "Reply to Group" via your newsreader so
|> that others may learn and benefit from your issue.
|> ====================================================
|> This posting is provided "AS IS" with no warranties, and confers no
|rights.
|>
|> --------------------
|> |From: "Jeff Smyrski" <[email protected]>
|> |References: <[email protected]>
|> <dhuumP#[email protected]>
|> <[email protected]>
|> <[email protected]>
|> <[email protected]>
|> <[email protected]>
|> <[email protected]>
|> <[email protected]>
|> |Subject: Re: Conditional Forwarding Not Available
|> |Date: Wed, 1 Oct 2003 16:01:02 -0400
|> |Lines: 468
|> |X-Priority: 3
|> |X-MSMail-Priority: Normal
|> |X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
|> |X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
|> |Message-ID: <[email protected]>
|> |Newsgroups: microsoft.public.win2000.dns
|> |NNTP-Posting-Host: bankofutica-gate-line-r.bankofutica.com
|216.230.225.242
|> |Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP09.phx.gbl
|> |Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.dns:27054
|> |X-Tomcat-NG: microsoft.public.win2000.dns
|> |
|> |I made the change you suggested, and made the gateway of the DNS server
|to
|> |be the Firewall IP. I left Proxy as is, since this should not matter.
|> Keep
|> |in mind that the DNS server does have the Proxy Client installed on it,
|so
|> |that it can go out the Proxy for web related matters such as Windows
|> Update.
|> |The Proxy does not have Proxy Client installed on it...for obvious
|reasons.
|> |
|> |The DNS server, is only allowed to go out I think it is port 53 UDP not
|> TCP.
|> |Only the Proxy Server has the rights in the firewall rules to go out for
|> all
|> |other defined ports.
|> |
|> |After doing all of that, the DNS server still can not resolve a DNS name
|> |outside of the domain, using the NSLOOKUP when it defaults to the
|localhost
|> |127.0.0.1 address.
|> |
|> |If I type server at the nslookup prompt, and enter 216.238.0.10 the IP
of
|> |the ISP DNS server, I can resolve all I want, it even returns the name
of
|> |the server, no prob.
|> |
|> |I MUST be missing something with these forwarders...it should work but
|does
|> |not!
|> |
|> |Do you know, or are you sure that the NSLOOKUP is using UDP where as the
|> |Forwarders are using TCP?
|> |
|> |Please let me know.
|> |
|> |Jeff Smyrski
|> |
|> ||> |> Dear Jeff,
|> |>
|> |> Thank you for your updates.
|> |>
|> |> Since the gateway on the DNS server is set to point to the proxy
|server,
|> |> the DNS query packets cannot be routed to the external DNS servers
(ISP
|> |DNS
|> |> servers). However, the DNS query packets can be sent to the external
|DNS
|> |> from the proxy server, as the gateway of the proxy server itself is
set
|> to
|> |> the Firewall.
|> |>
|> |> This should be the reason why the DNS forward does not work. Please go
|to
|> |> the DNS server and change the gateway from the proxy server to the
|> |Firewall
|> |> to see if the problem can be resolved.
|> |>
|> |> In the meantime, I think your ISA upgrade should work (generally, we
|> leave
|> |> the internal NIC's "Default gateway" blank on ISA server). You can get
|> |more
|> |> information from the following Knowledge Base article:
|> |>
|> |> 323387 HOW TO: Connect Your Company to the Internet by Using an ISA
|> |Firewall
|> |> http://support.microsoft.com/?id=323387
|> |>
|> |> Please let me know if any thing is unclear. Thanks!
|> |>
|> |> Regards,
|> |> Joe Wu
|> |> Product Support Services
|> |> Microsoft Corporation
|> |>
|> |> Get Secure! - www.microsoft.com/security
|> |>
|> |> ====================================================
|> |> When responding to posts, please "Reply to Group" via your newsreader
|so
|> |> that others may learn and benefit from your issue.
|> |> ====================================================
|> |> This posting is provided "AS IS" with no warranties, and confers no
|> |rights.
|> |>
|> |> --------------------
|> |> |From: "Jeff Smyrski" <[email protected]>
|> |> |References: <[email protected]>
|> |> <dhuumP#[email protected]>
|> |> <[email protected]>
|> |> <[email protected]>
|> |> <[email protected]>
|> |> <[email protected]>
|> |> |Subject: Re: Conditional Forwarding Not Available
|> |> |Date: Tue, 30 Sep 2003 08:56:31 -0400
|> |> |Lines: 337
|> |> |X-Priority: 3
|> |> |X-MSMail-Priority: Normal
|> |> |X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
|> |> |X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
|> |> |Message-ID: <[email protected]>
|> |> |Newsgroups: microsoft.public.win2000.dns
|> |> |NNTP-Posting-Host: bankofutica-gate-line-r.bankofutica.com
|> |216.230.225.242
|> |> |Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP11.phx.gbl
|> |> |Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.dns:26915
|> |> |X-Tomcat-NG: microsoft.public.win2000.dns
|> |> |
|> |> |I do have a Proxy Server, it is currently generating Netlogon errors
|> evey
|> |4
|> |> |hours in the system log event id 5774. I suspect that the issue is a
|> dns
|> |> |problem. The Proxy 2.0 server is currently uni-homed, but will soon
|be
|> |> |upgraded to ISA server with 2 NICs. In my model currently it looks
|like
|> |> |this.
|> |> |
|> |> | Proxy Server - Behind Firewall with an Internal Interface on my
|> |> |backbone. The gateway of the Proxy is pointing to the Firewall. (As
|> |> opposed
|> |> |to all other machines including my internal DNS server, they are all
|> |> |pointing to the Proxy as the gateway.)
|> |> | Proxy's NIC is configured with 3 DNS entries, the first (top of
|the
|> |> |list) is the internal DNS server, the next are the two ISP DNS
|servers.
|> |> |This is where I was attempting to remove the DNS entries for the ISP
|and
|> |> |move them to the Forwarders section of the Internal DNS server, but I
|> |can't
|> |> |get my DNS server to resolve names when I do this.
|> |> |
|> |> | The internal DNS server also has one NIC, pointing to the Proxy
|for
|> a
