abillybob Posted February 13, 2015 Posted February 13, 2015 Hey All, So I did some best practice analysis while we're having some problems with connectivity on the internal network. It's come up with a bunch of things all saying "Root hint server must respond to NS queries for the root zone" I have gone to the DNS servers properties and selected the tab "Root Hints" and see one server listed in there which was a Broadband server supplied to us via county, that still supplies the school with Broadband but we now have a Smoothwall box that all the computers point to for their proxy settings. I'll be honest I'm batting in the dark here and don't have a clue what I'm talking about but I'm just trying to think of information that you guys might need to help me!? Or am I worrying about nothing and should just ignore it? Here's a screenshot as well: Thankyou
ChrisH Posted February 13, 2015 Posted February 13, 2015 Root hint servers resolve the DNS names that your local DNS server can't unless you also use a forwarder for DNS resolution as a lot may do (your providers DNS server or maybe a GOogle one etc.) This list usually populates itself or is done via updates.
JRowley Posted February 13, 2015 Posted February 13, 2015 Your Root Hints should ideally list the servers on this page - https://en.wikipedia.org/wiki/Root_name_server They are a sort of "if all else fails" for DNS queries, your Forwarders will be doing all of the work, sending requests to your ISPs DNS servers, but in the event they are down then these root servers attempt to take over.
abillybob Posted February 13, 2015 Author Posted February 13, 2015 (edited) Thankyou for your reply So do you think I need to do anything or will it just sort itself out with updates? Your Root Hints should ideally list the servers on this page - https://en.wikipedia.org/wiki/Root_name_server They are a sort of "if all else fails" for DNS queries, your Forwarders will be doing all of the work, sending requests to your ISPs DNS servers, but in the event they are down then these root servers attempt to take over. Ah right ok, so do I just add all of those servers under IPV4 - Properties - Root Hints? Edited February 13, 2015 by abillybob
JRowley Posted February 13, 2015 Posted February 13, 2015 (edited) Personally I would add them, here is the list: a.root-servers.net 198.41.0.4 b.root-servers.net 192.228.79.201 c.root-servers.net 192.33.4.12 d.root-servers.net 199.7.91.13 e.root-servers.net 192.203.230.10 f.root-servers.net 192.5.5.241 g.root-servers.net 192.112.36.4 h.root-servers.net 128.63.2.53 i.root-servers.net 192.36.148.17 j.root-servers.net 192.58.128.30 k.root-servers.net 193.0.14.129 l.root-servers.net 199.7.83.42 m.root-servers.net 202.12.27.33 Open DNS Manager, right click the server name, go to the Root Hints tab and add them there. Edited February 13, 2015 by JRowley 1
abillybob Posted February 13, 2015 Author Posted February 13, 2015 Personally I would add them, here is the list: a.root-servers.net 198.41.0.4 b.root-servers.net 128.9.0.107 c.root-servers.net 192.33.4.12 d.root-servers.net 128.8.10.90 e.root-servers.net 192.203.230.10 f.root-servers.net 192.5.5.241 g.root-servers.net 192.112.36.4 h.root-servers.net 128.63.2.53 i.root-servers.net 192.36.148.17 j.root-servers.net 192.58.128.30 k.root-servers.net 193.0.14.129 l.root-servers.net 198.32.64.12 m.root-servers.net 202.12.27.33 Thankyou mate, just tried to add them but it says "A timeout occurred during validation"?
matt40k Posted February 13, 2015 Posted February 13, 2015 It's a warning. Not a problem. Its saying if it can't resolve the address from your ISP DNS server, it can't check with the core DNS servers directly - like @JRowley. To be honest, if you can't query your ISP DNS servers (or Google) then you haven't got a internet connection. So do you think I need to do anything Stop messing around!! will it just sort itself out with updates? Its working, if it isn't get some in, should take a day to check the config - much safer then posting all you intermit settings over the internet
JRowley Posted February 13, 2015 Posted February 13, 2015 (edited) Just updated the d root server, is that the message you get for all of them? Edit: As @matt40k said, in all likelihood if you can't use your ISPs DNS servers then these probably wont do much for you anyway. But I'm a bit like you I think, you want those green ticks. Edited February 13, 2015 by JRowley
abillybob Posted February 13, 2015 Author Posted February 13, 2015 Just updated the d root server, is that the message you get for all of them? Edit: As @matt40k said, in all likelihood if you can't use your ISPs DNS servers then these probably wont do much for you anyway. But I'm a bit like you I think, you want those green ticks. It does it for all of them? Yeah I like to look over Server manager and everything looks all clean and done properly with no errors or warnings!!! The story of my life
JRowley Posted February 13, 2015 Posted February 13, 2015 Are you able to perform an nslookup on the root servers?
matt40k Posted February 13, 2015 Posted February 13, 2015 everything looks all clean and done properly with no errors or warnings!!! I think your looking at the wrong screen - the "Microsoft best practices" is based on a clean test lab with no users, the real world has actual users and limited resources. Accept you live in the real world. Find the ignore\hide button haha
Firefox Posted February 13, 2015 Posted February 13, 2015 As said...it can be perfectly acceptable to see those warnings.....infact in our environment we have the very same. But we don't use root hints so we just have to ignore it
abillybob Posted February 13, 2015 Author Posted February 13, 2015 (edited) Are you able to perform an nslookup on the root servers? Yup :/ Returns IP address and the correct name!? As said...it can be perfectly acceptable to see those warnings.....infact in our environment we have the very same. But we don't use root hints so we just have to ignore it I think your looking at the wrong screen - the "Microsoft best practices" is based on a clean test lab with no users, the real world has actual users and limited resources. Accept you live in the real world. Find the ignore\hide button haha It's looking as if I might just have to face defeat soon and rock back and forth in a dark room... I know those warnings are there and it will forever haunt me even if they are meaningless!!!! Edited February 13, 2015 by abillybob
JRowley Posted February 13, 2015 Posted February 13, 2015 Yup :/ Returns IP address and the correct name!? And that's true on the DNS server? Well this is all very interesting. Are you using IPv4, IPv6 or both?
sparkeh Posted February 13, 2015 Posted February 13, 2015 (edited) "Microsoft best practices" Note that the "Microsoft DNS Best Practice Analyzer" advises you use Fowarders and not Root Hints. Its old thinking for an old problem. Edited February 13, 2015 by sparkeh
abillybob Posted February 13, 2015 Author Posted February 13, 2015 And that's true on the DNS server? Well this is all very interesting. Are you using IPv4, IPv6 or both? Both are enabled but I have IPv6 turned off manually via the network cards config, so it won't dish out IPv6 addresses.
JRowley Posted February 13, 2015 Posted February 13, 2015 Both are enabled but I have IPv6 turned off manually via the network cards config, so it won't dish out IPv6 addresses. Some of the root servers support IPv6, so it may be trying even though you don't have it configured on the cards. e.root-servers.net is IPv4 only so you might want to try that one on its own.
abillybob Posted February 13, 2015 Author Posted February 13, 2015 Some of the root servers support IPv6, so it may be trying even though you don't have it configured on the cards. e.root-servers.net is IPv4 only so you might want to try that one on its own. Nope still timed out. Weird!
JRowley Posted February 13, 2015 Posted February 13, 2015 Don't know what to suggest then without you getting into your DNS configuration and firewall rules. It's probably not worth it, just never look at that DPA again.
matt40k Posted February 13, 2015 Posted February 13, 2015 Nope still timed out. Weird! You on LA broadband?
abillybob Posted February 13, 2015 Author Posted February 13, 2015 You on LA broadband? Yup, how come!? Suppose it could be their filters?
matt40k Posted February 13, 2015 Posted February 13, 2015 Yes, they block everything by default and proxy it. IE email has to go via their mail relay, web traffic via there proxy and DNS, you have to use their DNS servers.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now