Internal DNS resolution issue - almost all external sites working

I administer an Xserve running 10.5.8 Server. This client is running internal DNS due to a few internal services (iChat, mail, VPN, etc) - but his website, of the same domain, is hosted externally at a hosting provider. This is where I'm running into odd problems. For examples:
ichat.company.com - 10.0.1.100 (when inside the network, also has FQDN on Internet)
mail.company.com - 10.0.1.100 (same as above)
www.company.com - xxx.xxx.xxx.xxx (the actual public IP address of the web server at the host)
Do I need to do it this way? If I don't define the "www" record internally, and point it to the external IP of the hosting provider for the website, the clients inside the network can't see the website, because the internal domain services aren't answering the "www" question and won't hand off to the internet records. It's frustrating because every time the client has a subdomain added to his website, i have to add a record on his internal DNS or it won't resolve at his office. example:
newdomain.company.com - xxx.xxx.xxx.xxx (public IP of the web host, or it fails)
Is there a way to have internal DNS for a domain answer most but not all questions for the domain?
- Bill

Just as an aside, you could potentially setup a subdomain for the internal systems, e.g. 'corp.company.com' and setup the internal services in this domain - ichat.corp.company.com, mail.corp.company.com, etc.
Then to get to the internal systems users use those .corp.company.com hostnames and the rest of .company.com gets sent upstream.
It may or may not be sufficient for your needs. This kind of model works well for static users that only work in the office but may not work so well for mobile users.

Similar Messages

  • AD DNS resolution Issue for specific Site

    Hello Experts,
    Currently I am facing issue for DNS Resolution.
    I have 2 Sites
    Site A(2003 R2 DC) & Site B(2008 R2 ADC)
    my domain name is abc.co.in
    and I have another forwardlookup zone abcl.com (mail.abcl.com/Dev.abcl.com)
    I am able to resolve host recoreds for abc.co.in & abcl.com from site A
    I am facing issue for Site B
    unable to resolve A records for mail.abcl.com
    when I am trying to resolve using
    ============================================================
    nslookup mail.abcl.com 192.168.0.5 (Site B ADC)
    getting below output
    Server : adc01siteB.abc.co.in
    Address : 192.168.0.5
    Non autoritative answer :
    Name : com.co.in
    address : 192.254.185.209
    Aliases : mail.abcl.com.co.in
    ==============================================================
    mail.abcl.com - 192.168.0.11 (Actual Internal A record)
    I want to know why this trying to resolve from external DNS (192.254.185.209)
    your help / pointers will be appreciable
    R Udeg

    Is your settings for site B the same for site A in the DNS Server properties?
    Did you make sure that UDP and TCP port 53 is open both ways?
    Did you make sure all resource records have been updated?
    Did you flush the cache/ scavenging happened?
    Did you check the DNS forwaders and recursion?
    Remember if a DNS server fails to resolve a name for which it is not authoritative, the cause is usually a failed recursive query. Recursive queries are used frequently by DNS servers to resolve remote names that are delegated to other DNS zones and servers.
    Note: If you disable recursion on the DNS server, you will not be able to use forwarders on the same server.

  • Problem: Slow Intranet Sites/Internal DNS Resolution for only AD Users

    Hello,
    We are experiencing a very odd problem.
    Any and All Active Directory users are experiencing very slow intranet sites.
    We are a school corporation, so this is affecting our Student Information System, as it is entirely web-based and locally hosted.
    All of our Domain Controllers are Windows Server 2012 R2, with all the latest critical updates.
    All client workstations are Windows 8.1 Professional.
    The problem occurs with ALL web browsers (IE, Chrome, FF, etc)
    All DNS queries respond in <1 ms (no matter whether we are logged in as AD User or local computer user).
    If we login as local computer user, we have blazing fast intranet sites/DNS resolution.
    If we login as AD user, everything crawls again... every click on the intranet site spins and says loading for up to 15 seconds.
    If we add the the intranet site to the local computer HOST file, it is blazing fast, just as if we logged on as local computer user.
    If we take it back out of the HOST file, it drags again.
    I am totally stumped!
    Any help is appreciated.
    Thanks!

    Hi,
    How are DNS settings configured?
    If there are any public DNS IP addresses in Preferred or Alternate field, please remove them, then input these DNS entries in the Advanced section. We should only configure Domain Controllers’ IP addresses on Preferred
    and Alternate DNS server section for domain-joined machines.
    More information for you:
    Active Directory’s Reliance on DNS, and using an ISP’s DNS address
    http://blogs.msmvps.com/acefekay/2009/08/17/ad-and-its-reliance-on-dns/
    Best Regards,
    Amy

  • DNS Resolution Issues

    Hey Guys,
    I have recently set up a Mac OS X server at home and have set it up to work with the domain name server.geckocentral.co.uk for which I have created an A record and it works perfectly.. this is the Mac OS X standard tutorial method presented by the great Todd Otholff for accessing your network on an outside line and I followed it perfectly.
    The problem I now have is that I cannot access http://geckocentral.co.uk anywhere in the world although I could on and off earlier on but even off my WiFi my mobile devices can no longer access it so I guess the internal and external DNS are both broken ?
    When you add the domain to the servers DNS it has to hold the zone geckocentral.co.uk and then server.geckocentral.co.uk is the machine name within the domain.
    Is there perhaps a record I can add somewhere to tell the DNS that anything not assigned to server.geckocentral.co.uk needs to look somewhere else since my website is hosted externally with innohosting along with my webmail etc and now its busted.
    This is for my business I run and I am hoping there is a way to fix it.
    Regards,
    Matt

    You'll want to launch the following diagnostic command and confirm your local DNS is working:
    sudo changeip -checkhostname
    If you're referring to any DNS services off of your network and if you're using NAT as is typical, then the above command will probably report a DNS error.
    Here are details on setting up LAN-local DNS on OS X Server.
    I would generally recommend against using the same domain name both inside your firewall on your NAT'd network and outside via your DNS provider's servers — it's possible to do that, but you'll then have to track public IP addresses around within your internal DNS.   If I've guessed at the trigger for the issue you've encountered, it's involving two separate authoritative DNS servers, or there's no internal DNS running here. 
    Either use a subdomain of a domain you've registered or have permission to use, or use a seperate registered domain inside your network, or (getting more difficult as ICANN is adding new top-level domains) use a bogis domain such as .mattd25 as your top-level domain.  If you choose to use a bogus domain, do not use .local, .com, .net or any other existing top-level domain.

  • Safari can't find insert server Server DNS resolution issues

    I'm getting this error a lot.
    Most of mine are to .gov sites that change their DNS resolution fairly frequently
    Here is a list of the types of sites that often come back with server not found errors.
    http://forecast.weather.gov/MapClick.php?CityName=Paonia&state=CO&site=GJT&textF ield1=38.8695&textField2=-107.59
    http://forecast.weather.gov/MapClick.php?lat=38.89317057287496&lon=-107.59323120 117188&site=gjt&smap=1&unit=0&lg=en&FcstType=text
    http://www.crh.noaa.gov/gjt/
    http://squall.sfsu.edu/gif/jetsat_00.gif
    http://science.nasa.gov/science-news/science-at-nasa/2010/11jan_antimatter/
    http://farmingforum.co.uk/forums/index.php
    Further research has shown that the problem is that Safari has changed how it looks up DNS services between revision 5.0.3 and the one in Leopard as the problem never happened in Leopard.
    Clearing the cache does not help, clearing and resetting cookies does not help. Constant reloading of the page will eventually fix it, whenever Safari finally goes to the proper DNS.
    There is clearly a change in how Safari is looking things up on the DNS but no clue hot to change the behavior to get it back to the Leopard version that worked.

    If you use a router, does it have the latest firmware installed? Safari 5 introduced 'DNS Prefetching' (Safari looks up the addresses of links on webpages and can load those pages faster) which could strain some routers or modems producing a 'latency' in page loading. This was fixed in Safari 5.0.2, but you may see a benefit from getting a faster router or modem. You can read more about that here:
    http://support.apple.com/kb/TS3408?viewlocale=en_US

  • Internal DNS Resolution

    What InkMaster said - you HAVE to use internal DNS to resolve internal systems, no external DNS server will ever work. Either don't use the external ones, or use them on your DNS server as forwarders.
    Many DNS tools will tell you what server is quickest at resolving external names, and has no relevance to internal systems.

    I currently have a dilemma with our internal DNS servers. I ran namebench and the recommended configuration is as follows:
    Primary Server: 4.2.2.2
    Secondary Server: 209.244.0.3
    Tertiary Server: 192.168.30.54
    I changed the DNS settings on my workstation but now I am unable to resolve internal addresses. Our DHCP server is handing out 192.168.30.53 and 54 as DNS servers. If I change the DNS settings on the DHCP server to the above recommended, internal users will not be able to resolve internal addresses. Is there a work around for this? I noticed a huge difference in browsing speed when using the recommended settings from namebench. Any help would be greatly appreciated. Thanks!
    This topic first appeared in the Spiceworks Community

  • Please help, I've tried everything! Gmail won't open, it just endlessly cycles and rarely even gives me an error message: all other sites work fine (Windows 8).

    All sites work fine except Gmail will not load. I prefer Firefox, but to be fair, Chrome and IE are doing the same thing when I try to use them. Occasionally Gmail will pop up, most of the time it just endlessly cycles and I don't even get an error message. I'm going to have to get rid of gmail if this goes on.
    It's maddening! I've tried everything I could find on mozilla support--restarted in safe mode, clear cache, cookies, etc. This is a brand new Windows 8 laptop. It started a few weeks after I got it. There is nothing else wrong with it, it had a fresh new OS installed before I got it. Please help! Thanks so much.

    '''Try Firefox Safe Mode''' to see if the problem goes away. Safe Mode is a troubleshooting mode, which disables most add-ons.
    ''(If you're not using it, switch to the Default theme.)''
    * You can open Firefox 4.0+ in Safe Mode by holding the '''Shift''' key when you open the Firefox desktop or Start menu shortcut.
    * Or open the Help menu and click on the '''Restart with Add-ons Disabled...''' menu item while Firefox is running.
    ''Once you get the pop-up, just select "'Start in Safe Mode"''
    '''''If the issue is not present in Firefox Safe Mode''''', your problem is probably caused by an extension, and you need to figure out which one. Please follow the [[Troubleshooting extensions and themes]] article for that.
    ''To exit the Firefox Safe Mode, just close Firefox and wait a few seconds before opening Firefox for normal use again.''
    Please report back soon.

  • I get a dialog box to allow a cookie from Yahoo mail but it does not respond and locks up the entire browser. All other sites work fine.

    The sign in page for yahoo mail wants to set cookies. I get a dialog box that asks to set a second cookie but it is unresponsive, eitehr to check allow or close it. Going to task manage says the site is waiting for input from me but I cannot get the browser to respond in any manner whatsoever.
    All other tabs work fine and the yahoo site can be opened with IE fine.

    Set up to "Ask me every time" in the Privacy elections. I think I found the problem. Looks like there were two dialog boxes, the second right on top of the first so I could not check the first one so it never got the OK and kept waiting for input.
    Seems OK now.

  • Safari won't load almost all adobe sites

    Everytime I do a google search or try to log into any Adobe site forum it doesn't work. Any question about Flash or Adobe product and the link starts with "http://www.adobe.com..." doesn't work. It is VERY frustrating! I've even tried resetting the browser and no luck. Try the link below, doesn't work.
    https://www.adobe.com/cfusion/entitlement/index.cfm?e=ca&returnurl=http://forums .adobe.com/adobe_login&loc=en
    SEE:

    You, or someone using your computer, hacked the system to enable the use of unlicensed Adobe software. To remove the hack, proceed as follows.
    Back up all data.
    These instructions must be carried out in an administrator account, if you have more than one user account.
    Launch the Terminal application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad. Click Utilities, then Terminal in the icon grid.
    Copy or drag — do not type — the line of text below into the Terminal window, then press return:
    open /etc/hosts
    A TextEdit window should open. At the top of the window, you should see something like this:
    # Host Database
    # localhost is used to configure the loopback interface
    # when the system is booting.  Do not change this entry.
    127.0.0.1                              localhost
    255.255.255.255          broadcasthost
    ::1                                        localhost
    fe80::1%lo0                    localhost
    Below that, you'll see some other lines. There should be nothing before the first line above. Make sure you scroll all the way to the bottom of the document. In OS X 10.7 or later, scroll bars are hidden by default until you actually start scrolling, so you may not realize that you’re not seeing the whole document.
    If the contents of the TextEdit window are as described, close it, then enter the following command in the Terminal window in the same way as before; i.e., without typing:
    sed '/lo0/q' !$ > Desktop/hosts
    You should now have a file named "hosts" on your Desktop. Double-click the file to open it in TextEdit, and verify that it has only the contents shown above, with any extra lines removed. If so, close the window without making any changes.
    Next, go back to the Terminal window and enter one final command, again without typing:
    sudo sh -c 'cat Desktop/hosts > /etc/hosts'
    This time, you'll be prompted for your login password, which won't be displayed when you type it. You may get a one-time warning not to screw up. Confirm. Quit Terminal.
    Do not type anything in the Terminal window except your password.
    That will fix the hosts file. You can now delete the file that was created on your Desktop.

  • I enable Auto Logon on one particular website, but firefox doesn't appear to remember this, all other sites work OK

    iMac running OSX10.6.
    MacBookPro running same system, and same version of Firefox, works OK on same website

    Websites remembering you and automatically log you on is stored in a cookie.
    * Create an allow cookie exception (Firefox > Preferences > Privacy > Cookies: Exceptions) to keep such a cookie, especially for secure websites and if cookies expire when Firefox is closed.
    Make sure that you do not run Firefox in Private Browsing mode.
    * https://support.mozilla.com/kb/Private+Browsing
    Do not use Clear Recent History to clear the "Cookies" and the "Site Preferences"
    * https://support.mozilla.com/kb/Clear+Recent+History
    Clearing "Site Preferences" clears all exceptions for cookies, images, pop-up windows, software installation, and passwords.
    * http://kb.mozillazine.org/Cookies

  • Facebook page not open while all other sites working probably

    i faced this problem only with facebook 2 days ago , and it is not only in firefox , i faced same issue for other browsers , i tried to do every thing , cleared caches and cookies , make firewall off , but the problem not solved , i need your help to solve this issue before i format my PC.