|> |> |gateway, with one DNS entry 127.0.0.1 (itself)
|> |> |
|> |> | If I try an nslookup at my workstation using my DNS server (by
|> |default)
|> |> |it looks like this.
|> |> |
|> |> |Microsoft Windows XP [Version 5.1.2600]
|> |> |(C) Copyright 1985-2001 Microsoft Corp.
|> |> |
|> |> |C:\Documents and Settings\jeff smyrski>nslookup
|> |> |Default Server: bofu2000.bankofutica.com
|> |> |Address: 192.168.1.13
|> |> |
|> |> |> www.cnn.com
|> |> |Server: bofu2000.bankofutica.com
|> |> |Address: 192.168.1.13
|> |> |
|> |> |DNS request timed out.
|> |> | timeout was 2 seconds.
|> |> |*** Request to bofu2000.bankofutica.com timed-out
|> |> |>
|> |> |
|> |> | If I go to the DNS server I get the same error, but I can tell
the
|> |DNS
|> |> |server to use another IP, and it seems to be able to resolve the
|> address,
|> |> |even after the ipconfig /flushdns command (just to make sure)
|> |> |
|> |> |In the future, I want to make this model work using an ISA server
|> |> |(multi-homed) behind a firewall.
|> |> |
|> |> | ISA Server NIC#1 - Remains the same, pointing to the Firewall as
|its
|> |> |gateway, but only has the two ISP DNS server entries in it.
|> |> |
|> |> | ISA Server NIC#2 - (New NIC Card, with new IP, will become
gateway
|> IP
|> |> |for workstations. The actual Gateway of this NIC would either be
|blank
|> |or
|> |> |the IP of the External NIC not sure on that one)
|> |> | (Only one DNS entry would be
|> |> associated
|> |> |with this NIC, and it would be the Internal DNS server)
|> |> |
|> |> | DNS Server NIC - Change Gateway to be the new IP of the new ISA
|> NIC#2
|> |> |also remove the Forwarder entries in DNS.
|> |> |
|> |> |NOTE - The Proxy server soon to be ISA server is also a DC for Active
|> |> |Directory, and I will be leaving this the same.
|> |> |
|> |> |Let me know if this will work, and / or how I can improve it?
|> |> |Thanks
|> |> |Jeff Smyrski
|> |> |
|> |> |
|message
|> |> ||> |> |> nltest /dsregdns was added in W2k3. In W2k a quick way to get the
|> same
|> |> |> effect is: net stop netlogon & net start netlogon
|> |> |>
|> |> |> Try launching nslookup, then setting server=<ip address of your DNS
|> |> |server>,
|> |> |> and then try to resolve some name.
|> |> |> If you can resolve records that are on the DNS server, you could
try
|> |the
|> |> |> same thing from your DNS server, but use the IP address of your ISP
|to
|> |> |make
|> |> |> sure that they are resolving the name.
|> |> |>
|> |> |> nslookup will default to the "dns server" as defined in your TCP/IP
|> |> |> settings.
|> |> |>
|> |> |> Do you have a proxy server in this setup? If so, where, and how is
|it
|> |> |> configured?
|> |> |>
|> |> |> --
|> |> |> Michael Snyder
|> |> |> Active Directory Admin Tool Test
|> |> |>
|> |> |> This posting is provided "AS IS" with no warranties, and confers no
|> |> |rights.
|> |> |>
|> |> |> |> |> |> > ipconfig /flushdns was performed this completed...
|> |> |> >
|> |> |> > I removed the 2 ISP DNS entries from the NIC and left only the
|> |Internal
|> |> |> DNS
|> |> |> > server in the list.
|> |> |> > I bounced the DNS client service as well
|> |> |> >
|> |> |> > I used the ipconfig /flushdns at the DNS server this completed.
|> |> |> > The DNS has two entries in the Forwarders tab of the DNS server
|> |> |> properties,
|> |> |> > both are for the ISP server.
|> |> |> >
|> |> |> > I then ran nslookup at the command prompt, it returned Default
|> Server
|> |> |> > 127.0.0.1
|> |> |> > I entered www.cnn.com
|> |> |> >
|> |> |> > It timed out after 2 seconds, server could not be found.
|> |> |> >
|> |> |> > I then tried an attempt to connect via the web, but IE just hangs
|> |> |looking
|> |> |> > for a way to resolve the URL.
|> |> |> >
|> |> |> > Please help! Arrg
|> |> |> >
|> |> |> > BTW the nltest does not have a /DSREGDNS option only a
/DSDEREGDNS
|> |> |option.
|> |> |> >
|> |> |> > Jeff Smyrski
|> |> |> >
|> |message
|> |> |> > |> |> |> > > Changes like this do not require reboots on the DNS server,
|> |however,
|> |> |you
|> |> |> > may
|> |> |> > > need to:
|> |> |> > > ipconfig /flushdns on clients to flush the dns client cache
|> |> |> > > ipconfig /registerdns on clients to make them re-register their
|A
|> |> |> records
|> |> |> > > nltest /dsregdns on DCs to make them re-register their SRV
|records
|> |> |> > >
|> |> |> > > --
|> |> |> > > Michael Snyder
|> |> |> > > Active Directory Admin Tool Test
|> |> |> > >
|> |> |> > > This posting is provided "AS IS" with no warranties, and
confers
|> no
|> |> |> > rights.
|> |> |> > >
|> |> |> > > |> |> |> > > > Additional Info:
|> |> |> > > >
|> |> |> > > > I added the ISP DNS entries in the 2K3 Snap in, then
|looked
|> |at
|> |> |the
|> |> |> > 2K
|> |> |> > > > snap in, and the checkbox was checked, and the two entries
|were
|> |> |> present.
|> |> |> > > > Here is what I just tried.
|> |> |> > > >
|> |> |> > > > With the two ISP entries present as forwarders, I removed the
|> |same
|> |> |> > entries
|> |> |> > > > from the DNS tab on the Proxy Server, and only left the DNS
|> |server
|> |> |IP
|> |> |> > > > present. I then attempted from my client to resolve CNN.COM
|it
|> |> will
|> |> |> not
|> |> |> > > go.
|> |> |> > > > I did not reboot or anything, I just made the changes, do
|> changes
|> |> |like
|> |> |> > > this
|> |> |> > > > require reboots, or DNS start stop to make not only the
|> |forwarders
|> |> |to
|> |> |> be
|> |> |> > > > effective but also the NIC DNS registration?
|> |> |> > > >
|> |> |> > > > Thanks
|> |> |> > > > Jeff Smyrski
|> |> |> > > >
|> |> |> > > > |> |> |> > > > > Dear Jeff,
|> |> |> > > > >
|> |> |> > > > > Thank you for your post.
|> |> |> > > > >
|> |> |> > > > > Actually, it is normal that there is a "." zone in the
|Cached
|> |> |> Lookups
|> |> |> > > > > folder and it does not affect the forward/root hint
|functions.
|> |We
|> |> |do
|> |> |> > not
|> |> |> > > > > need to delete it, if there is no "." zone in the Forward
|> |Lookups
