G
Guest
I have root domain, and in root domain DMZ there is FE Exchange server and
public DNS. There are several separated domains connected to root domain. All
domains are connected with netsceen.
The problem is getting worse because UDP traffic. More or les DNS traffic
related. The situation is getting worse. DNS fail to resolve FQDN to IP. And
this is getting problematic because of FE exchange server. All incoming and
outgoing SMTP traffic is going through FE exchange server, and because name
resolution is failing, there are a lot of failed mails that are not delivered.
If I tried to use nslookup in any server in root domain I get strange
responses.
I type one domain name.
1. no response
2. no response
3. no response
4. response
I use ISP DNS server
1. no response
2. no response
3. no response
4. response
5. response
6. response
7. no response
8. no response
9. response
And so on
I have to domain controllers and FE Exchange server in DMZ. Both DC use AD
integrated and FE use several standard zones, because we host several domains
there.
Root DC have the following configuration:
Network configuration: under TCP/IP they use first DNS there own IP and
second DNS IP of second DC in root domain. DNS server host AD integrated
zones. One zone is for root domain and _mscds zone, which is replicated to
other DNS server in other domains. Both DNS server use the same ip set of
addresses of ISP provider. And recursion is check and i increase time out
for now to 10s.
FE exchange server use in IP configuration on TCP/IP properties IP addresses
of both DC in root domain. On forwarder tab i tried different configuration
on IP addresses , at the moment there are ISP DNS first than local DC IP
addresses will remove DC IP address witch I don’t thing these are need it.
Recursion is used and is set up now to ten second…
Today I set up so that FE server uses external DNS servers for mail delivery
on SMTP connector. I will se how does it respond. The error that is pop in up
is that the SMTP could not connect to DNS server, these DNS server can be
internal DNS server of DC or external. There is the same netscreen there.
All others domain have the following configuration. There are usually two
domain controllers with AD integrated zone. And _msdcs yon, tah is replicated
through root domain. And Forwarders are local ISP provider. IP configuration
has the first ip address of the he first DC than the second DC and third and
the fort is IP address of root DC. Recursion is enabled and default.
How can I fix and lower DNS query traffic through domain. And most
important, how to fix problem in root domain. All servers and DMZ are going
through on Netscreen box. Root domain is problematic because FE Exchange
server.
Thank you for replay.
public DNS. There are several separated domains connected to root domain. All
domains are connected with netsceen.
The problem is getting worse because UDP traffic. More or les DNS traffic
related. The situation is getting worse. DNS fail to resolve FQDN to IP. And
this is getting problematic because of FE exchange server. All incoming and
outgoing SMTP traffic is going through FE exchange server, and because name
resolution is failing, there are a lot of failed mails that are not delivered.
If I tried to use nslookup in any server in root domain I get strange
responses.
I type one domain name.
1. no response
2. no response
3. no response
4. response
I use ISP DNS server
1. no response
2. no response
3. no response
4. response
5. response
6. response
7. no response
8. no response
9. response
And so on
I have to domain controllers and FE Exchange server in DMZ. Both DC use AD
integrated and FE use several standard zones, because we host several domains
there.
Root DC have the following configuration:
Network configuration: under TCP/IP they use first DNS there own IP and
second DNS IP of second DC in root domain. DNS server host AD integrated
zones. One zone is for root domain and _mscds zone, which is replicated to
other DNS server in other domains. Both DNS server use the same ip set of
addresses of ISP provider. And recursion is check and i increase time out
for now to 10s.
FE exchange server use in IP configuration on TCP/IP properties IP addresses
of both DC in root domain. On forwarder tab i tried different configuration
on IP addresses , at the moment there are ISP DNS first than local DC IP
addresses will remove DC IP address witch I don’t thing these are need it.
Recursion is used and is set up now to ten second…
Today I set up so that FE server uses external DNS servers for mail delivery
on SMTP connector. I will se how does it respond. The error that is pop in up
is that the SMTP could not connect to DNS server, these DNS server can be
internal DNS server of DC or external. There is the same netscreen there.
All others domain have the following configuration. There are usually two
domain controllers with AD integrated zone. And _msdcs yon, tah is replicated
through root domain. And Forwarders are local ISP provider. IP configuration
has the first ip address of the he first DC than the second DC and third and
the fort is IP address of root DC. Recursion is enabled and default.
How can I fix and lower DNS query traffic through domain. And most
important, how to fix problem in root domain. All servers and DMZ are going
through on Netscreen box. Root domain is problematic because FE Exchange
server.
Thank you for replay.