New, Single Server - DNS, Web, Wiki, Mail Setup Issues

I'm having some issues properly setting up 10.7.3 to host internal DNS and external Web, Wiki and Mail.  I'm having issues with the web and wiki hosting.  Since those are the most important right now, I haven't really had a chance to fully test the other features.  I was able to do some testing of the mail and iCal but it was limited.
Long read below but I thought the specifics would be helpful...
My goals and configuration are:
***GOALS***
Primary:
1) Host a public website: example.org and www.example.org
2) Host a public wiki: main.example.org and www.main.example.org
3) Host a public mail server: [email protected]
4) Host a public, group calendar
4a) Read only to majority - Read/Write to a group
5) Host a global address book for authenticated users
Secondary:
6) Allow anonymous public access to a file share (read only)
7) Allow authenticated access to the same file share (read/write)
8) Do as much of this via GUIs as possible.
***SETUP AND CONFIGURATION***
Physical:
1) Business class Internet (no blocked ports)
2) A single, public and static IP address
3) Domain name and public DNS via GoDaddy
4) Wildcard Cert: *.example.org from GoDaddy
5) Late 2011 (bought in Jan 2012) MacMini Lion Server (the $1,000 one).
5a) Upgraded the RAM to 16GB (need for VMware Windows clients)
5b) Added two USB to Ethernet adapters.
6) Using a new model AirPort Extreme Base Station (bought w/ the MM) as the main router.
Initial Configuration:
7) Setup a Mac Address reservation for the main and two USB Ethernet ports along with the wireless too.
7a) Main port = 10.0.1.5 / Others are .6, .7 and .10
8) During the setup, I chose the Host on the Internet (third) option and named my server: main.example.org
9) After the setup completed, I upgraded the OS & Admin Tool to 10.7.3 from a clean install (on #5 now)
DNS Config
10) I used the admin tool to open DNS and change:
11) "Primary Zone Name" from main.example.org to example.org.
12) In the "Nameservers:" block, I changed the zone name there but left the nameserver name alone (zone: example.org /// Nameserver Hostname: main.example.org).
13) The Machine Name and Reverse Zone was left alone.  RZ resolves to main.example.org.  sudo changeip -checkhostname is good.  dig on the example.org and main.example.org are good to go (NOERROR).
OD Config
14) From the server app, I clicked Manage/Network Accounts and setup the OD - No issues.
SSL
15) From the server app, I created self signed cert, generated a CSR, got a public Cert, then replaced the self-signed with the public one - No issues.
16) Changed any service using the self-signed cert to the public one - No issues.
17) Changed the cert in the OD to the public cert from server admin - No issues.
In order: File Sharing, Mail, AB, iCal, Web, Wiki, Profile Manager, Network Groups, Network Users
18) File Sharing was setup using the server app
19) Setup mail using the server app to start it and the server admin app to configure it - No issues there (I think...)
20) AB - Flipped the switch to on
21) iCal - Flipped the switch to on - I setup the e-mail address to use after I added the network accounts.
22) Web - Flipped the switch to on - Default site worked (main.example.org)
23) Wiki - Flipped the switch to on - Default wiki worked. (main.example.org)
24) PM - Checked the sign config profiles and enabled the device mgt.  I then flipped the switch to on - Default settings and pages worked.
***MY PROBLEMS***
Website:
Adding a website for example.org gave me the red dot in the server app.  To fix that, I added a Machine Name record to my primary zone (PZ = example.org Machine Name = example.org).  I first tried using the same 10.0.1.5 IP as the main.example.org and left the reverse mapping alone (still resolved to the NS of main.example.org).
That gave me the green light in the server app when trying to add the website again.  From there, I changed the "Store Site Files In" to the location of my website files (and confirmed "Everyone" has Read Access in the folder's security settings).  I left the other info alone (all defaults accepted) and clicked done.
Access to the website works on the server but external access doesn't (Network Error/timed out tcp_error).  Checked the AirPort settings using the AirPort utility (version 5.5.3) and the Port Mapping (under the "Advanced" icon) show serveral services all pointing to 10.0.1.5.  Thinking it could be DNS I tried main.example.org externally and it failed the same way.
I ran the changeip command (good to go) and dig on example.org and main.example.org and they both resolved to 10.0.1.5 correctly.
I removed the example.org Machine Record from the zone and it now looks like:
PZ=example.org / ZONE=example.org / NS=main.example.org
Machine Record=main.example.org / IP=10.0.1.5
RM=10.0.1.5 / Resolves=main.example.org
PLEASE HELP!

