Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: DC DNS Errors and blocks internet traffic  (Read 24780 times)

0 Members and 1 Guest are viewing this topic.

Chrisxs5

    Topic Starter


    Hopeful
  • Sup!?
  • Thanked: 8
    • Where we learn IT daily!
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 8
DC DNS Errors and blocks internet traffic
« on: June 22, 2009, 07:23:40 PM »
I seem to be getting errors 4005 and 4015 evry other day on my 2003 DC. When this happens all interent is blocked for domains on the controller. I know we still have internet for several reasons, our VOIP system is on a completely different server system but uses the same T1 as well as the router will ping outside websites.

Another weird thing about this is the network will allow some outgoing traffic. I have some scripts that run every 5 minutes to test that my offsite websites are up and running, I get the text message every time while trying to figure out what is up.

The internet is up and running right now but  will go down if I cant figure out the cause.

(The DC is a spare Dell I had with a 1 gig proc and 256 memory, running Server 2003 and all updates are current)
Check out my blog: http://vitrookie.com

System, Network, Virtualization, Storage, ETC Admin with a bunch of certs and an ego trip!

Rob Pomeroy



    Prodigy

  • Systems Architect
  • Thanked: 124
    • Me
  • Experience: Expert
  • OS: Other
Re: DC DNS Errors and blocks internet traffic
« Reply #1 on: June 24, 2009, 06:49:04 AM »
Are you using ISA?

Are you using that server for DHCP/as a DNS server for other machines?

PLEASE treat that server to a memory upgrade!
Only able to visit the forums sporadically, sorry.

Geek & Dummy - honest news, reviews and howtos

jerryheavyarms



    Apprentice

  • http://www.youtube.com/theoldpath
  • Thanked: 13
    • Bible insights by THE MOST SENSIBLE PREACHER OF OUR TIME.
  • Experience: Beginner
  • OS: Linux variant
Re: DC DNS Errors and blocks internet traffic
« Reply #2 on: June 24, 2009, 09:06:51 AM »
Also what do you get when you try to ping sites from the internet such as yahoo.com or google.com?
"Most complex problems do have a solution. It is only that we don't attempt to think. So let's apply: Dont just do something, sit there."
--Kuya Daniel Razon

Everything in this world will remind us of God, even every drop of a leaf from its stem will remind us of His glory. -Bro.Eli Soriano

Chrisxs5

    Topic Starter


    Hopeful
  • Sup!?
  • Thanked: 8
    • Where we learn IT daily!
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 8
Re: DC DNS Errors and blocks internet traffic
« Reply #3 on: June 24, 2009, 11:57:46 AM »
Are you using ISA?

Are you using that server for DHCP/as a DNS server for other machines?

PLEASE treat that server to a memory upgrade!
Were are not using ISA, I really wish we were. We have a Sonicwall that serves has the firewall. The DC does also serve as the DHCP and DNS server. It also seems that when the issue occurs, every time I make a chnage in  the DNS, I will get the net for about 20 seconds.

I will go ahead and max the server out in memory, it will only go to 1g tho.
Check out my blog: http://vitrookie.com

System, Network, Virtualization, Storage, ETC Admin with a bunch of certs and an ego trip!

Chrisxs5

    Topic Starter


    Hopeful
  • Sup!?
  • Thanked: 8
    • Where we learn IT daily!
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 8
Re: DC DNS Errors and blocks internet traffic
« Reply #4 on: June 24, 2009, 11:58:43 AM »
Also what do you get when you try to ping sites from the internet such as yahoo.com or google.com?
I can not ping from a cmd prompt at will. I can ping from within our router/firewall (Sonicwall) just fine.
Check out my blog: http://vitrookie.com

System, Network, Virtualization, Storage, ETC Admin with a bunch of certs and an ego trip!

jerryheavyarms



    Apprentice

  • http://www.youtube.com/theoldpath
  • Thanked: 13
    • Bible insights by THE MOST SENSIBLE PREACHER OF OUR TIME.
  • Experience: Beginner
  • OS: Linux variant
Re: DC DNS Errors and blocks internet traffic
« Reply #5 on: June 24, 2009, 12:28:41 PM »
Hmm..Have you tried to restart DNS/DHCP
"Most complex problems do have a solution. It is only that we don't attempt to think. So let's apply: Dont just do something, sit there."
--Kuya Daniel Razon

Everything in this world will remind us of God, even every drop of a leaf from its stem will remind us of His glory. -Bro.Eli Soriano

Chrisxs5

    Topic Starter


    Hopeful
  • Sup!?
  • Thanked: 8
    • Where we learn IT daily!
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 8
Re: DC DNS Errors and blocks internet traffic
« Reply #6 on: June 24, 2009, 12:36:38 PM »
That seems to do no good either. Most of the computers are static IP's anyways, I have basically ruled out the DHCP. I think it is the darn DNS. When I restart it, I will get the internet for about the same 20 seconds.

The first time this happened I added a Host A record pointing to the router and that seem to fix. The second time I deleted the record, The 3rd time I quit screwing with that record.
Check out my blog: http://vitrookie.com

System, Network, Virtualization, Storage, ETC Admin with a bunch of certs and an ego trip!

jerryheavyarms



    Apprentice

  • http://www.youtube.com/theoldpath
  • Thanked: 13
    • Bible insights by THE MOST SENSIBLE PREACHER OF OUR TIME.
  • Experience: Beginner
  • OS: Linux variant
Re: DC DNS Errors and blocks internet traffic
« Reply #7 on: June 24, 2009, 12:50:31 PM »
Can you visit the site using their IP address?

