Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Andrzejek on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Cant Resolve to Outside URL

Status
Not open for further replies.

100mbs

MIS
Feb 14, 2002
142
US
I am trying to hit an external website from inside my business domain.

I have setup my 3 Win2K3 DNS servers with Forwarders to point to Google DNS, XO DNS, and OPEN DNS IP's. I also setup my DNS info on my DHCP server to point to the same external DNS Plus our internale DNS servers.

For some reason I can not get users to see the select few external URL's unless I add one of the External DNS IP's to there TCP Stack on their XP/Win7 PC's.

If anybody has any ideas I would love to hear them.
 
What happens when you try to perform an NSLOOKUP from these client machines (without the addition of the external DNS servers)
 
Here is the results.

Microsoft Windows [Version 6.1.7600]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.

C:\Users\nslookup
Default Server: server.xyz.com (our internal DNS Server)
Address: 112.118.0.12

> (External URL trying to hit)

Server: server.xyz.com (our internal DNS Server)
Address: 112.118.0.12

*** server.xyz.com can't find Non-existent domain
 
So I cleared the Cache on all of DNS Servers and still the site doesnt work.

Any suggestions?
 
Tried it with the "." after the org but no luck.
 
Bit of a lark but have you tried telnetting from your DNS server to the DNS servers listed in your forwarders list on port 53 (DNS query) or have you checked your firewall logs for how traffic on port 53 is being routed back to your DNS server.
Also have you performed a whois lookup of sss.org to find what DNS servers they are registered on as you might want to use one of these as your forwarders as well.
 
So i have added one of the DNS servers that sss.org is using. No luck still.

I can traceroute and ping the sss.org from my firewall that we are using to the internet.

I am looking through the logs on the same firewall now.
 
Here is what I get on my Firewall when i try to do a Reverse Name Resolution.


Resolver Response

DNS Server 172.16.0.1 Name Error - Meaningful only for responses from an authoritative name server, this code signifies that the domain name referenced in the query does not exist.
DNS Server 172.16.0.2 resolved to sss.org
DNS Server 172.16.0.3 resolved to sss.org
NetBios host 65.17.194.20 failed
 
I checked my firewall logs and it is showing my server sending traffic out to their external DNS server and then it sends bytes back to me.
 
I looked at the link and that is for NT4 We are runing Server 2003.
 
Regardless if its for NT4, have you tried removing WINS lookup as a test to see if it changes anything.
 
Netsec50,

Yes I do get a response when doing nslookup with DNS entries in DNS Forwarders.
 
Itsp1965,

I will try without a wins lookup now.
 
So i assigned a static IP to my Workstation and did not assign WINS server. I was still not able to do an nslookup on the URL.

I added one Internal DNS server at a time then tried to nslookup the url with no luck.
 
Thanks for all your suggestions. I have resolved this issue.

Added a Host record in one my zones in DNS and all is good.

Thanks again.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top