|> |> |> > Zones
|> |> |> > > > > folder.
|> |> |> > > > >
|> |> |> > > > > I think that you have already removed the "." zone (in the
|> |> Forward
|> |> |> > > Lookups
|> |> |> > > > > Zones) before and this is why the
|> |"DNS_ERROR_ZONE_DOES_NOT_EXIST"
|> |> |> > error
|> |> |> > > > > appears.
|> |> |> > > > >
|> |> |> > > > > To be honest, the "Conditional Forwarding is Not Available
|> |> Because
|> |> |> > this
|> |> |> > > > > Server is a Downlevel Server" is a bit strange because
|> |> |"Conditional
|> |> |> > > > > Forwarding" is a new feature of Windows Server 2003.
|> |> |> > > > >
|> |> |> > > > > On my lab, I used Windows Server 2003 DNS Management
Snap-In
|> to
|> |> |> > connect
|> |> |> > > to
|> |> |> > > > > another "Windows 2000" DNS server, and in the Forwarders
|tab,
|> I
|> |> |saw
|> |> |> > the
|> |> |> > > > > message "Conditional Forwarding is Not Available Because
|this
|> |> |Server
|> |> |> > is
|> |> |> > > a
|> |> |> > > > > Downlevel Server".
|> |> |> > > > >
|> |> |> > > > > However, please note that I can still enable a regular
|> |forwarder,
|> |> |> > > although
|> |> |> > > > > the sentence makes it sound like forwarding isn't available
|at
|> |> |all.
|> |> |> > > > >
|> |> |> > > > > Did you configure DNS in this way? Please try to add a
|regular
|> |> |> > forwarder
|> |> |> > > > to
|> |> |> > > > > see if it works.
|> |> |> > > > >
|> |> |> > > > > However, if you cannot add a regular DNS forwarder, please
|let
|> |me
|> |> |> know
|> |> |> > > > more
|> |> |> > > > > about your network topology. For example, are you using a
|> |Windows
|> |> |> > Server
|> |> |> > > > > 2003 domain? Is the DNS server a Windows 2000 Server? And
|how
|> |did
|> |> |> you
|> |> |> > > > > install DNS?
|> |> |> > > > >
|> |> |> > > > > If you want, please also send the following to me at
|> |> |> > > (e-mail address removed):
|> |> |> > > > >
|> |> |> > > > > 1. A screenshot of the Forwarders tab as well as
screenshots
|> of
|> |> |any
|> |> |> > > error
|> |> |> > > > > messages you encounter.
|> |> |> > > > > 2. All related Event Logs.
|> |> |> > > > >
|> |> |> > > > > Thank you and have a nice day!
|> |> |> > > > >
|> |> |> > > > > Regards,
|> |> |> > > > > Joe Wu
|> |> |> > > > > Product Support Services
|> |> |> > > > > Microsoft Corporation
|> |> |> > > > >
|> |> |> > > > > Get Secure! - www.microsoft.com/security
|> |> |> > > > >
|> |> |> > > > > ====================================================
|> |> |> > > > > When responding to posts, please "Reply to Group" via your
|> |> |> newsreader
|> |> |> > so
|> |> |> > > > > that others may learn and benefit from your issue.
|> |> |> > > > > ====================================================
|> |> |> > > > > This posting is provided "AS IS" with no warranties, and
|> |confers
|> |> |no
|> |> |> > > > rights.
|> |> |> > > > >
|> |> |> > > > > --------------------
|> |> |> > > > > |From: "Jeff" <[email protected]>
|> |> |> > > > > |Subject: Conditional Forwarding Not Available
|> |> |> > > > > |Date: Thu, 25 Sep 2003 15:34:09 -0400
|> |> |> > > > > |Lines: 27
|> |> |> > > > > |X-Priority: 3
|> |> |> > > > > |X-MSMail-Priority: Normal
|> |> |> > > > > |X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
|> |> |> > > > > |X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
|> |> |> > > > > |Message-ID: <[email protected]>
|> |> |> > > > > |Newsgroups: microsoft.public.win2000.dns
|> |> |> > > > > |NNTP-Posting-Host: bankofutica-gate-line-r.bankofutica.com
|> |> |> > > > 216.230.225.242
|> |> |> > > > > |Path:
|> |> |> cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!tk2msftngp13.phx.gbl
|> |> |> > > > > |Xref: cpmsftngxa06.phx.gbl
|microsoft.public.win2000.dns:26616
|> |> |> > > > > |X-Tomcat-NG: microsoft.public.win2000.dns
|> |> |> > > > > |
|> |> |> > > > > |In harmony with KB 229840 I attempted to delete the . root
|> dns
|> |> |> entry
|> |> |> > > > using
|> |> |> > > > > |the dnscmd /ZoneDelete . /DsDel but received an error
|> |> |> > > > > |DNS_ERROR_ZONE_DOES_NOT_EXIST 9601 (00002581)
|> |> |> > > > > |
|> |> |> > > > > |If I look at the DNS Console I only see a . (root) entry
in
|> |the
|> |> |> > cached
|> |> |> > > > > |lookups and my regular domain is in the Forward Lookups.
|> |> |> > > > > |
|> |> |> > > > > |When I choose properties, and click on the Forwarders tab,
|> |> (which
|> |> |> is
|> |> |> > > not
|> |> |> > > > > |grayed out) there is a message displayed that says:
|> |"Conditional
|> |> |> > > > Forwarding
|> |> |> > > > > |is Not Available Because this Server is a Downlevel
Server"
|> |and
|> |> |> there
|> |> |> > > is
|> |> |> > > > no
|> |> |> > > > > |option to enable forwarders.
|> |> |> > > > > |
|> |> |> > > > > |This machine connects to a Proxy Server which is behind a
|> |> |firewall.
|> |> |> > > The
|> |> |> > > > > |proxy server has one NIC and has three entries for DNS,
one
|> is
|> |> |the
|> |> |> > DNS
|> |> |> > > > > |server mentioned above and the other two are the ISP
Public
|> |DNS
|> |> |> > > servers.
|> |> |> > > > I
|> |> |> > > > > |am interested in removing the 2 ISP entries so that I can
|> |> |eliminate
|> |> |> > > some
|> |> |> > > > > |possible event errors such as 5774. But in order to do
|this,
|> |my
|> |> |> > > clients
|> |> |> > > > > all
|> |> |> > > > > |point to the Proxy (client installed) so the Proxy would
|look
|> |to
|> |> |> the
|> |> |> > > DNS
|> |> |> > > > > |server to resolve a name, but I don't think I have
|something
|> |> |right
|> |> |> so
|> |> |> > > > that
|> |> |> > > > > I
|> |> |> > > > > |can enable Forwarding to ISP DNS servers.
|> |> |> > > > > |
|> |> |> > > > > |How can I make this work.
|> |> |> > > > > |
|> |> |> > > > > |Thanks
|> |> |> > > > > |Jeff Smyrski
|> |> |> > > > > |
|> |> |> > > > > |
|> |> |> > > > > |
|> |> |> > > > >
|> |> |> > > >
|> |> |> > > >
|> |> |> > >
|> |> |> > >
|> |> |> >
|> |> |> >
|> |> |>
|> |> |>
|> |> |
|> |> |
|> |> |
|> |>
|> |
|> |
|> |
|>
|
|
|
 
