DNS
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationDNS

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old July 12th, 2004, 12:25 PM
BMG BMG is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2003
Posts: 16 BMG User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
DNS forward lookup zone not registering chages.

We recently made some changes (added 2 new A records) to our forward lookup zone on a win2k3 server. However, the forward lookup zone is not registering these chages. The reverse zone does but not the forward one. I have not been able to figure out what the problem is for several days now. Any help will be appreciated.
Thanks,
-- Nick

Reply With Quote
  #2  
Old July 12th, 2004, 04:25 PM
BMG BMG is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2003
Posts: 16 BMG User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Here is some more information:
DNS lookup returns the following: http://www.dollardns.net/cgi-bin/dn...bmit=Send+Query

However, there should be 2 more entries in there:
mlist.saclaw.lib.ca.us 600 A 63.195.132.197
scllhip.saclaw.lib.ca.us 600 A 63.195.132.211.


I am not sure why the server is not showing these 2 A records. There are in the zone file.

Any ideas on what is going on?
Thanks,
-- Nick

Reply With Quote
  #3  
Old July 12th, 2004, 05:35 PM
BMG BMG is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2003
Posts: 16 BMG User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
At this point, the forward lookup zone is propagating to root hints and notify serves.

Ergo, the problem is that the changes is not registered. The changes show up in the zone file but quering the server, the changes do not show up.

Reply With Quote
  #4  
Old July 12th, 2004, 06:43 PM
SilentRage's Avatar
SilentRage SilentRage is offline
DNS/BIND Guru
Dev Shed Specialist (4000 - 4499 posts)
 
Join Date: Jun 2003
Location: OH, USA
Posts: 4,195 SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 1 Week 5 Days 15 h 53 m 4 sec
Reputation Power: 77
I see them just fine:

mlist.saclaw.lib.ca.us. 600 A 63.195.132.197
scllhip.saclaw.lib.ca.us. 600 A 63.195.132.211

The reason those records don't show up in the other query is cause they exist under a different domain. It's not like you were looking at a zone transfer, your server doesn't allow DNS Crawler to grab zone transfers.

However, notice we were using TCP before to see the records. Now let's see it with UDP.

mlist.saclaw.lib.ca.us. 600 A 63.195.132.197
scllhip.saclaw.lib.ca.us. 600 A 63.195.132.211

Interesting that it timed out. I know it's not firewall/router related cause the query you made using UDP works. MS DNS strikes again. Shame I don't know it better.
__________________
Send me a private message if you would like me to setup your DNS for you for a price of your choosing. This is the preferred method if your DNS needs to be fixed/setup fast and you don't have the time to bounce messages back and forth on a forum. Also, check out these links:

Whois Direct | DNS Crawler | NS Trace | Compare Free DNS Hosts

Last edited by SilentRage : July 12th, 2004 at 06:47 PM.

Reply With Quote
  #5  
Old July 16th, 2004, 03:19 PM
BMG BMG is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2003
Posts: 16 BMG User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
I have a secondary server (win2k) that returns the same information as the primary.

So, is there anything else I can do?

Reply With Quote
  #6  
Old July 16th, 2004, 06:52 PM
SilentRage's Avatar
SilentRage SilentRage is offline
DNS/BIND Guru
Dev Shed Specialist (4000 - 4499 posts)
 
Join Date: Jun 2003
Location: OH, USA
Posts: 4,195 SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 1 Week 5 Days 15 h 53 m 4 sec
Reputation Power: 77
Tell me what all forward zones you have setup on the server. I have a suspicion you've got a confusing subzone setup that could be causing problems and should be consolidated under a single zone.

Reply With Quote
  #7  
Old July 19th, 2004, 11:40 AM
BMG BMG is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2003
Posts: 16 BMG User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Only one forward zone: saclaw.lib.ca.us.

Reply With Quote
  #8  
Old July 19th, 2004, 12:32 PM
BMG BMG is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2003
Posts: 16 BMG User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
So, I can query the newly added records over TCP but not UDP. Older records can be queried over both TCP and UDP.
What does this actually mean? Aren't all queries going over UDP? And, what does it mean that server can be queried over TCP?

Thanks.