The amount of users (if relevant):
On site - 1 (Me)
Off site - 16 (Windows clients - some have iOS devices too)
Web site traffic - less than 50 regular visits per day (avg of 15) with a peek of ~125 once a month.
This is for a 501c3 public nonprofit made of all unpaid volunteers (including the officers and directors).  All of us have paying day jobs and I just so happen to be the guy that knows just enough to get myself in trouble here.

Similar Messages

  • Exchange Server 2003 with Apple Mail Setup Issues

    Hi everyone,
    I've been trying my hardest to setup my designer's Mac on our Exchange 2003 Server with Apple Mail with little success. I was able to setup the Exchange account as the Outlook Web Access server is setup for IMAP. However, I seem to have trouble with the incoming and outgoing mail servers. Running through the Connection Doctor says that the account is connected, however the outgoing mail server is not responding. I am using the mail server info from my MIS guy. For examples:
    I setup the Outlook Web Access Sever as: "OWA-XX/exchange"
    - This seems to connect the account
    I setup the Outgoing Mail Server as: "mail-xxx2", with password enabled. This server address was provided to me by my MIS guy
    - The Mac claims is cannot access this server.
    Any suggestions here? My buddy is running the latest 10.4 on a old PowerMac G4 QuickSilver.

    My buddy upgraded to Office 2004 with Entourage which did the trick!

  • Exchange Server 2003/2010 Coexistence Mail-flow Issues

    I've installed Exchange 2010 in a 2003 coexistence scenario.
    2010 was deployed with CAS,HUB, and Mailbox roles. 
    The installation went through smoothly, and the default RGC was created.
    On the 2010 Server, when I create a new users with mailbox, that user is no able to send or receive mail from anywhere.
    2010 user to 2010 user does not work
    2003 user to 2010 user does not work
    Mail delivery between 2003 users works fine. 
    The RGC message queue in ESM 2003 shows that the messages are queued and keep retrying. 
    I have deleted the RGC twice and created new ones, I have un-installed the HUB and CAS roles and re-installed them, and I have also re-run setup /preparead and setup /preparelegacyexchangepermissions
    I'm not able to make any sense of the message tracking on the 2010 side. It just shows a bunch of entries: 
    EventID: NOTIFYMAPI
    Source: STOREDRIV 
    When I use the best practices analyzer to test mailflow to a 2010 user from the outside, the test comes back with a pass even though the message itself isn't delivered to the specified mailbox. 
    There is no smart host defined on the default SMTP virtual server on 2003.
    There is no SMTP Send Connector for External or Internal mail configured on 2003 besides the 2010 RGC
    Any ideas?
    Here is the mail flow analyzer result:
         Testing inbound SMTP mail flow for domain '[email protected]'.
         Inbound SMTP mail flow was verified successfully.
         Additional Details
    Elapsed Time: 3437 ms.
         Test Steps
         Attempting to retrieve DNS MX records for domain 'test.com'.
         One or more MX records were successfully retrieved from DNS.
         Additional Details
    MX Records Host mail.test.com, Preference 0
    , Host test.com, Preference 10
    Elapsed Time: 110 ms.
         Testing Mail Exchanger mail.test.com.
         This Mail Exchanger was tested successfully.
         Additional Details
         Test Steps
         Attempting to resolve the host name mail.test.com in DNS.
         The host name resolved successfully.
         Additional Details
         Testing TCP port 25 on host mail.test.com to ensure it's listening and open.
         The port was opened successfully.
         Additional Details
    Banner received: 220 EX2K3w2K3.test.net Microsoft ESMTP MAIL Service, Version: 6.0.3790.3959 ready at Wed, 5 Feb 2014 14:40:44 -0500
    Elapsed Time: 368 ms.
         Analyzing SMTP Capabilities for server mail.test.com:25
         SMTP Capabilities were analyzed successfuly.
         Additional Details
         Attempting to send a test email message to [email protected] using MX mail.test.com.
         The test email message was delivered successfully.
         Additional Details
    Elapsed Time: 621 ms.
         Testing the MX mail.test.com for open relay by trying to relay to user [email protected].
         The Open Relay test passed. This MX isn't an open relay.
         Additional Details
         Testing Mail Exchanger test.com.
         This Mail Exchanger was tested successfully.
         Additional Details
         Test Steps
         Attempting to resolve the host name test.com in DNS.
         The host name resolved successfully.
         Additional Details
         Testing TCP port 25 on host test.com to ensure it's listening and open.
         The port was opened successfully.
         Additional Details
         Analyzing SMTP Capabilities for server test.com:25
         SMTP Capabilities were analyzed successfuly.
         Additional Details
         Attempting to send a test email message to [email protected] using MX test.com.
         The test email message was delivered successfully.
         Additional Details
         Testing the MX test.com for open relay by trying to relay to user [email protected].
         The Open Relay test passed. This MX isn't an open relay.
         Additional Details