J

Jeff Smyrski

I looked at this article, too 314494, but there is no EnableDFS in the
registry under Mup.

I added the value and left its setting at 0
This did not matter

Looking at the error it seems that it is related to
\\DOMAINNAME.COM\SYSVOL\domainname.com...etc...etc

The folder exists, but if I attempt to browse to it from the machine
generating the error, I either get file can not be found, or a permissions
error if I just try to browse to the SYSVOL folder, all the while doing this
as admin.

On the other hand, if I do the same thing from my workstation, as me, a
member of admins, I can get to the file no prob. It almost seems that even
though I am logging into the domain, I am not getting the permissions to do
anything on it...

Currently I am reinstalling XP from scratch using the restore CD for this
machine, but not the HP Restore Plus feature, I will just install XP myself
instead of letting HPs cd do it.

Related to the SYSVOL if I look a the properties of the folder there is a
DFS tab, but for both domain controllers the Status for active says NO from
this machine, and checking the status says unreachable. But again if I do
it from my XP workstation as me, I get the Backup DC as active and both
check out okay.

Any ideas...

Jeff Smyrski


Joe Wu said:
Dear Jeff,

Thank you for your reply.

I am glad to hear that the DNS forwarder issue has been resolved. Regarding
the 1058 Event on the Windows XP client, it seems it is not a DNS problem.
You may try the solution mentioned in the following Knowledge Base article
first to see if it works:

314494 Group Policies Are Not Applied The Way You Expect; "Event ID 1058"
and
http://support.microsoft.com/?id=314494

By the way, I have check the ISA thread you mentioned. Currently an
engineer is performing researching on that issue and will get back to you
soon.

If you have any other concerns, please feel free to let me know. I will do
my best to help you.

Thanks!

Regards,
Joe Wu
Product Support Services
Microsoft Corporation

Get Secure! - www.microsoft.com/security

====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.

