+ Post New Thread
Results 1 to 4 of 4
Windows Server 2000/2003 Thread, Cannot query External host IP from new DNS Server + DC in Technical; Hi All, I've just promote this NewDC01 serve which act as Domain Controller + Global Catalog and DNS, from the ...
  1. #1

    Join Date
    May 2009
    Location
    Sydney
    Posts
    282
    Thank Post
    322
    Thanked 3 Times in 3 Posts
    Rep Power
    12

    Question Cannot query External host IP from new DNS Server + DC

    Hi All,

    I've just promote this NewDC01 serve which act as Domain Controller + Global Catalog and DNS,
    from the DNS console, i can resolve simple and recursive query.

    from this server cmd prompt i can perform nslookup successfully to the world and internal host.

    However when i use this NewDC01 IP address as 1st DNS in my computer, it failed for the external ?

    the following is the DCdiag /DNS result:

    Code:
    Domain Controller Diagnosis 
    Performing initial setup:
       Done gathering initial info. 
    Doing initial required tests 
       Testing server: Default-First-Site-Name\NewDC01
          Starting test: Connectivity
             ......................... NewDC01 passed test Connectivity 
    Doing primary tests 
       Testing server: Default-First-Site-Name\NewDC01 
    DNS Tests are running and not hung. Please wait a few minutes... 
       Running partition tests on : DomainDnsZones 
       Running partition tests on : ForestDnsZones 
       Running partition tests on : Schema 
       Running partition tests on : Configuration 
       Running partition tests on : Domain 
       Running enterprise tests on : Domain.com
          Starting test: DNS
             Test results for domain controllers: 
                DC: NewDC01.Domain.com
                Domain: Domain.com 
    
                   TEST: Forwarders/Root hints (Forw)
                      Error: Forwarders list has invalid forwarder: 139.130.4.4 (<name unavailable>)
                      Error: Forwarders list has invalid forwarder: 203.50.2.71 (<name unavailable>) 
                   TEST: Delegations (Del)
                      Error: DNS server: DCDNSExchange01.Domain.com. IP:10.2.2.4 [Broken delegated domain Domain.com.Domain.com.]
                      Error: DNS server: DCDNS01.Domain.com. IP:10.2.2.3 [Broken delegated domain Domain.com.Domain.com.]
                      Error: DNS server: NewDC01.Domain.com. IP:10.2.2.34 [Broken delegated domain Domain.com.Domain.com.]
                      Error: DNS server: RemoteDC01.Domain.com. IP:10.1.2.13 [Broken delegated domain Domain.com.Domain.com.] 
    
             Summary of test results for DNS servers used by the above domain controllers: 
                DNS server: 10.1.2.13 (RemoteDC01.Domain.com.)
                   1 test failure on this DNS server
                   Delegation is broken for the domain Domain.com.Domain.com. on the DNS server 10.1.2.13 
                DNS server: 10.2.2.3 (DCDNS01.Domain.com.)
                   1 test failure on this DNS server
                   Delegation is broken for the domain Domain.com.Domain.com. on the DNS server 10.2.2.3 
                DNS server: 10.2.2.34 (NewDC01.Domain.com.)
                   1 test failure on this DNS server
                   Delegation is broken for the domain Domain.com.Domain.com. on the DNS server 10.2.2.34 
                DNS server: 10.2.2.4 (DCDNSExchange01.Domain.com.)
                   1 test failure on this DNS server
                   Delegation is broken for the domain Domain.com.Domain.com. on the DNS server 10.2.2.4 
                DNS server: 139.130.4.4 (<name unavailable>)
                   1 test failure on this DNS server
                   This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 139.130.4.4 
                DNS server: 203.50.2.71 (<name unavailable>)
                   1 test failure on this DNS server
                   This is not a valid DNS server. PTR record query for the 1.0.0.127.in-addr.arpa. failed on the DNS server 203.50.2.71 
             Summary of DNS test results: 
                                                Auth Basc Forw Del  Dyn  RReg Ext
                   ________________________________________________________________
                Domain: Domain.com
                   NewDC01                       PASS PASS FAIL FAIL PASS PASS n/a 
             ......................... Domain.com failed test DNS
    =========
    DNS test . . . . . . . . . . . . . : Failed
              [WARNING] Cannot find a primary authoritative DNS server for the name
                'NewDC01.Domain.com.'. [ERROR_TIMEOUT]
                The name 'NewDC01.Domain.com.' may not be registered in DNS.
        [FATAL] Could not open file C:\WINDOWS\system32\config\netlogon.dns for reading.
        [FATAL] Could not open file C:\WINDOWS\system32\config\netlogon.dns for reading.
        [FATAL] No DNS servers have the DNS records for this DC registered. 
    