    No duplicate security groups. I did notice Exchange 2010 is not in the Exchange Domain Servers group, but 2k3 is. Not sure if that matters. 
    In the Application event log I'm seeing this error a lot.
    Log Name:      Application
    Source:        MSExchangeMailSubmission
    Date:          05/02/2014 3:02:31 PM
    Event ID:      1009
    Task Category: MSExchangeMailSubmission
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      ex2010w2k8.test.net
    Description:
    The Microsoft Exchange Mail Submission service is currently unable to contact any Hub Transport servers in the local Active Directory site. The servers may be too busy to accept new connections at this time.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="MSExchangeMailSubmission" />
        <EventID Qualifiers="49156">1009</EventID>
        <Level>2</Level>
        <Task>1</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2014-02-05T20:02:31.000000000Z" />
        <EventRecordID>6530</EventRecordID>
        <Channel>Application</Channel>
        <Computer>ex2010w2k8.test.net</Computer>
        <Security />
      </System>
      <EventData>
        <Data>HubTransport</Data>
      </EventData>
    </Event>
    As long as you cannot send email between ex2010 users this has nothing to do with connectors/smtp config..
    I had the same issue one year ago and solved adding both sevrers to old/new exchange sevrers security groups.
    Looks like for some missing security entry (not sure why) mailbox is unable to conact HUB  (MSExchangeMailSubmission) I expect you seing items stuck in draft for owa (outbok for outlook)
    I saw in some blogs similar cases solved by setting static DNS servers for HUB severs config.
    Yes that is similar to what I'm experiencing.
    When using the Outlook client with a 2010 mailbox the mail leaves the outbox fine. When using OWA new messages just get saved as drafts when I try to send them.
    I will try your suggestions. I see two groups. Exchange Domain Servers, and Exchange Enterprise Servers of which Exchange Domain Servers is a member.

  • Mail setup issue

    Hi all.
    I have recently just made the leap of faith and decided to move away from a PC/Microsoft platform, and have purchased an iMac. There are obviously a lot of differences which I am getting my head around and it is going to take some time and patience, however the biggest thing that is puzzling me at the moment is the mail client.
    I have a few email addresses, but my main one is through my ISP, BT Internet. When configuring this as a POP3 account in Outlook on my PC, it runs fine and physically removes copies of the mail from the webmail server. With the Mac however, the email is downloading to the machine, but it is not removing the copy from the webmail server, which I am having to do manually.
    I have read a few articles on the support forums and it seems a few people have had this issue, but there doesn't appear to be an option for me to remove the mail from the server when they download to the client. Any help would be massively appreciated.
    I have noticed that the account has been setup in the mail client as an IMAP account, but I can't see any way of being able to setup a POP3 account.
    If it makes any difference I am running OSX 10.9.4 and version 7.3 of Mail.
    Thanks,
    Ben

    If you have the settings for POP, delete the existing account. Add a new account and when the 1st screen is filled, hold down the option/alt key while clicking continue. That should allow you to manually set up the account.
    Then go Mail/Preferences/Accounts, select the account, then Advanced where there is an option to remove from server.
    Welcome to the world of Mac. Some ‘light’ reading to help the transition. I don’t recommend trying to get through all of this at once.
    
A guide for switching to a Mac
    Anatomy of a Mac
    
Mac Basics—Tutorials on using a Mac
    
Mac OS X keyboard shortcuts,
    Mac Basics – Switching From Windows
    Mac OS FAQ
    MacTips,
    Quick Assist
    Switch Basics
    Switching to Mac Superguide
    Switching to the Mac: The Missing Manual, Mountain Lion Edition
    
Take Control E-books
    
Welcome to the Switch To A Mac Guides

  • IPhone3g Mail Setup Issue - Advanced settings no-more?

    Ok, so I'm a student at TCU in Ft. Worth. I recently purchased the new iPHone3g to replace my old palm lifedrive. I was following the instructions my school provides to setup email on iphones at http://www.tr.tcu.edu/iPhone.htm and came across quite a big issue. Step six tells me to go to advanced settings and set SSL for incoming to OFF and SSL for outgoing to ON.
    WELLLLL on the I-3g, there is no longer an advanced settings section. The only place I have found one is for email accounts that have already been set up on the phone, and even then they don't give the option to change for outgoing or incoming.
    So does anyone know of a way to setup my email? I'd be ****** if my iphone was just as useless as my brick of a palm.

    I think I can help. I have yahoo and gmail set up on 3G.
    Go to Settings> Mail, contacts,.....> choose your email account> outgoing mail server set-up (smtp) is just above the advanced button at the bottom of that screen. Click on primary server and change SSL to watever you need it to be. Go back and click advanced and change your imap or pop server. cheers.

  • IPhone Mail Setup Issue

    Hi,
    I had configured my iPhone to access my corporate mails through Microsoft Exchange server (Office 2003 server and it uses RPC type connection). At first I was able to access my mails, but in my organization it is mandate to change the password every 60 days. So I changed my password word and tried to do the same in my iPhone. It connected to the email initially with my new password. After that when I check my account settings in iPhone it still shows the old password and it tries to connect to the mail and then locks my account. I tried following things
    1. Deleting the email account and recreating the new one but it still shows the same old password even though I give the new password while I setup the account.
    2. Deleting the email account and then Resetting the network settings to factory setting and creating the new email account again with new password but it still connects with the old password and locks my account.
    I do not want to restore my iPhone with the option in iTunes and also do not want to use the erase all the settings in iPhone. Please help me to resolve this issue as soon as possible. Thanks in advance. I am using iPhone 2.2.

    I'm having the exact same issue. Did you ever get this resolved?

  • E-mail setup issues on Curve 8530

    Hello, I'm new to the BB and am having issues with setting up e-mail. I purchased this BB on e-Bay and did not receive any manuals with it. When trying to setup e-mail, the only option I get is for the Enterprise Server. I do need to use this as one of my mail programs is GroupWise. However, I also use Hotmail e-mail and can't get to this. What else do you need to help me?
    Solved!
    Go to Solution.