--------------------
|From: "Jeff Smyrski" <[email protected]>
|References: <[email protected]>
<dhuumP#[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
<[email protected]>
|Subject: Re: Conditional Forwarding Not Available
|Date: Thu, 2 Oct 2003 16:26:21 -0400
|Lines: 646
|X-Priority: 3
|X-MSMail-Priority: Normal
|X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
|X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
|Message-ID: <[email protected]>
|Newsgroups: microsoft.public.win2000.dns
|NNTP-Posting-Host: bankofutica-gate-line-r.bankofutica.com 216.230.225.242
|Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP09.phx.gbl
|Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.dns:27101
|X-Tomcat-NG: microsoft.public.win2000.dns
|
|Well, Before trying these steps, the forwarders began to work. I am not
|really sure, why, but I did change the Gateway to be the firewall, although
|this did not seem to matter, last night.
|
|This morning, I was able to perform a NSLOOKUP using the local DNS server,
|and it forwarded the request as expected.
|
|I then removed the ISP's DNS entries in the Proxy's NIC that points to the
|firewall. So that the only entry that remains is my internal DNS server
|entry.
|
|Everything seems to be working fine now, and the Netlogon 5774 error at the
|Proxy has not shown up in 7 hours...so this is good.
|
|HOWEVER - On my new XP machines I am still getting the following errors of
|which I thought might be solved with this DNS error, as if it can't find
|the server, the path does exist, but it seems to be related the the Proxy
|Client that is installed on the machine. By the way I posted on the
|ISA.Configuration board 3 days ago and nobody has replied...I thought as a
|technet subscriber, I am guaranteed a response. Thanks.
|
|Jeff Smyrski
|
| Event Type: Error
|Event Source: Userenv
|Event Category: None
|Event ID: 1058
|Date: 10/2/2003
|Time: 10:20:07 AM
|User: NT AUTHORITY\SYSTEM
|Computer: STATION_120
|Description:
|Windows cannot access the file gpt.ini for GPO
|CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=BANKOFUT
I
|CA,DC=COM. The file must be present at the location
|<\\BANKOFUTICA.COM\sysvol\BANKOFUTICA.COM\Policies\{31B2F340-016D-11D2-945F
-
|00C04FB984F9}\gpt.ini>. (The network path was not found. ). Group Policy
|processing aborted.
|
|
|
|
|
|
||> Dear Jeff,
|>
|> Thank you for your reply.
|>
|> By default, the DNS server sends queries to other DNS servers using User
|> Datagram Protocol (UDP) port 53. However, this can be customized by
|> adjusting registry entries.
|>
|> To narrow down the problem's scope, please check the following:
|>
|> 1. Please install DNS and configure a zone for the domain on your proxy
|> server. Add the ISP DNS servers to the proxy server's forwarder and then
|> change the local TCP/IP settings to only use itself as the Preferred DNS.
|> Check if the forwarder works on this server.
|>
|> If the problem still occurs on this server, I think we need to check the
|> firewall settings to check if the DNS query packets are blocked.
|>
|> 2. Please check if the following registry entries exist on the two
|servers:
|>
|> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters
|> Value Name: SendPort
|> Value type: REG_DWORD
|>
|> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters
|> Value Name: SendOnNonDnsPort
|> Data Type : REG_DWORD
|>
|> Thank you for your time and efforts!
|>
|> Regards,
|> Joe Wu
|> Product Support Services
|> Microsoft Corporation
|>
|> Get Secure! - www.microsoft.com/security
|>
|> ====================================================
|> When responding to posts, please "Reply to Group" via your newsreader so
|> that others may learn and benefit from your issue.
|> ====================================================
|> This posting is provided "AS IS" with no warranties, and confers no
|rights.
|>
|> --------------------
|> |From: "Jeff Smyrski" <[email protected]>
|> |References: <[email protected]>
|> <dhuumP#[email protected]>
|> <[email protected]>
|> <[email protected]>
|> <[email protected]>
|> <[email protected]>
|> <[email protected]>
|> <[email protected]>
|> |Subject: Re: Conditional Forwarding Not Available
|> |Date: Wed, 1 Oct 2003 16:01:02 -0400
|> |Lines: 468
|> |X-Priority: 3
|> |X-MSMail-Priority: Normal
|> |X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
|> |X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
|> |Message-ID: <[email protected]>
|> |Newsgroups: microsoft.public.win2000.dns
|> |NNTP-Posting-Host: bankofutica-gate-line-r.bankofutica.com
|216.230.225.242
|> |Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP09.phx.gbl
|> |Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.dns:27054
|> |X-Tomcat-NG: microsoft.public.win2000.dns
|> |
|> |I made the change you suggested, and made the gateway of the DNS server
|to
|> |be the Firewall IP. I left Proxy as is, since this should not matter.
|> Keep
|> |in mind that the DNS server does have the Proxy Client installed on it,
|so
|> |that it can go out the Proxy for web related matters such as Windows
|> Update.
|> |The Proxy does not have Proxy Client installed on it...for obvious
|reasons.
|> |
|> |The DNS server, is only allowed to go out I think it is port 53 UDP not
|> TCP.
|> |Only the Proxy Server has the rights in the firewall rules to go out for
|> all
|> |other defined ports.
|> |
