DNS server do not forward requests


domain dns server not forwards requests, serves requests domain names served dns server.

#nslookup google.com 127.0.0.1                                   --         not resolve dns name

#nslookup google.com <external dns server ip>           --         resolves

event log not gives errors. forwarder set in dns server. dns server generates following warning:

log name:      dns server source:        microsoft-windows-dns-server-service date:          3/21/2012 1:30:44 event id:      5501 task category: none level:         information keywords:      classic user:          n/a computer:      dc01.test.home description: dns server encountered bad packet 192.168.0.1.  packet processing leads beyond packet length. event data contains dns packet. event xml: <event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">   <system>     <provider name="microsoft-windows-dns-server-service" guid="{71a551f5-c893-4849-886b-b5ec8502641e}" eventsourcename="dns" />     <eventid qualifiers="16384">5501</eventid>     <version>0</version>     <level>4</level>     <task>0</task>     <opcode>0</opcode>     <keywords>0x80000000000000</keywords>     <timecreated systemtime="2012-03-20t19:30:44.000000000z" />     <eventrecordid>156</eventrecordid>     <correlation />     <execution processid="0" threadid="0" />     <channel>dns server</channel>     <computer>dc01.test.home</computer>     <security />   </system>   <eventdata name="dns_event_bad_packet_length">     <data name="param1">192.168.0.1</data>     <binary>057d851001000100000001000363726c096d6963726f736f667403636f6d00000100010000290fa0000080000000c00c000100010001518000045c7b9b29</binary>   </eventdata> </event>

i don't have idea on how resolve problem, kindly asking help.

the operation system windows server 2008r2

under forward lookup zones, root zone exist? root zone period (".").

or under dns properties, advanced tab, recursion disabled?

.

based on kb198757, corrected in nt4? "event 5501 indicates after sending recursive query on behalf of client, dns received response fragmented flat set indicating answer did not fit in 1 packet , there more data follow."

.

does perimeter firewall support edns0?

here's quick command test if there's edns0 restriction in firewall:
nslookup -type=txt rs.dns-oarc.net

look part in response says, " ...dns reply size limit @ least xxxx." xxxx support. if it's under 512, blocking edns0 or forwarder using blocking or not allowing/configured use edns0.

what edns0? (extension mechanisms dns)
http://msmvps.com/blogs/acefekay/archive/2010/10/11/edns0-extension-mechanisms-for-dns.aspx 

.

is there av installed? avs known block necessary traffic.

.


ace fekay
mvp, mct, mcitp enterprise administrator, mcts windows 2008 & exchange 2007 & exchange 2010, exchange 2010 enterprise administrator, mcse & mcsa 2003/2000, mcsa messaging 2003
microsoft certified trainer
microsoft mvp - directory services
complete list of technical blogs: http://www.delawarecountycomputerconsulting.com/technicalblogs.php

this posting provided as-is no warranties or guarantees , confers no rights.

facebook twitter linkedin



Windows Server  >  Network Infrastructure Servers



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2