DNS problems on W2K server with MS Proxy installed

M

M Weisman

Hello all-
Hoping to find some help on this issue...
First, the config:
I have a Windows 2000 SP4 server configured as a one-armed, caching MS
Proxy 2.0 server, for allowing our employees access to the Internet.
It serves to control access, cache web pages, and serve DNS queries
for Internet access.
The server is not a DC and we run our domain in mixed mode.
DNS server services are configured for caching only.
The server uses our ISP's DNS server as it's primary and secondary DNS
servers and my firewall's internal address as it's default gateway.
The router on the local subnet uses the proxy server as it's default
gateway.
The proxy server has static routes for all internal subnets
Clients are configured to use a local DNS server as Primary (for
internal browsing) and the Proxy server as Secondary (for web
browsing)

Now, the problem:
Web seems to work OK, with one exception, DNS. DNS seems to work as
the wind blows! Web browsing wil be OK for two or three days, then we
will suddenly start receiving Proxy errors (Unable to resolve the
addres of the URL entered, etc..) generally indicating that the URLs
cannot be found. Sometimes this problem will clear up on it's own,
sometimes I can switch the Primary and Secondary DNS on the Proxy
server and that will clear it up. Sometimes rebooting the Proxy
server will clear the problem up.
I spoke to our ISP and they claim that they "currently have no
reported problems" with their DNS servers.
Goal:
I want to know that my config is rock solid before I go back to my ISP
and tell them that the problem is on their end because of X, Y, and Z.

Any help would be greatly appreciated.
Matt Weisman
Milwaukee, WI
 
P

Phillip Windell

M Weisman said:
Clients are configured to use a local DNS server as Primary (for
internal browsing) and the Proxy server as Secondary (for web
browsing)

There is the problem. Everything,..I repeat *everything*,...must use the
local DNS Server and that is the *only* one that must be used. The ISP's
DNS will appear in only one place and that is inside the Forwarder's List
within the configuration of you local DNS Server.
 
K

Kevin D. Goodknecht Sr. [MVP]

In
M Weisman said:
Hello all-
Hoping to find some help on this issue...
First, the config:
I have a Windows 2000 SP4 server configured as a
one-armed, caching MS Proxy 2.0 server, for allowing our
employees access to the Internet. It serves to control
access, cache web pages, and serve DNS queries for
Internet access.
The server is not a DC and we run our domain in mixed
mode.

Which is it. is it a DC or not? You can't have a Win2k domain without a DC.
DNS server services are configured for caching only.
The server uses our ISP's DNS server as it's primary and
secondary DNS servers and my firewall's internal address
as it's default gateway. The router on the local subnet
uses the proxy server as it's default gateway.
The proxy server has static routes for all internal
subnets
Clients are configured to use a local DNS server as
Primary (for internal browsing) and the Proxy server as
Secondary (for web browsing)

Now, the problem:
Web seems to work OK, with one exception, DNS. DNS seems
to work as the wind blows! Web browsing wil be OK for
two or three days, then we will suddenly start receiving
Proxy errors (Unable to resolve the addres of the URL
entered, etc..) generally indicating that the URLs cannot
be found. Sometimes this problem will clear up on it's
own, sometimes I can switch the Primary and Secondary DNS
on the Proxy server and that will clear it up. Sometimes
rebooting the Proxy server will clear the problem up.
I spoke to our ISP and they claim that they "currently
have no reported problems" with their DNS servers.
Goal:
I want to know that my config is rock solid before I go
back to my ISP and tell them that the problem is on their
end because of X, Y, and Z.

In an Active Directory Domain environment, you must have a local DNS server
preferably on a DC. All DCs and domain members must use the local DNS only
in TCP/IP properties, no ISP's allowed in any position. You can configure
your ISP's DNS as a forwarder only.
300202 - HOW TO: Configure DNS for Internet Access in Windows 2000
http://support.microsoft.com/?id=300202&FR=1

825036 - Best practices for DNS client settings in Windows 2000 Server and
in Windows Server 2003
http://support.microsoft.com/default.aspx?scid=kb;en-us;825036
 
M

M Weisman

Which is it. is it a DC or not? You can't have a Win2k domain without a DC.

It's not a DC, as was stated in the original message. Just because
it's not a DC doesn't mean we don't have other servers (among then
DCs, all of which are DNS servers) in the enterprise.

<snip>
 
M

M Weisman

Phil-
Thanks! Made some tweaks along these lines and have things running in top shape.
Matt
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top