|> |After doing all of that, the DNS server still can not resolve a DNS name
|> |outside of the domain, using the NSLOOKUP when it defaults to the
|localhost
|> |127.0.0.1 address.
|> |
|> |If I type server at the nslookup prompt, and enter 216.238.0.10 the IP
of
|> |the ISP DNS server, I can resolve all I want, it even returns the name
of
|> |the server, no prob.
|> |
|> |I MUST be missing something with these forwarders...it should work but
|does
|> |not!
|> |
|> |Do you know, or are you sure that the NSLOOKUP is using UDP where as the
|> |Forwarders are using TCP?
|> |
|> |Please let me know.
|> |
|> |Jeff Smyrski
|> |
|> ||> |> Dear Jeff,
|> |>
|> |> Thank you for your updates.
|> |>
|> |> Since the gateway on the DNS server is set to point to the proxy
|server,
|> |> the DNS query packets cannot be routed to the external DNS servers
(ISP
|> |DNS
|> |> servers). However, the DNS query packets can be sent to the external
|DNS
|> |> from the proxy server, as the gateway of the proxy server itself is
set
|> to
|> |> the Firewall.
|> |>
|> |> This should be the reason why the DNS forward does not work. Please go
|to
|> |> the DNS server and change the gateway from the proxy server to the
|> |Firewall
|> |> to see if the problem can be resolved.
|> |>
|> |> In the meantime, I think your ISA upgrade should work (generally, we
|> leave
|> |> the internal NIC's "Default gateway" blank on ISA server). You can get
|> |more
|> |> information from the following Knowledge Base article:
|> |>
|> |> 323387 HOW TO: Connect Your Company to the Internet by Using an ISA
|> |Firewall
|> |> http://support.microsoft.com/?id=323387
|> |>
|> |> Please let me know if any thing is unclear. Thanks!
|> |>
|> |> Regards,
|> |> Joe Wu
|> |> Product Support Services
|> |> Microsoft Corporation
|> |>
|> |> Get Secure! - www.microsoft.com/security
|> |>
|> |> ====================================================
|> |> When responding to posts, please "Reply to Group" via your newsreader
|so
|> |> that others may learn and benefit from your issue.
|> |> ====================================================
|> |> This posting is provided "AS IS" with no warranties, and confers no
|> |rights.
|> |>
|> |> --------------------
|> |> |From: "Jeff Smyrski" <[email protected]>
|> |> |References: <[email protected]>
|> |> <dhuumP#[email protected]>
|> |> <[email protected]>
|> |> <[email protected]>
|> |> <[email protected]>
|> |> <[email protected]>
|> |> |Subject: Re: Conditional Forwarding Not Available
|> |> |Date: Tue, 30 Sep 2003 08:56:31 -0400
|> |> |Lines: 337
|> |> |X-Priority: 3
|> |> |X-MSMail-Priority: Normal
|> |> |X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
|> |> |X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
|> |> |Message-ID: <[email protected]>
|> |> |Newsgroups: microsoft.public.win2000.dns
|> |> |NNTP-Posting-Host: bankofutica-gate-line-r.bankofutica.com
|> |216.230.225.242
|> |> |Path: cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP11.phx.gbl
|> |> |Xref: cpmsftngxa06.phx.gbl microsoft.public.win2000.dns:26915
|> |> |X-Tomcat-NG: microsoft.public.win2000.dns
|> |> |
|> |> |I do have a Proxy Server, it is currently generating Netlogon errors
|> evey
|> |4
|> |> |hours in the system log event id 5774. I suspect that the issue is a
|> dns
|> |> |problem. The Proxy 2.0 server is currently uni-homed, but will soon
|be
|> |> |upgraded to ISA server with 2 NICs. In my model currently it looks
|like
|> |> |this.
|> |> |
|> |> | Proxy Server - Behind Firewall with an Internal Interface on my
|> |> |backbone. The gateway of the Proxy is pointing to the Firewall. (As
|> |> opposed
|> |> |to all other machines including my internal DNS server, they are all
|> |> |pointing to the Proxy as the gateway.)
|> |> | Proxy's NIC is configured with 3 DNS entries, the first (top of
|the
|> |> |list) is the internal DNS server, the next are the two ISP DNS
|servers.
|> |> |This is where I was attempting to remove the DNS entries for the ISP
|and
|> |> |move them to the Forwarders section of the Internal DNS server, but I
|> |can't
|> |> |get my DNS server to resolve names when I do this.
|> |> |
|> |> | The internal DNS server also has one NIC, pointing to the Proxy
|for
|> a
|> |> |gateway, with one DNS entry 127.0.0.1 (itself)
|> |> |
|> |> | If I try an nslookup at my workstation using my DNS server (by
|> |default)
|> |> |it looks like this.
|> |> |
|> |> |Microsoft Windows XP [Version 5.1.2600]
|> |> |(C) Copyright 1985-2001 Microsoft Corp.
|> |> |
|> |> |C:\Documents and Settings\jeff smyrski>nslookup
|> |> |Default Server: bofu2000.bankofutica.com
|> |> |Address: 192.168.1.13
|> |> |
|> |> |> www.cnn.com
|> |> |Server: bofu2000.bankofutica.com
|> |> |Address: 192.168.1.13
|> |> |
|> |> |DNS request timed out.
|> |> | timeout was 2 seconds.
|> |> |*** Request to bofu2000.bankofutica.com timed-out
|> |> |>
|> |> |
|> |> | If I go to the DNS server I get the same error, but I can tell
the
|> |DNS
|> |> |server to use another IP, and it seems to be able to resolve the
|> address,
|> |> |even after the ipconfig /flushdns command (just to make sure)
|> |> |
|> |> |In the future, I want to make this model work using an ISA server
|> |> |(multi-homed) behind a firewall.
|> |> |
|> |> | ISA Server NIC#1 - Remains the same, pointing to the Firewall as
|its
|> |> |gateway, but only has the two ISP DNS server entries in it.
|> |> |
