DNS
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationDNS

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old May 1st, 2004, 05:53 PM
fudgemonster fudgemonster is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 1 fudgemonster User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Question Secondary ZOne not receiving current information in transfers

Hi

Our group is creating a private WAN connected over VPN tunnels using Netscreen hardware and software. We are using DNS and W2K as the backbone for our network and resource sharing internally and across the WAN.

The network consists of two LANs and a number of remote users who connect to one of the hubs. Currently each LAN has a primary DNS server setup to provide name service within each. In addition we created secondary zones on each lan to pull the information from the primary on the opposing LAN, therefore allowing users on each side to access resources by name on either LAN.

Lan1
Primary A – Secondary A

Lan2
Primary B – Secondary B

This was function reasonably well for a period, however in order to access high speed connections we changed ISPs and had to reestablish the tunnels. Once this was complete, we found that the secondary on Lan1 re-established the zone connections without problem. The secondary on Lan2 did not. We noticed the following event log errors

1202 - SceCli – an indication that the trust relationship had been broken
6534 – DNS – no explanations found (NetID, MS support). It seems to be associated with zone information not being received.

The trust failed because the DNS could not identify the trusted network on the other side of the tunnel. After not finding any errors in the configuration of the Lan2 secondary or the Lan1 primary, we recreated the secondary on Lan2. This did not initially work, however after a few hours the transfer occurred. The information transferred was old however (secondary index 1666, primary 1749). Over the period of the wait – the Lan1 server indicated successful transfer in the event log, however the Lan2 side showed the 6534 errors.

My questions

1) The research seemed to suggest that there may be illegal characters in the primary zone of Lan1, what are these illegal characters, how can we remove them?

2) That the secondary on Lan1 us receiving and updating without problem is mystifying – it suggests that the connectivity across the tunnel is there. What are we missing?

3) Is it likely that the continuing lack of updates will eventually result in the Lan2 secondary expiring? How can we address that (at least short term in the absence of a solution)?

Any thoughts, suggestions, solutions, fixes or workarounds would be appreciated.

Thanks

Reply With Quote
  #2  
Old May 1st, 2004, 08:01 PM
SilentRage's Avatar
SilentRage SilentRage is offline
DNS/BIND Guru
Dev Shed Specialist (4000 - 4499 posts)
 
Join Date: Jun 2003
Location: OH, USA
Posts: 4,193 SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level)SilentRage User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 1 Week 5 Days 14 h 35 m 27 sec
Reputation Power: 77
Well I glanced through your post. Can't find a domain to test. Oh well. One thing that you should know is that you need to raise the value of the SOA serial every time you change the zone information. Otherwise the secondary will never know that it needs to redownload the zone.
__________________
Send me a private message if you would like me to setup your DNS for you for a price of your choosing. This is the preferred method if your DNS needs to be fixed/setup fast and you don't have the time to bounce messages back and forth on a forum. Also, check out these links:

Whois Direct | DNS Crawler | NS Trace | Compare Free DNS Hosts

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationDNS > Secondary ZOne not receiving current information in transfers


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 5 hosted by Hostway