Reply With Quote
  #9  
Old July 19th, 2004, 12:41 PM
BMG BMG is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2003
Posts: 16 BMG User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Also, in your DNSCrawler, when you enter a.root-servers.net in server and query some FQDN that needs a referal but you check TCP, it seems that is only the first query is over TCP but subsequent queries are over UDP.

Reply With Quote
  #10  
Old July 20th, 2004, 03:45 AM
SilentRage's Avatar
SilentRage SilentRage is offline
DNS/BIND Guru
Dev Shed Specialist (4000 - 4499 posts)
 
Join Date: Jun 2003
Location: OH, USA
Posts: 4,195 SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 1 Week 5 Days 15 h 53 m 4 sec
Reputation Power: 77
That is correct, you should not try to resolve a domain from root using TCP cause not all servers allow TCP queries. DNS Crawler will only query the first server via TCP.

Attach your zone file for me. Don't know if you realized it, but MS DNS also has zone files. I'd like to take a look at it.

Reply With Quote
  #11  
Old July 20th, 2004, 11:51 AM
SilentRage's Avatar
SilentRage SilentRage is offline
DNS/BIND Guru
Dev Shed Specialist (4000 - 4499 posts)
 
Join Date: Jun 2003
Location: OH, USA
Posts: 4,195 SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 1 Week 5 Days 15 h 53 m 4 sec
Reputation Power: 77
Ok, now I think it might not be a normal problem. Something is/was very wrong. You made a query recently in DNS Crawler which caused my script to complain to me in my logs. It said that it was confused, it didn't know what the heck a certain record was. After looking through the access logs, I found out it was you who made that query. Remember when you made a query and it resulted in a "Unknown Record" result? That should never have happened. Both DNS Crawler and DIG had a problem with the dns response. Here's a link:

dig @63.195.132.195 211.132.195.63.in-addr.arpa ptr

I've looked at the raw response, and found the bug. The SOA record name field had a domain pointer (used for compression in DNS packets) with a value 1 greater than it should have been. Either this is the result of something seriously wrong with your server, or it's a bug in the server.

Last edited by SilentRage : July 20th, 2004 at 01:06 PM.

Reply With Quote
  #12  
Old July 23rd, 2004, 10:27 AM
BMG BMG is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2003
Posts: 16 BMG User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
The server is a windows 2003 server upgraded from windows NT. The problem was present on NT as well.

Reply With Quote
  #13  
Old July 23rd, 2004, 11:02 AM
alangrah alangrah is offline
Nettica DNS Services
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2004
Posts: 65 alangrah User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 5
Indeed very strange action from your server. Your server isn't named 'localhost' or 'local' or anything like that is it?

Have you tried adding a new record, maybe 'test' to see if that works? Have you tried deleting and recreating the entire zone from scratch? There are some known and extremely annoying bugs in w2k3 dns, but I have to admit this is the first time I've seen this particular one. Are you using AD, the registry, or zone files?

AlanGrah

Reply With Quote
  #14  
Old July 23rd, 2004, 11:46 AM
SilentRage's Avatar
SilentRage SilentRage is offline
DNS/BIND Guru
Dev Shed Specialist (4000 - 4499 posts)
 
Join Date: Jun 2003
Location: OH, USA
Posts: 4,195 SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 1 Week 5 Days 15 h 53 m 4 sec
Reputation Power: 77
Is there any error reporting in MS DNS server? When things get especially head scratching with BIND, the error messages always bail me out.

Reply With Quote
  #15  
Old July 23rd, 2004, 02:24 PM
BMG BMG is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2003
Posts: 16 BMG User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Quote:
Originally Posted by alangrah
Indeed very strange action from your server. Your server isn't named 'localhost' or 'local' or anything like that is it?

No.

Quote:
Originally Posted by alangrah
Have you tried adding a new record, maybe 'test' to see if that works?

Yes. That is what the problem is. The "old" records are OK. Any A record I add in is not working.

Quote:
Originally Posted by alangrah
Have you tried deleting and recreating the entire zone from scratch?

Yes.

Quote:
Originally Posted by alangrah
There are some known and extremely annoying bugs in w2k3 dns, but I have to admit this is the first time I've seen this particular one. Are you using AD, the registry, or zone files?

No AD.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationDNS > DNS forward lookup zone not propagating


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread