Cisco 877W acting a a DNS server. Does it answer external DNS queries coming from the WAN
Hello,
I have a Cisco 877W running on my ADSL2+ service at home.
It is setup to act as a DNS server to answer DNS queries for my LAN and has the below commands as part of its configuration
ip dns server
ip dhcp pool LAN
network 192.168.2.0 255.255.255.0
default-router 192.168.2.254
dns-server 8.8.8.8
My question is, when I scan my WAN IP for open ports, port 53 (DNS) is open. Does this mean my router will be acting as a DNS server for anyone on the internet who directs DNS queries to my WAN IP?
If so, am I able to turn off port 53 towards the Internet, or do I need to add an an access-list to only accept queries from my internal network.
Thanks for your feedback.
That's correct. The "ip dns server" command will answer queries on any interface.
Given that your DHCP server is telling your clients to use Google DNS and not your router, I would just turn the router's DNS server off with the "no ip dns server" command.
Setting up an ACL (and/or inspection or zone-based firewalling) on your Internet-facing interface is the best practice to protect your network in general, not just to prevent external DNS queries.
Similar Messages
-
DNS Server does not resolve new generic Top Level Domain names- CNR configuration issue?
Hi all,
I am not sure if this is the correct community to post this question, but I will give it a try. I noticed that the users of my network cannot resolve web sites using new top level domain names, like ".education", ".international", etc. I have an internal DNS server made by Infoblox and a Cisco CNR v6.3.3.1 as an external DNS server. Infoblox uses CNR as its forwarder and CNR uses the root DNS servers for queries.
I would think that CNR was the problem because it is an obsolete product but after speaking with a fellow engineer at another organization where they still use an older version of CNR than mine, they have no problems at all. So now I am thinking it is a setting either on Infoblox, or on CNR I need to change. I can see Infoblox is forwarding the requests to CNR but that's about it. I am not sure if CNR is discarding the request. When I do an nslookup from a PC in my network it does not matter if I set my DNS server to be the Infoblox or the CNR. Neither resolves the URL.
Then again, no matter what I lookup using the CNR as my DNS, I only get a response with the root DNS names and IPs!
Any help is appreciated!Hi Constantinos,
Have you taken a look at the infoblox community site? We've just reposted your question there and alerted some internal SMEs that should provide a solution soon.
https://community.infoblox.com/forum/ddi/dns-server-does-not-resolve-new-generic-top-level-domain-names-cnr-configuration-issue
Best,
Eric -
Hello,
Today i tried accessing transitbux.com with mozilla, but i'm getting this kind of a error as mentioned below:
Unknown Host
Description: Unable to locate the server requested --- the server does not have a DNS entry. Perhaps there is a misspelling in the server name, or the server no longer exists. Double-check the name and try again.
Can anyone help me please, and the same website is accessible with my phone.
Help me please. :(
Regards
-Try http://www.transitbux.com/
Clear the cache and remove cookies only from websites that cause problems.
"Clear the Cache":
*Firefox/Tools > Options > Advanced > Network > Cached Web Content: "Clear Now"
"Remove Cookies" from sites causing problems:
*Firefox/Tools > Options > Privacy > "Use custom settings for history" > Cookies: "Show Cookies" -
Hi Guys,
I have just purchased Mac OS X Lion Server. When I launch the Server App I am told I need to download additional software but once the App attempts to do so I get this message "Can't install Server Essentials because it is not currently available from the Software Update server".
I looked around on the internet and I found a few vague comments stating I may need to insert commands into the Terminal. Can anybody help me please?Had the same message myelf but it is there. Somebody posted a link to it, will see if I can find it......
Thought so, Karlegas found it. -
Firefox does not appear on screen when started from the start menu or the shortcuts, but task manager says the process is running.
No - I get the message basically saying "Can't run program while Firefox is running. Please close down Firefox & try again".
I rebooted my computer and it all works now - but that's weird it was happening before. Kinda weirded out that it happened at all.
To avoid that happening again, I still wanna know what to do to avoid it or fix it for next time. Thanks -
When does Photoshop cc supports the raw files wich are coming from the Nikon D5500 ?
Hello,
When does Photoshop cc supports the raw files wich are coming from the Nikon D5500 ?
Iam a very happy user of Photoshop, specially for my raw files... i find it frustrated that i can't work on my files for now..
Greatings DannyThe D5500 was just released and Adobe is working on support. Cannot say how long for sure, but it should be within a month or two. Meanwhile, you could shoot in NEF+JPEG and set Camera Raw to open your JPEGs as well. Not as much data, but will be better than nothing..
Benjamin -
Using osx mavericks on macbook pro. My printer for HP-photosmart 6280 all-in-one now does not show options for printing photos from the photo tray.
What router? Have you restarted the router?
Say thanks by clicking "Kudos" "thumbs up" in the post that helped you.
I am employed by HP -
My settings "general". Does not show a"update software " choice from the menu?
My settings "general". Does not show a"update software " choice from the menu? I cannot find what iOS software I'm currently using or what iPad I have
The option to update without the computer (Over the air) was made available with iOS 5. If your iDevice is using a version of iOS lower than 5, you will need to use iTunes on your syncing computer to perform the upgrade. Use the Apple link below as a guide for the upgrade.
http://support.apple.com/kb/HT4972
Also read the instructions from the section entitled "Update your device using iTunes" at the link below.
http://support.apple.com/kb/HT4623
Information regarding transferring purchases from your iDevice to iTunes on your syncing computer can be found at the link below.
http://support.apple.com/kb/ht1848 -
External DNS server not replicating records to secondary after migration from 2003 to 2012
Hi
I have a query relating to 2012 Server and DNS.
Last week we de-commissioned our primary external DNS server (Windows 2003 Server) and moved the role over to a new Windows 2012 server.
Since this point replication to our secondary server (3rd party hosted) does not seem to occur and our DNS records seem to have expired on the secondary server as we cannot look these up via nslookup.
I cannot see any failures in the event log of the server; I have checked our external firewall logs and nothing is being blocked inbound/ outbound as far as I can see. And the server’s local firewall has been disabled.
The server is a standalone server in a workgroup with a standard filebased primary zone, with no AD integration and recursion disabled.
When I created the zone I copied the .dns file from the old server and selected this in the interface during the creation of the zone on the new server. The new server has the same internal and external IP as the old server and the old server is off-line.
I have also manually increased the serial number of the zone and still no joy.
One thing that I have noticed is when I open the zones properties/Name Servers and click edit on the external nameserver I get the infamous "The server with this IP address is not authoritative for the required zone" error.
Any help Would be appreciated, thanks in advanceNice to hear that you are close in finding the problem. So in short:
You have enabled Zone transfers in DNS management console for the applicable zone
You have verified that your DNS is listening to the correct interfaces
You have enabled firewall rules to accept TCP and UDP traffic to port 53
You have checked if "BIND secondaries" option is applicable to your case
You have initiated a zone transfer from the secondary server
Lefteris Karafilis
MCSE, MCTS, SEC+
LinkedIn: http://www.linkedin.com/in/lkarafilis
Mail: [email protected]
Blog: http://www.karafilis.net -
2K8 - Best practice for setting the DNS server list on a DC/DNS server for an interface
We have been referencing the article
"DNS: DNS servers on <adapter name> should include their own IP addresses on their interface lists of DNS servers"
http://technet.microsoft.com/en-us/library/dd378900%28WS.10%29.aspx but there are some parts that are a bit confusing. In particular is this statement
"The inclusion of its own IP address in the list of DNS servers improves performance and increases availability of DNS servers. However, if the DNS server is also a domain
controller and it points only to itself for name resolution, it can become an island and fail to replicate with other domain controllers. For this reason, use caution when configuring the loopback address on an adapter if the server is also a domain controller.
The loopback address should be configured only as a secondary or tertiary DNS server on a domain controller.”
The paragraph switches from using the term "its own IP address" to "loopback" address. This is confusing becasuse technically they are not the same. Loppback addresses are 127.0.0.1 through 127.255.255.255. The resolution section then
goes on and adds the "loopback address" 127.0.0.1 to the list of DNS servers for each interface.
In the past we always setup DCs to use their own IP address as the primary DNS server, not 127.0.0.1. Based on my experience and reading the article I am under the impression we could use the following setup.
Primary DNS: Locally assigned IP of the DC (i.e. 192.168.1.5)
Secondary DNS: The assigned IP of another DC (i.e. 192.168.1.6)
Tertiary DNS: 127.0.0.1
I guess the secondary and tertiary addresses could be swapped based on the article. Is there a document that provides clearer guidance on how to setup the DNS server list properly on Windows 2008 R2 DC/DNS servers? I have seen some other discussions
that talk about the pros and cons of using another DC/DNS as the Primary. MS should have clear guidance on this somewhere.Actually, my suggestion, which seems to be the mostly agreed method, is:
Primary DNS: Locally assigned IP of the DC (i.e. 192.168.1.5)
Secondary DNS: The assigned IP of another DC (i.e. 192.168.1.6)
Tertiary DNS: empty
The tertiary more than likely won't be hit, (besides it being superfluous and the list will reset back to the first one) due to the client side resolver algorithm time out process, as I mentioned earlier. Here's a full explanation on how
it works and why:
This article discusses:
WINS NetBIOS, Browser Service, Disabling NetBIOS, & Direct Hosted SMB (DirectSMB).
The DNS Client Side Resolver algorithm.
If one DC or DNS goes down, does a client logon to another DC?
DNS Forwarders Algorithm and multiple DNS addresses (if you've configured more than one forwarders)
Client side resolution process chart
http://msmvps.com/blogs/acefekay/archive/2009/11/29/dns-wins-netbios-amp-the-client-side-resolver-browser-service-disabling-netbios-direct-hosted-smb-directsmb-if-one-dc-is-down-does-a-client-
logon-to-another-dc-and-dns-forwarders-algorithm.aspx
DNS
Client side resolver service
http://technet.microsoft.com/en-us/library/cc779517.aspx
The DNS Client Service Does Not Revert to Using the First Server in the List in Windows XP
http://support.microsoft.com/kb/320760
Ace Fekay
MVP, MCT, MCITP EA, MCTS Windows 2008 & Exchange 2007 & Exchange 2010, Exchange 2010 Enterprise Administrator, MCSE & MCSA 2003/2000, MCSA Messaging 2003
Microsoft Certified Trainer
Microsoft MVP - Directory Services
Complete List of Technical Blogs: http://www.delawarecountycomputerconsulting.com/technicalblogs.php
This posting is provided AS-IS with no warranties or guarantees and confers no rights.
I agree with this proposed solution as well:
Primary DNS: Locally assigned IP of the DC (i.e. 192.168.1.5)
Secondary DNS: The assigned IP of another DC (i.e. 192.168.1.6)
Tertiary DNS: empty
One thing to note, in this configuration the Best Practice Analyzer will throw the error:
The network adapter Local Area Connection 2 does not list the loopback IP address as a DNS server, or it is configured as the first entry.
Even if you add the loopback address as a Tertiary DNS address the error will still appear. The only way I've seen this error eliminated is to add the loopback address as the second entry in DNS, so:
Primary DNS: The assigned IP of another DC (i.e. 192.168.1.6)
Secondary DNS: 127.0.0.1
Tertiary DNS: empty
I'm not comfortable not having the local DC/DNS address listed so I'm going with the solution Ace offers.
Opinion? -
Seeded LOV in OA Page works on internal server, does not in external server
I am using the appraisal creation page '/oracle/apps/per/selfservice/appraisals/webui/MASetupDetailsPG'. Here we have a LOV that lists the appraisal template.
The LOV returns records when Pressing 'Go' from the LOV Search page while accessing from internal server.
However, while performing the same steps from external server, on clicking 'Go' , we get 'No Search Conducted'. ideally , we'll expect the records to come up (or) no results match the chosen criteria. However in this case, it simply gives 'No Search Conducted'.
The 'About this Page' on LOV Page does not show the VO/AM details from external server.
I have checked the following:
1. Class path is same while accessing from both external and internal server
2. Page personalisations are fairly starightforward, just prompts,instruction text changes etc
3. There is no VO/AM customisation. This was done by checking jdr_utils from apps. i suppose this is just application-wide and cannot be checked at server level. pls validate my statement.
4. I have tried 'Diagnostics' using 'About this Page'. It works internally and gives the LOV query with bind parameters. However when I try to do 'Diagnostics'-->Show log on Screen, the screen just hangs before i can see the 'log Level' list on the screen. So I am unable to take trace even from external server.
5. Few other LOVs work from external server. But this one does not.
What could be the cause and how do i debug further?
Any help is appreciated.
Thanks,
LNAs far as I know, if he does what you suggest he won't be able to resolve the "main" domainname.
The internal DNS will think it is the SOA for the "whole" domainname, including subdomain or not, and woun't ask any other DNS. So he needs to add all public IPs/names in his DNS if using the same domainname.
Delegation of a subdomain, this requires both DNS using public IPs:
http://www.zytrax.com/books/dns/ch9/delegate.html
I guess this is "wishful thinking":
IF he (most likely woun't happen) could/be allowed to do zone transfers from a DNS hosting the "main" domainname and run that zone as a slave/secondary on his internal DNS it should work. It wouldn't be ugly if it can be done without adding his internal DNS IP as a NS record. I don't know about notifying the slave about changes to the main domain then though.
If running your own public DNS to separate between public and internal only/private IP lookups depending on what IP the request is coming from:
http://www.zytrax.com/books/dns/ch7/acl.html -
Exchange Server 2013 internal and external DNS records
I recently installed Exchange Server 2013 and I've register a pubic ip too for exchange server. How can I create internal DNS as well MX record for my Exchange server to send and receive internet mails. It's my first time configuring exchange for a organization.
registered domain name=====np.bbcmediaaction.org
public ip=====202.166.212.221Hi,
For external mail flow, we need the following DNS records: MX records for the domain part of the external recipient, A records for the destination messaging servers. For more information, you can refer to the following article:
http://technet.microsoft.com/en-us/library/bb676467(v=exchg.150).aspx
Additionally, to ensure external mail flow works well, we also need to configure send connector.
