Win2003r2 Caching DNS Server fails/stops resolving after 4 cname answers for www.cisco.com


hi guys,

we got realy strange dns cache resolving problem.  if cache empty works!

> www.cisco.com.
server:  dc2.xxx.local
address:  10.255.248.10

------------
got answer:
    header:
        opcode = query, id = 24, rcode = noerror
        header flags:  response, want recursion, recursion avail.
        questions = 1,  answers = 6,  authority records = 0,  additional = 0

    questions:
        www.cisco.com, type = a, class = in
    answers:
    ->  www.cisco.com
        canonical name = www.cisco.com.akadns.net
        ttl = 0 (0 secs)
    ->  www.cisco.com.akadns.net
        canonical name = geoprod.cisco.com.akadns.net
        ttl = 0 (0 secs)
    ->  geoprod.cisco.com.akadns.net
        canonical name = www.cisco.com.edgekey.net
        ttl = 0 (0 secs)
    ->  www.cisco.com.edgekey.net
        canonical name = www.cisco.com.edgekey.net.globalredir.akadns.net
        ttl = 0 (0 secs)
    ->  www.cisco.com.edgekey.net.globalredir.akadns.net
        canonical name = e144.cd.akamaiedge.net
        ttl = 0 (0 secs)
    ->  e144.cd.akamaiedge.net
        internet address = 84.53.164.170
        ttl = 19 (19 secs)

------------
non-authoritative answer:
name:    e144.cd.akamaiedge.net
address:  84.53.164.170
aliases:  www.cisco.com
          www.cisco.com.akadns.net
          geoprod.cisco.com.akadns.net
          www.cisco.com.edgekey.net
          www.cisco.com.edgekey.net.globalredir.akadns.net

 

but if query again, fails.

> www.cisco.com.
server:  dc2.xxx.local
address:  10.255.248.10

------------
got answer:
    header:
        opcode = query, id = 22, rcode = noerror
        header flags:  response, want recursion, recursion avail.
        questions = 1,  answers = 4,  authority records = 0,  additional = 0

    questions:
        www.cisco.com, type = a, class = in
    answers:
    ->  www.cisco.com
        canonical name = www.cisco.com.akadns.net
        ttl = 0 (0 secs)
    ->  www.cisco.com.akadns.net
        canonical name = geoprod.cisco.com.akadns.net
        ttl = 0 (0 secs)
    ->  geoprod.cisco.com.akadns.net
        canonical name = www.cisco.com.edgekey.net
        ttl = 0 (0 secs)
    ->  www.cisco.com.edgekey.net
        canonical name = www.cisco.com.edgekey.net.globalredir.akadns.net
        ttl = 0 (0 secs)

------------
non-authoritative answer:
name:    www.cisco.com

 

i spend lot of time troubleshooting cant put finger onto it. have other windows 2003 machine dc1 (through different internet pipe) work time. both running: dns.exe version 5.2.3790.4460

we not sure if network/firewall issue somewhere in our network our windows 2003 isn't resolving query correctly. installed wireshark because suspected @ first network issue, seems afther last query responce dns server stops:

1323    19.574477    64.211.42.196    10.255.248.10    dns    standard query response cname www.cisco.com.edgekey.net.globalredir.akadns.net

the dns server configured use resolving useing root hints (same dc1).

i see lot of eventlog entries eventid: 5504  , contents:

the dns server encountered invalid domain name in packet 150.70.147.168. packet rejected. event data contains dns packet.

anybody can shed light on this? why doesn't work when there entries in cache?

hi customer,
 
i understand eventide 5504 error dns received. please try solve issue by the below steps.

 

 

1.      check if incorrect forwarder address in dc2 dns
2.     
use correct isp dns forwarder instead of root hint,  only isp dns ips set forwarders
3.     
check article, description of dns server secure cache against pollution setting

http://support.microsoft.com/?kbid=316786
 

4.      patch windows server 2003 not support dname

http://support.microsoft.com/kb/920162
 
http://www.microsoft.com/technet/support/ee/transform.aspx?prodname=windows%20operating%20system&prodver=5.2&evtid=5504&evtsrc=dns&lcid=1033

 
http://www.eventid.net/display.asp?eventid=5504&eventno=642&source=dns&phase=1
regards, rick tan


Windows Server  >  Network Infrastructure Servers



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file