    Redir and Browser test . . . . . . : Failed
        List of NetBt transports currently bound to the Redir
            NetBT_Tcpip_{4EF94F59-3AC4-49D2-B273-AD028AAB3211}
            NetBT_Tcpip_{E3EBCC79-1D85-4CDF-AE17-9B57770C1CFF}
        The redir is bound to 2 NetBt transports. 
        List of NetBt transports currently bound to the browser
            NetBT_Tcpip_{4EF94F59-3AC4-49D2-B273-AD028AAB3211}
            NetBT_Tcpip_{E3EBCC79-1D85-4CDF-AE17-9B57770C1CFF}
        The browser is bound to 2 NetBt transports.
        [FATAL] Cannot send mailslot message to 'DOMAIN*' via browser. [ERROR_INVALID_FUNCTION]
    and the cmd prompt history list:

    Code:
    C:\Documents and Settings\Administrator>ping vcenter
    
    Pinging BackupServer.Domain.com [10.2.2.5] with 32 bytes of data:
    
    Reply from 10.2.2.5: bytes=32 time<1ms TTL=128
    Reply from 10.2.2.5: bytes=32 time<1ms TTL=128
    Reply from 10.2.2.5: bytes=32 time<1ms TTL=128
    Reply from 10.2.2.5: bytes=32 time<1ms TTL=128
    
    Ping statistics for 10.2.2.5:
        Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 0ms, Maximum = 0ms, Average = 0ms
    
    C:\Documents and Settings\Administrator>nslookup
    DNS request timed out.
        timeout was 2 seconds.
    *** Can't find server name for address 10.2.2.34: Timed out
    Default Server:  UnKnown
    Address:  10.2.2.34
    
    > vcenter
    Server:  UnKnown
    Address:  10.2.2.34
    
    DNS request timed out.
        timeout was 2 seconds.
    *** Request to UnKnown timed-out
    > NewDC01
    Server:  UnKnown
    Address:  10.2.2.34
    
    DNS request timed out.
        timeout was 2 seconds.
    *** Request to UnKnown timed-out
    >
    Any kind of help would be greatly appreciated.

    Thanks.

  2. #2

    Join Date
    Nov 2009
    Posts
    54
    Thank Post
    3
    Thanked 12 Times in 12 Posts
    Rep Power
    13
    Opn your Dnsmgmt on your server. Right click on your server > Properties > Forwarders tab. Check to make sure your external DNS servers are listed there.

  3. Thanks to Nixphoe from:

    albertwt (7th November 2009)

  4. #3

    Join Date
    May 2009
    Location
    Sydney
    Posts
    282
    Thank Post
    322
    Thanked 3 Times in 3 Posts
    Rep Power
    12

    Exclamation

    Hi

    Sorry for the late reply due to the weekend activity :-0

    I've just found out that the Subnet mask for the NewDC01 was 255.255.255.0 it is supposed to be 255.255.254.0 >_<

    after I changed it then i can use the NSlookup query on test host :-)

    one problem still remains though it's the Broken delegation, what is that actually means ?

  5. #4
    bio
    bio is offline
    bio's Avatar
    Join Date
    Apr 2008
    Location
    netherlands
    Posts
    520
    Thank Post
    16
    Thanked 130 Times in 102 Posts
    Rep Power
    38
    I bet you have an entry in your forward lookup zone like domain.com -> com -> domain thats has an A record in it. Delete com- > domain and restart DNS service

    bio..



SHARE:
+ Post New Thread

Similar Threads

  1. DNS + DC GPO Query
    By PRicho in forum Windows
    Replies: 1
    Last Post: 11th September 2009, 11:56 AM
  2. My DNS won't release old host names!
    By steele_uk in forum Windows
    Replies: 5
    Last Post: 10th September 2009, 10:32 AM
  3. Unable to query host name
    By scalywag66 in forum Windows
    Replies: 6
    Last Post: 10th June 2009, 02:55 AM
  4. Exchange and DNS Query
    By rob998 in forum Windows
    Replies: 7
    Last Post: 9th September 2008, 11:45 PM
  5. DNS Query
    By brahma in forum Windows
    Replies: 4
    Last Post: 17th July 2008, 03:33 PM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •