• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Problems publishing a DNS query srv.

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2000 General] >> Server Publishing >> Problems publishing a DNS query srv. Page: [1]
Login
Message << Older Topic   Newer Topic >>
Problems publishing a DNS query srv. - 27.Feb.2002 10:24:00 PM   
alejandro

 

Posts: 9
Joined: 14.Jul.2001
From: Costa Rica
Status: offline
Hi all.
I've been publishing several DNS servers on the same ISA machine with no problems. They work great.
But now I'm trying to publish a DNS on an internal W2K box and .... no success.
If try to make a query using nslookup and start network monitor, I found that the query reaches the internal DNS Server but the reply does not reach back to the client.
I placed a packet filter receive/send - send/receive - up/down on Local UPD/53 and nothing.
If I allow Zone transfers and open TCP/53 the transfer works immediatelly.
From time to time the DNS replies but that is 1 in 20 queries.
The problem is with UPD.
I found an KB article Q312640 that states:

"A DNS server that is configured as a secure NAT or firewall client to ISA Server may stop resolving names. When you restart the DNS service on the internal DNS server or restart the Firewall service on the ISA Server computer, the problem is temporarily resolved. A Network Monitor trace may show that the ISA Server computer is returning "Destination Port Unreachable". This issue could also occur with a UDP program other than DNS."

The ISA Server has SP1.
This is a big issue!
Any help will be great.
Thanks.
Post #: 1
RE: Problems publishing a DNS query srv. - 3.Mar.2002 11:34:00 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi Alejandro,

Are the DNS servers on the ISA Server contending for the port on the external interface of the ISA Server and preventing publishing?

Thanks!

Tom

(in reply to alejandro)
Post #: 2
RE: Problems publishing a DNS query srv. - 5.Mar.2002 10:23:00 PM   
alejandro

 

Posts: 9
Joined: 14.Jul.2001
From: Costa Rica
Status: offline
Thanks for the reply Tom and no, there's no DNS on the ISA box.

(in reply to alejandro)
Post #: 3
RE: Problems publishing a DNS query srv. - 11.Apr.2002 4:07:00 AM   
feliciogs

 

Posts: 10
Joined: 20.Jul.2001
From: Recife, PE, Brazil
Status: offline
Hi Tom,

I have the same problem, but when you query with timeout between 10-20 second (default is 02seconds, just for remember), i can get the answers and this problem continues until i restart the server. After restart, the answer stay fine for a unknown time, reappearing the problem after 01 day/week/month (i just now the problem is occurring, after stops receive mails because the senders cannot resolve mx record)...

If you now a solution (I already running W2k SP2 w/ ISA SP1), please answer us... I have this problem in 04 ISA servers on 04 internet different networks and 04 different servers & nics.

TIA.

Felicio Santos.

PS: My english is under construction.

quote:
Originally posted by tshinder:
Hi Alejandro,

Are the DNS servers on the ISA Server contending for the port on the external interface of the ISA Server and preventing publishing?

Thanks!

Tom


(in reply to alejandro)
Post #: 4
RE: Problems publishing a DNS query srv. - 19.May2002 3:07:00 AM   
olicharl

 

Posts: 3
Joined: 19.May2002
Status: offline
Have you found a solution to your problem ? I'm interested in because I have the same problem when publishing an internal DNs to external using ISA.

(in reply to alejandro)
Post #: 5
RE: Problems publishing a DNS query srv. - 18.Jul.2002 4:40:00 PM   
msonnentag

 

Posts: 63
Joined: 7.Jan.2002
From: Minneapolis, MN
Status: offline
Did anyone ever find a solution to this. I am having this exact same problem.

(in reply to alejandro)
Post #: 6
RE: Problems publishing a DNS query srv. - 18.Jul.2002 10:38:00 PM   
LoginKat

 

Posts: 12
Joined: 18.Jul.2002
Status: offline
Here's my scenario which works great and I think addresses your issues.

MachineA - Active Directory enabled DNS (PDC)
MachineB - DNS Server for Hosted Internet Sites
MachineC - ISA Server with caching only DNS

The idea is to provide DNS services for the Active Directory, the Hosted Internet Sites, AND external internet queries for your internal clients, and also to publish the Hosted Internet Sites to external clients.

MachineC runs DNS server in caching only mode (no zone files) with recursion turned ON. ISA on this machine uses standard Server Publishing rules to publish the DNS server on MachineB for external clients.

MachineB contains the zone files ONLY for the Hosted Sites and has recursion DISABLED. It also has MachineC listed as its default gateway.

The DNS server on MachineA (which has all the Active Directory entries) is configured to use Forwarders without recursion. The first forwarder is to MachineB, the second is to MachineC. MachineA itself has recursion enabled (its only off for the Forwarders).

The client machine has only one DNS entry pointing to MachineA. MachineA tries to resolve the request against the Active Directory. Failing that it goes to the forwarders trying first to resolve against the locally hosted internet sites and then to the ISA server which handles external internet name resolution.

External clients get name resolution directly thru the ISA Server Publishing rules. Since MachineC is listed as the default gateway, query requests know how to find their way back to the ISA box.

Does this make sense?

[ July 18, 2002, 10:41 PM: Message edited by: ISAKat ]

(in reply to alejandro)
Post #: 7

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2000 General] >> Server Publishing >> Problems publishing a DNS query srv. Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts