Jump to content

Recommended Posts

Posted

So I've been having a weird DNS problem for a few months that I can't quite figure out.

 

What happens is, for short amounts of time, DNS queries to a very small number of domain names time out when querying my local DNS servers (2012R2). During this time, other queries will be provided with an accurate and timely response - it's just the one or two that I've been told about that cause Chrome to produce an error stating the DNS lookup failed.

 

The only thing I've been able to do to resolve it is restart the DNS services. If I don't do this, occasionally queries to affected sites start working again after a few minutes, but often this does not happen.

 

It isn't the internet connection or router, as the affected domains work properly directly by IP or via our public wifi which uses a different (non-Windows) DNS server, and I've been unable to find any errors being recorded anywhere that would explain this.

 

For a time, I thought this was being caused by having turned on 'Enable DNSSEC validation for remote responses' on my DNS servers a few weeks before the first complaint, but having disabled this again not long after, it is still going on.

 

Does anyone have a clue what this might be or what I could look at for more clues?

Posted (edited)
dumb thing to check would be the DNS settings of the DNS servers them selves. I think best practice is 1 to self and 1 to your secondary DNS server. Oh and check your forwarders if you have more than one check them all. I assume the DNS queries your not getting replies to are external ones. Edited by chazzy2501
Posted

Thanks. Yeah, it's external queries that have been failing. The most prominent is to Adobe services - Adobe Fonts (ex Typekit) stops working and that's typically when I get reports of problems.

 

DNS is all set up as it should be. Each of my two DNS servers have their IP4 settings point to themselves and then the other.

 

What exactly do you mean by 'check your forwarders'? It's a bit vague to me! You mean set my machine to use each of those in turn (rather than my internal ones) and check I can resolve the domains I'm looking for? I'm not sure that will prove much - I use the same forwarders for my corporate network as I do my public wifi, and the last time I checked that, it was still working when my corporate was not. :(

 

 

I've not had to touch DNS since I upgraded my network from Server 2003 to 2012R2 about 5 years ago. I really hate such difficult problems, where something is definitely wrong, but there are no indicators as to why!

Posted

Not very technical answer this, but when I had a very odd issue with no errors in the logs, I turned off one of the DNS servers as soon as an issue was reported, I then noticed that turning off one of them fixed the issue. I then re installed DNS on that server and had no issues.

 

I know there are probably better ways of working it out, but that worked for me :0)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...