    Do you have a BlackBerry Data Plan enabled on your account with your carrier or mobile provider?
    You must, in order to get the RIM push email functions you are looking for, as well as addtional BlackBerry data services such as the internet browser, Facebook for BlackBerry, BlackBerry Messenger, and much more.
    So, call your carrier and inquire about having the BlackBerry Data Plan added to your account.
    Good luck.
    1. If any post helps you please click the below the post(s) that helped you.
    2. Please resolve your thread by marking the post "Solution?" which solved it for you!
    3. Install free BlackBerry Protect today for backups of contacts and data.
    4. Guide to Unlocking your BlackBerry & Unlock Codes
    Join our BBM Channels (Beta)
    BlackBerry Support Forums Channel
    PIN: C0001B7B4   Display/Scan Bar Code
    Knowledge Base Updates
    PIN: C0005A9AA   Display/Scan Bar Code

  • Solution to yahoo mail setup issues with Apple mail...

    There have to be a lot of people out there who have a similar setup as me --- ISP is Verizon (FIOS), and am using an iMac w/OS X, v 10.7.4, and Apple Mail v 5.2.  No matter what I did, I could not get Apple mail to connect to Yahoo's smtp server...  (Gmail was not working either)  I spent hours on this.  FINALLY -- I discovered the problem.  My FIOS router/firewall was on the maximum security setting, which only allows outgoing smtp mail to port 25!  Once I changed that firewall setting (which allows outgoing smtp mail to port numbers other than 25), I was finally able to connect to yahoo's smtp server!  Now my Apple mail works just fine.  Here are the settings I used:
    Incoming mail server: pop.mail.yahoo.com
    Incoming port: 995
    Outgoing mail server: smtp.mail.yahoo.com
    Outgoing port: Used "custom port" set to 465
    SSL is used for both incoming and outgoing servers, with password as the authentication method.
    Full email address is used wherever it says "user name" in mail preferences
    * This is with Yahoo Plus mail.  And before you do anything with Apple mail, you have to make sure that you enable "POP" mail in your Yahoo Plus account, under mail - settings.
    I hope this saves some people the hours of time that it cost me!! 

    I have managed to get incoming mail to work. It is the outgoing settings that are still not working on my system. I have tried every configuration. I have gone back and forth between Verizon and Apple Care too many times to count.
    Do you have to turn down the security level on the FIOS router/firewall before making these changes? If you do, it probably makes the system more vulnerable to malware, etc.
    I have standard Yahoo Verizon mail. I believe you can enable it for POP mail. It certainly always worked for me before. Like you I have tried everything. I was also told that my internet connection is PPPoE versus DHCP which may also cause problems. Like you, I have spent days trying to sort this out.

  • Mail setup issues

    I have setup two email accounts on my Mac, but now have two setup popup boxes open on the main screen that I cannot cancel or close.  Because they are unresponsive I cannot open the mail icon.  How can I close these?

    Hey cottagelife,
    Thanks for the question. Let’s try force quitting the Mail application (and any other applications that may not be responding):
    OS X: How to quit an unresponsive application using Force Quit
    http://support.apple.com/kb/HT3411
    Thanks,
    Matt M.

  • HT6030 Apple Mail setup Issues. I have issues trying to use apple mail even after all updates and fixes. What else can i do to try and use it?

    Does Anybody have issues setting up the mail accounts in apple Mail. I am trying to set up Google mail accounts and icloud account with no luck. All recent updates is done and still it does not setup. I have re-installed the OSX and still no luck.when it does accept the passwords it does not appear in the mail application so i can still not send and receive!!!!! PLEASE any help will be appreciated.

    Have you Enabled Two Step Verification Recently with Gmail?

  • Microsoft exchange mail setup issue

    Hi, i keep having a problem trying to add a microsoft exchange mail server on my iphone
    the serve is
    http://getmail.technologyevaluation.com/exchange/
    i use the same login/password that works on the website and works
    but on the iphone, i keep getting the error : Exchange Account verification Failed.
    what gives

    ya ofcourse
    i put getmail.technologyevaluation.com/exchange
    i even tried exchange.technologyevaluation.com
    same problem

  • E-mail setup issues

    I need HELP!
    I have been receiving absolutly no help from my local SPRINT representatives and I am about ready to throw my blackberry out the window!
    I received a replacement phone for my blackberry that has a missing part and I was able to sycronize all things from the old blackberry 8330 onto the new blackberry 8530...problem is that I am not getting my emails now! When I go to set up wizard, I am not given the options to set up new accounts or to delete accounts, just to sign in and when I do, the log in and passwords are not correct...even though they are...HELP!

    Cath,
    It sounds like they just got a new device and need to get the pin swapped in BIS.  It's simple if/when the OP comes back. 
    1. Please thank those who help you by clicking the "Like" button at the bottom of the post that helped you.
    2. If your issue has been solved, please resolve it by marking the post "Solution?" which solved it for you!

  • New M5000 server - Can't get bge0 to work in the OS

    Just recently powered up a new M5000 server. Went through the setup process of setting the networking details of the management card - which I believe also works through ethernet0 (LAN#0). That is working just fine and is what I have used to access the system console. Single domain, nothing odd in the configuration.
    The pre-installed Solaris sees bge0 and bge1. It also shows the ppp connection for the dscp.
    if config shows a normal adapter config but without the RUNNING flag. cfgadm shows the drivers properly loaded. There are cables connected to both NIC cards. The same result, btw, on the bge1 card. The NIC's show activity LED's so there is definitely a physical connection there.
    What else can I provide to get assist anyone in helping me solve this problem?
    Thanks
    Norm Dressler

    Hi all, I'm new to the forum
    Have installed the above mentioned server running the x86 platform with Solaris 10 1/08 with broadcom ethernet adaptor cards.
    My network connections are giving issues. bge0 and bge1both show physical activity and these are my configs
    # ifconfig -a
    lo0: flags=2001000849<UP,LOOPBACK,RUNNING,MULTICAST,IPv4,VIRTUAL> mtu 8232 index 1
    inet 127.0.0.1 netmask ff000000
    bge0: flags=1000843<UP,BROADCAST,RUNNING,MULTICAST,IPv4> mtu 1500 index 2
    inet 192.168.1.170 netmask ffffff00 broadcast 192.168.1.255
    ether 0:11:25:22:1f:26
    bge0: flags=1000843<UP,BROADCAST,RUNNING,MULTICAST,IPv4> mtu 1500 index 3
    inet 10.0.0.1 netmask ffffff00 broadcast 10.255.255.255
    ether 0:11:25:22:1f:27
    My default router also exists
    # vi /etc/defaultrouter
    192.168.1.254
    ~
    The hosts file
    # vi /etc/hosts
    ::1          localhost
    127.0.0.1 localhost
    192.168.1.170 hostname1      loghost
    10.0.0.1      hostname1
    ~
    ~
    And the device files
    # vi /etc/hostname.bge0
    hostname1
    ~
    ~
    # vi /etc/hostname.bge1
    hostname2
    ~
    ~
    All these including restart procedures aren't working.
    I dont seem to be able to get to other devices on the network yet the local TCP/IP stack behaves just OK. I can ping all the interfaces but cannot ping any device on the network.
    During install too, I attempted to acquire a dhcp address via the network from a dhcp server that serves IPs to our network but failed thus proceeded to static addressing.
    Any advice please?

  • Intermittend DNS resolution, timeserver, group policy updates errors in client logs in Win 2012 R2 single server environement

