• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

DNS Server on ISA fails to operate regularly. No clues.

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 General ] >> Installation >> DNS Server on ISA fails to operate regularly. No clues. Page: [1]
Login
Message << Older Topic   Newer Topic >>
DNS Server on ISA fails to operate regularly. No clues. - 25.Feb.2005 9:45:00 AM   
thona

 

Posts: 16
Joined: 4.May2001
Status: offline
I have a setup where we have external offices. Those get an ISA box from us that includes:
* Active Directory
* DHCP
* DNS Server
* WUS on an internal IIS.

The concept is that this box basically is their end-side. Most of these offices are small and run a minor number of items, and the ISA-Server is basically acting as the ONLY server they have. We know about this being sub-optimal from a security point of view, but it basically is the only cost-effective solution.

ISA Server is configured to dial into the ISP and establish a persistent VPN to the central office automatically. It uses it's own DNS server for DNS, forwarding requests to the provider's DNS (as it has the local domain through ActiveDirectory). It has an internal IP network, normally a DMZ ip network (connected to a WLAN adapter for the office, so people on the WLAN need to VPN into the ISA Server) and a PPPOE connection to an internet provider.

Now, here is my problem. Regularly (every couple of hours), the DNS Server will stop responding. No clue is given to why - no event log entries. In the DNS manager I have set up monitoring, and it also turnes to "Fail" on both tests. When this happens, DNS is totally breaking down for the respective location.

Anyone a clue what this is? We have, in one location, put the DNS to a separate server, and then it works flawless. I start assuming that it is the firewall starting to block the ISA Server, but I am totally clueless in general on WHY this happens - it works perfectly for some hours after I restart the firewall.
Post #: 1
RE: DNS Server on ISA fails to operate regularly. No cl... - 27.Feb.2005 3:21:00 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Thona,

The ISA firewall on a DC is a no-go. Remember, its a network firewall, like CP, PIX, Netscreen etc. You don't put Web servers, Kazaa servers or AD on those boxes either.

HTH<
Tom

(in reply to thona)
Post #: 2
RE: DNS Server on ISA fails to operate regularly. No cl... - 27.Feb.2005 3:35:00 PM   
thona

 

Posts: 16
Joined: 4.May2001
Status: offline
Good.

You are willing to pay the difference in required hardware and licenses?

(in reply to thona)
Post #: 3
RE: DNS Server on ISA fails to operate regularly. No cl... - 28.Feb.2005 12:25:00 AM   
longman

 

Posts: 50
Joined: 7.Feb.2005
Status: offline
Do the isa firewall logs have any entries that show a dns issue with the server?

(in reply to thona)
Post #: 4
RE: DNS Server on ISA fails to operate regularly. No cl... - 28.Feb.2005 6:17:00 AM   
thona

 

Posts: 16
Joined: 4.May2001
Status: offline
This is actually the problem. No, I do not get any hints about something going wrong. It is just that the DNS seems to stop responding.

You know, in DNS you can set up monitoring, and this also fails. I can restart the DNS service and it does not work, so I seriously doubt this is an issue related to the DNS service itself.

(in reply to thona)
Post #: 5
RE: DNS Server on ISA fails to operate regularly. No cl... - 9.Mar.2005 11:38:00 AM   
Dwayne75

 

Posts: 3
Joined: 1.Mar.2005
Status: offline
I have the exact same problem, as I have ISA 2004 running on my Sbs server. The problem seems to be down to the MSDE engine using too much memory. I find it uses getting on to 2gb of ram. I restart this instance of msde and suddenly the DNS starts working again. I am going to try and get sp3 for msde installed to see if that helps.

(in reply to thona)
Post #: 6
RE: DNS Server on ISA fails to operate regularly. No cl... - 9.Mar.2005 11:44:00 AM   
thona

 

Posts: 16
Joined: 4.May2001
Status: offline
This is interesting.

I have not checked this yet, but I will next time the thing fails. If this is the case, then this can be handled easily - simply by limiting the amount of memory the MSDE uses.

(in reply to thona)
Post #: 7

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 General ] >> Installation >> DNS Server on ISA fails to operate regularly. No clues. Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts