Reggie Posted June 14, 2013 Posted June 14, 2013 Hi, I am having some problems on a Windows domain, quite frequently the Internet will go down. I think it is DNS related as the only fix is to flush the DNS cache on the server. The Internet connection is still up when it happens, but the clients get the usual DNS error when trying to browse the web. I have looked through the DNS configuartion many times and it all looks fine. Can anyone help?
plexer Posted June 14, 2013 Posted June 14, 2013 How are your dns servers resolving external addresses via root hints or an isp dns server? Ben
psydii Posted June 14, 2013 Posted June 14, 2013 What do the firewall logs say? Sometimes Firewalls get twitchy at the rate a DC might be making DNS look ups and start blocking them.
Reggie Posted June 14, 2013 Author Posted June 14, 2013 root hints, I've even tried using Google public DNS.
Reggie Posted June 14, 2013 Author Posted June 14, 2013 I've not looked at the firewall logs, I'll take a look and report back. Thanks.
pantscat Posted June 14, 2013 Posted June 14, 2013 Sometimes Firewalls get twitchy at the rate a DC might be making DNS look ups and start blocking them. Yes, indeed -some firewalls are particularly unhappy about this. I had a similar issue whereby we had some firewall rules that were based on destination hostnames rather than IP addresses and all the additional DNS lookups caused issues.
psydii Posted June 14, 2013 Posted June 14, 2013 There is specific documentation (and a GUI) for dealing with this in TMG, no idea about anything else.
Oaktech Posted June 14, 2013 Posted June 14, 2013 Threat Management Gateway. Microsoft's now deprecated successor to ISA If you don't know about it, don't try and find out. It's a world of pain you don't need! 1
psydii Posted June 14, 2013 Posted June 14, 2013 TMG, like Windows 7 is great once it has three years worth of hotfixes installed. I love the level of diagnostics available, far superior to most commercial firewalls, and the tools are familiar to any Windows Admin. Linux/BSD it ain't. I'm quite sad that its going.
cogrady84 Posted June 20, 2013 Posted June 20, 2013 (edited) I've been using TMG for almost a year now, yes I had some serious headaches with setup and maintenance for the first 3 months, but after everything is nailed down, its a great piece of kit with some very high level diagnostics/logging capabilities. Back on-topic, take a look at your flood mitigation settings (or equivalent) on your firewall and create an exception for your DC(s) so that they don't trigger a DoS when you have a spike in activity. Edited June 20, 2013 by cogrady84
pantscat Posted June 20, 2013 Posted June 20, 2013 So how did you resolve it pantscat? Sorry - missed this! Basically it's a case of going through all the rules and removing any references to hostnames and substituting them for IPs or IP ranges. Didn't take too long and it solves this particular problem. Oh, and RIP TMG... replacing this is causing me a headache!
cogrady84 Posted June 20, 2013 Posted June 20, 2013 Sorry - missed this! Basically it's a case of going through all the rules and removing any references to hostnames and substituting them for IPs or IP ranges. Didn't take too long and it solves this particular problem. Oh, and RIP TMG... replacing this is causing me a headache! What are you replacing TMG with?
pantscat Posted June 20, 2013 Posted June 20, 2013 What are you replacing TMG with? Exactly. No idea yet... although my initial thoughts are that it'll need to "boxes" to replace it entirely. I'll probably end up with a firewall of some sort and then UAG in order to publish OWA/ActiveSync/SharePoint etc. I am trialing Smoothwall Advanced Firewall at the moment but I'm just not terribly keen on using it at the edge... I've got a bit of a dislike for Linux that I can't really justify!
pantscat Posted June 20, 2013 Posted June 20, 2013 Having said that - I have just spotted this: LoadMaster Microsoft TMG Load Balancer | Endpoint Load Balancing | Load Balancer | Europe, Africa
chazzy2501 Posted June 20, 2013 Posted June 20, 2013 (edited) have you specified more than 1 external dns address on your dns server? you could use this tool to test external DNSs and it may trigger any firewall rule into blocking you if there is one. https://www.grc.com/dns/benchmark.htm Edited June 20, 2013 by chazzy2501
psydii Posted June 20, 2013 Posted June 20, 2013 I have heard murmurings about some sort of roadmap for functionality lost by the removal of TMG due in the next month or so... It is also interesting to note that on some recent MS/MVP sites outlining the migration to exchange 2013 still include TMG as the edge... the message seems to be very strongly - don't retire it yet...
cogrady84 Posted June 21, 2013 Posted June 21, 2013 I have heard murmurings about some sort of roadmap for functionality lost by the removal of TMG due in the next month or so... It is also interesting to note that on some recent MS/MVP sites outlining the migration to exchange 2013 still include TMG as the edge... the message seems to be very strongly - don't retire it yet... I don't really have the option of retiring TMG, it's only been in a year and as far as i'm concerned, learning new firewalls is one of the toughest tasks! I saw a recommendation for Citrix NetScaler as a TMG replacement yesterday... not sure on that one
pantscat Posted June 21, 2013 Posted June 21, 2013 Yes, I've also heard good things about Citrix Netscaler... but I think they're a tad pricey. I'll have to sell a technician...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now