|> |> | ISA Server NIC#2 - (New NIC Card, with new IP, will become
gateway
|> IP
|> |> |for workstations. The actual Gateway of this NIC would either be
|blank
|> |or
|> |> |the IP of the External NIC not sure on that one)
|> |> | (Only one DNS entry would be
|> |> associated
|> |> |with this NIC, and it would be the Internal DNS server)
|> |> |
|> |> | DNS Server NIC - Change Gateway to be the new IP of the new ISA
|> NIC#2
|> |> |also remove the Forwarder entries in DNS.
|> |> |
|> |> |NOTE - The Proxy server soon to be ISA server is also a DC for Active
|> |> |Directory, and I will be leaving this the same.
|> |> |
|> |> |Let me know if this will work, and / or how I can improve it?
|> |> |Thanks
|> |> |Jeff Smyrski
|> |> |
|> |> |
|message
|> |> ||> |> |> nltest /dsregdns was added in W2k3. In W2k a quick way to get the
|> same
|> |> |> effect is: net stop netlogon & net start netlogon
|> |> |>
|> |> |> Try launching nslookup, then setting server=<ip address of your DNS
|> |> |server>,
|> |> |> and then try to resolve some name.
|> |> |> If you can resolve records that are on the DNS server, you could
try
|> |the
|> |> |> same thing from your DNS server, but use the IP address of your ISP
|to
|> |> |make
|> |> |> sure that they are resolving the name.
|> |> |>
|> |> |> nslookup will default to the "dns server" as defined in your TCP/IP
|> |> |> settings.
|> |> |>
|> |> |> Do you have a proxy server in this setup? If so, where, and how is
|it
|> |> |> configured?
|> |> |>
|> |> |> --
|> |> |> Michael Snyder
|> |> |> Active Directory Admin Tool Test
|> |> |>
|> |> |> This posting is provided "AS IS" with no warranties, and confers no
|> |> |rights.
|> |> |>
|> |> |> |> |> |> > ipconfig /flushdns was performed this completed...
|> |> |> >
|> |> |> > I removed the 2 ISP DNS entries from the NIC and left only the
|> |Internal
|> |> |> DNS
|> |> |> > server in the list.
|> |> |> > I bounced the DNS client service as well
|> |> |> >
|> |> |> > I used the ipconfig /flushdns at the DNS server this completed.
|> |> |> > The DNS has two entries in the Forwarders tab of the DNS server
|> |> |> properties,
|> |> |> > both are for the ISP server.
|> |> |> >
|> |> |> > I then ran nslookup at the command prompt, it returned Default
|> Server
|> |> |> > 127.0.0.1
|> |> |> > I entered www.cnn.com
|> |> |> >
|> |> |> > It timed out after 2 seconds, server could not be found.
|> |> |> >
|> |> |> > I then tried an attempt to connect via the web, but IE just hangs
|> |> |looking
|> |> |> > for a way to resolve the URL.
|> |> |> >
|> |> |> > Please help! Arrg
|> |> |> >
|> |> |> > BTW the nltest does not have a /DSREGDNS option only a
/DSDEREGDNS
|> |> |option.
|> |> |> >
|> |> |> > Jeff Smyrski
|> |> |> >
|> |message
|> |> |> > |> |> |> > > Changes like this do not require reboots on the DNS server,
|> |however,
|> |> |you
|> |> |> > may
|> |> |> > > need to:
|> |> |> > > ipconfig /flushdns on clients to flush the dns client cache
|> |> |> > > ipconfig /registerdns on clients to make them re-register their
|A
|> |> |> records
|> |> |> > > nltest /dsregdns on DCs to make them re-register their SRV
|records
|> |> |> > >
|> |> |> > > --
|> |> |> > > Michael Snyder
|> |> |> > > Active Directory Admin Tool Test
|> |> |> > >
|> |> |> > > This posting is provided "AS IS" with no warranties, and
confers
|> no
|> |> |> > rights.
|> |> |> > >
|> |> |> > > |> |> |> > > > Additional Info:
|> |> |> > > >
|> |> |> > > > I added the ISP DNS entries in the 2K3 Snap in, then
|looked
|> |at
|> |> |the
|> |> |> > 2K
|> |> |> > > > snap in, and the checkbox was checked, and the two entries
|were
|> |> |> present.
|> |> |> > > > Here is what I just tried.
|> |> |> > > >
|> |> |> > > > With the two ISP entries present as forwarders, I removed the
|> |same
|> |> |> > entries
|> |> |> > > > from the DNS tab on the Proxy Server, and only left the DNS
|> |server
|> |> |IP
|> |> |> > > > present. I then attempted from my client to resolve CNN.COM
|it
|> |> will
|> |> |> not
|> |> |> > > go.
|> |> |> > > > I did not reboot or anything, I just made the changes, do
|> changes
|> |> |like
|> |> |> > > this
|> |> |> > > > require reboots, or DNS start stop to make not only the
|> |forwarders
|> |> |to
|> |> |> be
|> |> |> > > > effective but also the NIC DNS registration?
|> |> |> > > >
|> |> |> > > > Thanks
|> |> |> > > > Jeff Smyrski
|> |> |> > > >
|> |> |> > > > |> |> |> > > > > Dear Jeff,
|> |> |> > > > >
|> |> |> > > > > Thank you for your post.
|> |> |> > > > >
|> |> |> > > > > Actually, it is normal that there is a "." zone in the
|Cached
|> |> |> Lookups
|> |> |> > > > > folder and it does not affect the forward/root hint
|functions.
|> |We
|> |> |do
|> |> |> > not
|> |> |> > > > > need to delete it, if there is no "." zone in the Forward
|> |Lookups
|> |> |> > Zones
|> |> |> > > > > folder.
|> |> |> > > > >
|> |> |> > > > > I think that you have already removed the "." zone (in the
|> |> Forward
|> |> |> > > Lookups
|> |> |> > > > > Zones) before and this is why the
|> |"DNS_ERROR_ZONE_DOES_NOT_EXIST"
|> |> |> > error
|> |> |> > > > > appears.
|> |> |> > > > >
|> |> |> > > > > To be honest, the "Conditional Forwarding is Not Available
|> |> Because
|> |> |> > this
|> |> |> > > > > Server is a Downlevel Server" is a bit strange because
|> |> |"Conditional
|> |> |> > > > > Forwarding" is a new feature of Windows Server 2003.
|> |> |> > > > >