    Do a malware check with several malware scanning programs on the Windows computer.<br>
    Please scan with all programs because each program detects different malware.<br>
    All these programs have free versions.
    Make sure that you update each program to get the latest version of their databases before doing a scan.
    *Malwarebytes' Anti-Malware:<br>http://www.malwarebytes.org/mbam.php
    *AdwCleaner:<br>http://www.bleepingcomputer.com/download/adwcleaner/<br>http://www.softpedia.com/get/Antivirus/Removal-Tools/AdwCleaner.shtml
    *SuperAntispyware:<br>http://www.superantispyware.com/
    *Microsoft Safety Scanner:<br>http://www.microsoft.com/security/scanner/en-us/default.aspx
    *Windows Defender:<br>http://windows.microsoft.com/en-us/windows/using-defender
    *Spybot Search & Destroy:<br>http://www.safer-networking.org/en/index.html
    *Kasperky Free Security Scan:<br>http://www.kaspersky.com/security-scan
    You can also do a check for a rootkit infection with TDSSKiller.
    *Anti-rootkit utility TDSSKiller:<br>http://support.kaspersky.com/5350?el=88446
    See also:
    *"Spyware on Windows": http://kb.mozillazine.org/Popups_not_blocked

  • All browsers return blank screen for Facebook. All other sites work.

    I have 2 macs: iMac and MacBook Pro 17". Both are running the latest version of Mountain Lion (10.8.3), and the latest versions of Firefox and Chrome. Both have the same problem. When I try to open facebook, I get a completely blank window in my browser (regardless of which one). No errors, no spinning wheel, just white screen. I've been all over the net looking for a solution. I'm using https:, I can ping successfully, other sites load fine. I've logged out and logged in using a different user name and the same problem occurred after I went from my personal profile to a Page I manage (which means it changed URLs). I can't go to any facebook URL, not any help articles, etc. I've rebooted my router, rebooted the computer, restarted the browser. I am using a verizon MiFi as my router (my only way to connect to the internet), so if I boot to safe mode I have no way of plugging in to the router using ethernet.  The only thing that changes anything is when I disable "javascript", not "java". When I do this, I'm able to browse facebook, but many of the features no longer work, so that isn't a solution.
    I hope someone can help me, I'm not a teenager who is missing their friends, I'm a social media consultant and I need facebook to do my job! 
    Thanks in advance.

    I can ping successfully
    What IP address do you get for Facebook?

  • I cannot access my ebay account. I can still look for stuff but if I try to login in I get an error message saying that the connection was reset. This is the only site I am having issues with. The site works with IE6 but I would rather use Firefox.

    - Was having problems accessing messages on Facebook, seems to be working now
    - Cannot login on ebay.ca or ebay.com
    - Having troubles listing items on ebay (uploading pictures)... this started before the logging in problems
    - Problems only on laptop, other PC in the not having any problems
    - Can log in to ebay using IE on laptop, but I would rather use Firefox

    HouFunGuy wrote:
     One thing I notice is that the _mmServerScripts folder does not show up in my Local Files folder - even after refreshing. (The underscore must hide this folder?)When I change the drop-down from Local View to Testing Server I don't see the _mmServerScripts folder, and all folders are red.
    The underscore at the beginning of the folder name hides it in the Files panel, although you can turn on the option to display hidden files by accessing the panel options menu.
    The folder icons in the Files panel are colour coded: green is for local files, red represents the testing server (or Subversion repository, if defined), and yellow (Windows) or blue (Mac) represents your remote server.
    As Randy says, check the Web URL in your testing server definition. It should be http://localhost/check_php/.

  • Interactive portions of web sites are not working. I click on the interactive buttons and nothing happens. All these sites work normally on Safari. I am using a MacBook Pro and an IMac.

    Examples are click to purchase or click to download PDF files. This is happening on most if not all websites.

    Well that's nice and all, but why not just spend the 50 bucks on a router? Also, why do you need a crossover cable? Modern operating systems do not require crossovers anymore.
    ~David

  • Can't connect to a site - all other sites working fine

    Bizarre problem here: I can't connect to one particular site from my iMac. I have a WiFi network, using an Apple Airport Express. I can connect to this same site from my MacBook, connected to the same WiFi network.
    Has any one encoutered this same problem before?

    Have you tried resetting Safari or clearing the cache (vs a full reset)? The command is in the Safari menu. My wife's PC sometimes has a similar problem with IE occasionally and requires the cache to emptied to fix it.

Maybe you are looking for