May we know how did you set up your servers? where did you point the server's DNS and alternate DNS server?
"Most complex problems do have a solution. It is only that we don't attempt to think. So let's apply: Dont just do something, sit there."
--Kuya Daniel Razon

Everything in this world will remind us of God, even every drop of a leaf from its stem will remind us of His glory. -Bro.Eli Soriano

Chrisxs5

    Topic Starter


    Hopeful
  • Sup!?
  • Thanked: 8
    • Where we learn IT daily!
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 8
Re: DC DNS Errors and blocks internet traffic
« Reply #8 on: June 24, 2009, 12:58:07 PM »
No I can not visit the sites by IP address. I did try that.

The original design when I came on was all 2K servers including the 2 DC's. I built the 2003 DC and promoted it to master in all areas. I then (after giving it a week of replication) demoted all the other DC's since they were actual application and SQL servers. I have not yet created the alternate DC yet. And yes: I know better.  :-[

(You can interchange DC and DNS if you would like, it was all done the same way.)
Check out my blog: http://vitrookie.com

System, Network, Virtualization, Storage, ETC Admin with a bunch of certs and an ego trip!

Rob Pomeroy



    Prodigy

  • Systems Architect
  • Thanked: 124
    • Me
  • Experience: Expert
  • OS: Other
Re: DC DNS Errors and blocks internet traffic
« Reply #9 on: June 24, 2009, 02:14:52 PM »
By coincidence I think 20 seconds is the initial default timeout on most Windows clients' DNS queries.  Will give this some more thought, but just wanted to toss that one in there for now.
Only able to visit the forums sporadically, sorry.

Geek & Dummy - honest news, reviews and howtos

Chrisxs5

    Topic Starter


    Hopeful
  • Sup!?
  • Thanked: 8
    • Where we learn IT daily!
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 8
Re: DC DNS Errors and blocks internet traffic
« Reply #10 on: June 25, 2009, 08:19:12 AM »
By coincidence I think 20 seconds is the initial default timeout on most Windows clients' DNS queries.  Will give this some more thought, but just wanted to toss that one in there for now.
I had a feeling it was something like that. I think tonight I will stop DNS and seewhat effect that has on the system as well as throwing those Host A records in back in.
Check out my blog: http://vitrookie.com

System, Network, Virtualization, Storage, ETC Admin with a bunch of certs and an ego trip!

Rob Pomeroy



    Prodigy

  • Systems Architect
  • Thanked: 124
    • Me
  • Experience: Expert
  • OS: Other
Re: DC DNS Errors and blocks internet traffic
« Reply #11 on: June 25, 2009, 11:28:15 AM »
I'd be interested in an answer to Jerry's question - the 2003 server - what DNS servers is it pointing at?

SonicWalls are a PITA by the way.  You already know that.  ;)  If price is an issue, better get a Vyatta.

One last question: when the internet appears to be down, if you run "nslookup" from a client workstation, what happens?
Only able to visit the forums sporadically, sorry.

Geek & Dummy - honest news, reviews and howtos

Chrisxs5

    Topic Starter


    Hopeful
  • Sup!?
  • Thanked: 8
    • Where we learn IT daily!
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 8
Re: DC DNS Errors and blocks internet traffic
« Reply #12 on: June 25, 2009, 12:33:08 PM »
I might not be understanding the question, which happens alot with me. But here is answer just the same  ;D

The DC is also the DNS server (.10), all computers point here, including itself. The router serves as the firewall also(.1).
Check out my blog: http://vitrookie.com

System, Network, Virtualization, Storage, ETC Admin with a bunch of certs and an ego trip!

Rob Pomeroy



    Prodigy

  • Systems Architect
  • Thanked: 124
    • Me
  • Experience: Expert
  • OS: Other
Re: DC DNS Errors and blocks internet traffic
« Reply #13 on: June 26, 2009, 01:45:35 AM »
So let me just check I've got this right.  Your domain controller has a single network card on your LAN (it is not operating as a router).  Its DNS server points only at itself for all DNS queries.  In that case, how can it resolve queries concerning external domains?
Only able to visit the forums sporadically, sorry.

Geek & Dummy - honest news, reviews and howtos

Chrisxs5

    Topic Starter


    Hopeful
  • Sup!?
  • Thanked: 8
    • Where we learn IT daily!
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 8
Re: DC DNS Errors and blocks internet traffic
« Reply #14 on: June 26, 2009, 07:50:17 AM »
So let me just check I've got this right.  Your domain controller has a single network card on your LAN (it is not operating as a router).  Its DNS server points only at itself for all DNS queries.  In that case, how can it resolve queries concerning external domains?
You do have it all right. THe DC doesnt need to resolve external DNS queries for itself only for the computers going through it. This is my the theory in my head  :-\, do I need to change some things?
Check out my blog: http://vitrookie.com

System, Network, Virtualization, Storage, ETC Admin with a bunch of certs and an ego trip!