    We recently switched hardware and server software Win SBS 2008 to 2012R2 for a small network roughly 40 clients (Win7 Pro / Win 8.1 Pro) about 16 running concurrently at a given time and one network printer with the printer queue residing on the DC as well.
    I read that a single server environment might not be ideal in particular no fail-over but that is an accepted risk in this particular network here.
    Errors:
    Error 1043: Timeout during name resolution request
    Error 1129: Group policy updates could not be processed due to DC not available
    Error 5719: Could not establish secure connection to DC, DC not available
    Occasionally but disappears after a while
    Error 134: As a result of a DNS resolution timeout could not reach time server
    Symptoms
    On Win 7 Clients
    Network shares added through Group Policy will not show sometimes
    Network shares disconnect (red X) and when accessed return access authorization error after one or two clicks on the share finally grant access again
    When the issue with accessing network shares occurs, it usually also affects Internet access meaning a 'server not responding' error appears in the browser windows when trying to open just any web page
    nslookup during the incident returns cannot resolve error
    ipconfig on client shows correct default router (VDSL Router) and DHCP / DNS Domain Controller
    Also, the Win system log shows the above errors during these incidents, however, the nuimber of incidents vary from 20-30
    On Win 8.1 Clients
    Same as above with the slight variation for network shares apparently due to Server 2012 and Win 8.1 clients managing drive shares differently. However, network share refresh does not work with this clients. In most cases only a gpupdate /force returns
    drive shares but usually only for the active session. After logoff / logon the shares are gone again.
    The issue does appear to be load related since it occurs even if there are only one or two workstations active.
    Server Configuration
    Dell R320 PowerEdge 16GB / 4TB 7200RPM RAID10 / GBitEthernet
    Zyxel 1910-48 Port Switch
    VDSL 50Mbps Down / 20Mbps Up
    Since the DC is the only local DNS and there are no plans to add another one or move DNS to another server, the DNS server is configured with this own address as preferred DNS with three DNS forwarders 1) VDSL Router 2) ISP DNS1 3) ISP DNS2
    Currently only one Network card is active for problem determination reasons.
    There appears to be no consensus concerning IPV6 enabled or disabled, I tried both with no apparent effect
    I have set all network cards server and client to Full Duplex and the same speed, also disabled Offload functions within the adapter settings. Some but no consistent improvements.
    Best Practice Analyzer Results
    DNS server scavening not enabled
    Root hint server XYZ must respond to NS queries for the root zone
    More than one forwarding server should be configured (although 3 are configured)
    NIC1 should be configured to use both a preferred and alternate DNS (there is only one DNS in this network)
    I have found some instructions to apply changes to the clients through a host file but I would rather like to understand whether this DNS response time issue can be resolved on the server for example timing setting perhaps. Currently the DNS forwarders are
    set to 3 second.
    Since a few people have reported issues with DNS but most are working with multi DNS, DC environment I could not really apply any suggestions made there. perhaps there is anyone like me who is running a single server who has overcome or experience the same
    issues. Any help would be appreciated