For more information, you can refer to the following article:
http://technet.microsoft.com/en-us/library/jj218640(v=exchg.150).aspx
If you have any question, please feel free to let me know.
Thanks,
Angela Shi
TechNet Community Support -
I need to run an active directory that is on a WAN (Utah). a server 2012 standard will be the DC with 60Mbps internet speed both up and downstream.
approximately 100 clients/member systems will be all over the united states. NO VPN. only via internet. I can use SSL certificate for secure ldap.
I need this setup to use GPO for different permissions and policies instead of manually doing those on each windows 7 or 8 professional system.
Ideas??Daniel,
I think since this will be the ONLY system that will be running as a DC providing ADDS and the Direct access server, i should follow this advice from the article you sent:
For users who never connect directly to the Contoso intranet or through a VPN, they must use the DirectAccess
Offline Domain Join process to initially join the appropriate domain and configure DirectAccess. When this process
is complete, the users log on normally and have the same experience as if they were directly connected to the Contoso intranet.
Because remember, no user will ever connect directly to the subnet where the server is. so do an offline join First and then start managing.. Only thing im worried about is: they keep saying that the direct access function has significantly improved in windows
8. hmmmmm many systems will be using windows 7 Pro 64Bit. Some windows 8.1 Pro 64bit. should i worry? -
Why does my iPad 2 only store emails from the last 3 or 4 days?
Why does my iPad2 only store emails from the last 3 or 4 days? I have it set up to store the last 1000 messages but I can't seem to keep them...
What is the account type - POP, IMAP, or Exchange?
If a POP account, are you also accessing the account with an email client on your computer? If so, what is the account setting for removing messages from the server after being downloaded with the email client used on your computer for accessing the account? -
My Mail program has gone south on Leopard on my 27-month old Macbook. I can't send, even though the server details are correct. I tried reinstalling the Mail program from the install DVD, but no go; apparently that two-year old Mail is no longer compatible with my up-to-date Leopard. I tried deleting the account (hotmail) from Mail and setting up a different account (Yahoo). After loading all the inbox two things happened: first, I still couldn't send, and second, when I closed the Mail window the whole inbox then disappeared and doesn't come back. Although I couldn't reinstall the Mail program from the install DVD, would it still be possible to reinstall the whole system from that DVD? If I do, will I lose files or will there be another problem since that DVD is now over two years old?
Thanks for any suggestions; they will be much appreciated.
P.S. I've just noticed that now I can't change the desktop picture: I go through the motions in Preferences, but the new picture doesn't appear on the desktop. Is there a systemic problem?You are waiting for an apology to something that happened over a year ago? Really? This is why there is a manager in the store. You have a problem with an employee you speak to the manager. Just like you did on the phone. You would have gotten your apology in July 2013.
Here is the information about your upgrade fee.
Upgrade Fee
It is because when you have a problem you (customers) go running to the store and want to take up the time of the reps to fix it. Other carriers have third parties that deal with technical support and those locations are few and far between. VZW provides this directly through their stores. Also, when you subsidize a $650 and pay $200 VZW has to pay $400. Your monthly service fee doesn't begin to scratch the surface of paying that back. Not with all the money that is put into the network and its improvements.
Then over a year later you get someone on the phone who apologized and offered to waive the fee on your phone and you didn't take it? That offer won't come down the pike again.
One thing you should know is that all these employees are people and as such they sometimes come off cross. I doubt that you speak to everyone so sweetly all the time. Cut them a little slack and put this whole thing behind you after 15 months. Either upgrade with VZW or move on.
Maybe you are looking for
-
The front camera on my iPod touch 4th generation is frozen. I cannot use it. Updating software does not help. This started right after I bought it, new from BestBuy. What can I do? When i go to the camera, it is stuck on a black screen. the only way
-
SSD Cache Not Working U840 after Clean Install Intel Smart Response Technology
Hello, I completed a clean install of Windows 8 on my ultrabook model U840 (Core i3, 16GB SSD). I would appreciate any advice to get the SSD to use the Intel Smart Response Technology (SRT) for SSD Cache. I used the Intel Rapid Storage Technology (R
-
My apple TV has stopped working completely. Just a flashing Amber light
My Apple TV has stopped working. When it is turned on I just get a flashing amber light and it does not turn blue as normal. It doesn't connect wirelessly to my Mac and it doesn't connect to the TV. I do not get the setup menu and it is totally un
-
Only Part of Music Library Home Shared
Is there any obvious explanation for why only 51 of my 293 albums show up on iPad 2 using Home Sharing?
-
Hi All, can any one send me some sample reports in service management ,and also tables used in Service Management.Its very urgent.... Thanks in advance. Amith