|> |> |> > > > > On my lab, I used Windows Server 2003 DNS Management
Snap-In
|> to
|> |> |> > connect
|> |> |> > > to
|> |> |> > > > > another "Windows 2000" DNS server, and in the Forwarders
|tab,
|> I
|> |> |saw
|> |> |> > the
|> |> |> > > > > message "Conditional Forwarding is Not Available Because
|this
|> |> |Server
|> |> |> > is
|> |> |> > > a
|> |> |> > > > > Downlevel Server".
|> |> |> > > > >
|> |> |> > > > > However, please note that I can still enable a regular
|> |forwarder,
|> |> |> > > although
|> |> |> > > > > the sentence makes it sound like forwarding isn't available
|at
|> |> |all.
|> |> |> > > > >
|> |> |> > > > > Did you configure DNS in this way? Please try to add a
|regular
|> |> |> > forwarder
|> |> |> > > > to
|> |> |> > > > > see if it works.
|> |> |> > > > >
|> |> |> > > > > However, if you cannot add a regular DNS forwarder, please
|let
|> |me
|> |> |> know
|> |> |> > > > more
|> |> |> > > > > about your network topology. For example, are you using a
|> |Windows
|> |> |> > Server
|> |> |> > > > > 2003 domain? Is the DNS server a Windows 2000 Server? And
|how
|> |did
|> |> |> you
|> |> |> > > > > install DNS?
|> |> |> > > > >
|> |> |> > > > > If you want, please also send the following to me at
|> |> |> > > (e-mail address removed):
|> |> |> > > > >
|> |> |> > > > > 1. A screenshot of the Forwarders tab as well as
screenshots
|> of
|> |> |any
|> |> |> > > error
|> |> |> > > > > messages you encounter.
|> |> |> > > > > 2. All related Event Logs.
|> |> |> > > > >
|> |> |> > > > > Thank you and have a nice day!
|> |> |> > > > >
|> |> |> > > > > Regards,
|> |> |> > > > > Joe Wu
|> |> |> > > > > Product Support Services
|> |> |> > > > > Microsoft Corporation
|> |> |> > > > >
|> |> |> > > > > Get Secure! - www.microsoft.com/security
|> |> |> > > > >
|> |> |> > > > > ====================================================
|> |> |> > > > > When responding to posts, please "Reply to Group" via your
|> |> |> newsreader
|> |> |> > so
|> |> |> > > > > that others may learn and benefit from your issue.
|> |> |> > > > > ====================================================
|> |> |> > > > > This posting is provided "AS IS" with no warranties, and
|> |confers
|> |> |no
|> |> |> > > > rights.
|> |> |> > > > >
|> |> |> > > > > --------------------
|> |> |> > > > > |From: "Jeff" <[email protected]>
|> |> |> > > > > |Subject: Conditional Forwarding Not Available
|> |> |> > > > > |Date: Thu, 25 Sep 2003 15:34:09 -0400
|> |> |> > > > > |Lines: 27
|> |> |> > > > > |X-Priority: 3
|> |> |> > > > > |X-MSMail-Priority: Normal
|> |> |> > > > > |X-Newsreader: Microsoft Outlook Express 6.00.2800.1158
|> |> |> > > > > |X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
|> |> |> > > > > |Message-ID: <[email protected]>
|> |> |> > > > > |Newsgroups: microsoft.public.win2000.dns
|> |> |> > > > > |NNTP-Posting-Host: bankofutica-gate-line-r.bankofutica.com
|> |> |> > > > 216.230.225.242
|> |> |> > > > > |Path:
|> |> |> cpmsftngxa06.phx.gbl!TK2MSFTNGP08.phx.gbl!tk2msftngp13.phx.gbl
|> |> |> > > > > |Xref: cpmsftngxa06.phx.gbl
|microsoft.public.win2000.dns:26616
|> |> |> > > > > |X-Tomcat-NG: microsoft.public.win2000.dns
|> |> |> > > > > |
|> |> |> > > > > |In harmony with KB 229840 I attempted to delete the . root
|> dns
|> |> |> entry
|> |> |> > > > using
|> |> |> > > > > |the dnscmd /ZoneDelete . /DsDel but received an error
|> |> |> > > > > |DNS_ERROR_ZONE_DOES_NOT_EXIST 9601 (00002581)
|> |> |> > > > > |
|> |> |> > > > > |If I look at the DNS Console I only see a . (root) entry
in
|> |the
|> |> |> > cached
|> |> |> > > > > |lookups and my regular domain is in the Forward Lookups.
|> |> |> > > > > |
|> |> |> > > > > |When I choose properties, and click on the Forwarders tab,
|> |> (which
|> |> |> is
|> |> |> > > not
|> |> |> > > > > |grayed out) there is a message displayed that says:
|> |"Conditional
|> |> |> > > > Forwarding
|> |> |> > > > > |is Not Available Because this Server is a Downlevel
Server"
|> |and
|> |> |> there
|> |> |> > > is
|> |> |> > > > no
|> |> |> > > > > |option to enable forwarders.
|> |> |> > > > > |
|> |> |> > > > > |This machine connects to a Proxy Server which is behind a
|> |> |firewall.
|> |> |> > > The
|> |> |> > > > > |proxy server has one NIC and has three entries for DNS,
one
|> is
|> |> |the
|> |> |> > DNS
|> |> |> > > > > |server mentioned above and the other two are the ISP
Public
|> |DNS
|> |> |> > > servers.
|> |> |> > > > I
|> |> |> > > > > |am interested in removing the 2 ISP entries so that I can
|> |> |eliminate
|> |> |> > > some
|> |> |> > > > > |possible event errors such as 5774. But in order to do
|this,
|> |my
|> |> |> > > clients
|> |> |> > > > > all
|> |> |> > > > > |point to the Proxy (client installed) so the Proxy would
|look
|> |to
|> |> |> the
|> |> |> > > DNS
|> |> |> > > > > |server to resolve a name, but I don't think I have
|something
|> |> |right
|> |> |> so
|> |> |> > > > that
|> |> |> > > > > I
|> |> |> > > > > |can enable Forwarding to ISP DNS servers.
|> |> |> > > > > |
|> |> |> > > > > |How can I make this work.
|> |> |> > > > > |
|> |> |> > > > > |Thanks
|> |> |> > > > > |Jeff Smyrski
|> |> |> > > > > |
|> |> |> > > > > |
|> |> |> > > > > |
|> |> |> > > > >
|> |> |> > > >
|> |> |> > > >
|> |> |> > >
|> |> |> > >
|> |> |> >
|> |> |> >
|> |> |>
|> |> |>
|> |> |
|> |> |
|> |> |
|> |>
|> |
|> |
|> |
|>
|
|
|
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top