    Hello Milos thx for your reply.. my comments below
    1. What does it "switched"? You may mean migration or new installation. We do not know...
    >> Switched is probably the incorrect term, replaced would be the appropriate wording. Before, there was a HP Proliant Server with SBS 2008 with distinct domain and now there is a Dell Server with MS 2012 R2 with a distinct domain. Client were
    removed from one (SBS) domain and added to the new Server 2012 domain. Other components did not change for example same Network Switch or VDSL Router, Workstations and Printer
    2. Two DCs are better alternative. Or backup very frequently. There are two groups of administrators. Those who have lost DC and those who will experience this disaster in near future.
    >> Correct, and I am aware of that
    3. NIC settings in W 7 and W 8.1, namely DNS points to DC (...and NOTHING else. No public IP or that of router DNS.))
    >> Correct, this is how it's currently implemented. Clients point to DC for DHCP and DNS and Default Router, no public IP or DNS. The only references to ISP DNS exist on the VDSL Router itself as provided through ISP when establishing VDSL
    Link and the list of Forwarders in the DNS Server configuration. However, I have just recently added the ISPs DNS as forwarders for test purposes and will probably learn tomorrow morning whether this had any effect for better or worse.
    4. Do nslookup to RR on clients. RR branch is saying client basic info on LDAP parameters of AD.
    >> Will post as soon as available
    5. I do not use forwarders and the system works
    >> Ok, does this mean it works for you in a similar or the same infrastructure setup or are you saying it is not required at all and I can remove any forwarder in a scenario like mine? If not required can you explain a bit more why it is not
    required apart from that it does work for you that way?
    6. DHCP should sit on DC (DHCP on router is disabled)
    >> Correct, no other device is configured to provide DHCP service other than DC and DHCP is currently running on DC
    7. NIC settings in DC points to itself (loopback address 127.0.0.1)
    >> Are you sure this is still correct and does apply to Server 2012? I am reading articles stating that it should be the servers own IP but local loop or should this be added as alternate DNS in addition to the servers own IP?
    8. Use IPCONFIG /FLUSHDNS whenever you change DNS settings.
    >> OK, that was not done every time I changed some settings but I can do that next week. Reboot alone would not suffice, correct?
    9. Test your system with dcdiag.
    >> See result below
    10. Share your findings.
    Regards
    Milos
    Directory Server Diagnosis
    Performing initial setup:
       Trying to find home server...
      Home Server = GSERVER2
       * Identified AD Forest.
       Done gathering initial info.
    Doing initial required tests
    Testing server: Default-First-Site-Name\GSERVER2
          Starting test: Connectivity
             ......................... GSERVER2 passed test Connectivity
    Doing primary tests
       Testing server: Default-First-Site-Name\GSERVER2
          Starting test: Advertising
             ......................... GSERVER2 passed test Advertising
          Starting test: FrsEvent
             ......................... GSERVER2 passed test FrsEvent
          Starting test: DFSREvent
             ......................... GSERVER2 passed test DFSREvent
          Starting test: SysVolCheck
             ......................... GSERVER2 passed test SysVolCheck
          Starting test: KccEvent
             ......................... GSERVER2 passed test KccEvent
          Starting test: KnowsOfRoleHolders
             ......................... GSERVER2 passed test
             KnowsOfRoleHolders
          Starting test: MachineAccount
             ......................... GSERVER2 passed test MachineAccount
          Starting test: NCSecDesc
             ......................... GSERVER2 passed test NCSecDesc
          Starting test: NetLogons
             ......................... GSERVER2 passed test NetLogons
          Starting test: ObjectsReplicated
             ......................... GSERVER2 passed test
             ObjectsReplicated
          Starting test: Replications
             ......................... GSERVER2 passed test Replications
          Starting test: RidManager
             ......................... GSERVER2 passed test RidManager
          Starting test: Services
             ......................... GSERVER2 passed test Services
          Starting test: SystemLog
             ......................... GSERVER2 passed test SystemLog
          Starting test: VerifyReferences
             ......................... GSERVER2 passed test VerifyReferences  
       Running partition tests on : ForestDnsZones
          Starting test: CheckSDRefDom
             ......................... ForestDnsZones passed test CheckSDRefDom
          Starting test: CrossRefValidation
             ......................... ForestDnsZones passed test
             CrossRefValidation
       Running partition tests on : DomainDnsZones
          Starting test: CheckSDRefDom
             ......................... DomainDnsZones passed test CheckSDRefDom
          Starting test: CrossRefValidation
             ......................... DomainDnsZones passed test
             CrossRefValidation
       Running partition tests on : Schema
          Starting test: CheckSDRefDom
             ......................... Schema passed test CheckSDRefDom
          Starting test: CrossRefValidation
             ......................... Schema passed test CrossRefValidation
       Running partition tests on : Configuration
          Starting test: CheckSDRefDom
             ......................... Configuration passed test CheckSDRefDom
          Starting test: CrossRefValidation
             ......................... Configuration passed test CrossRefValidation
       Running partition tests on : GS2
          Starting test: CheckSDRefDom
             ......................... GS2 passed test CheckSDRefDom
          Starting test: CrossRefValidation
             ......................... GS2 passed test CrossRefValidation  
       Running enterprise tests on : GS2.intra
          Starting test: LocatorCheck
             ......................... GS2.intra passed test LocatorCheck
          Starting test: Intersite
             ......................... GS2.intra passed test Intersite
    Server:  gserver2.g2.intra
    Address:  192.168.240.6
    *** gserver2.g2.intra can't find g2: Non-existent domain
    > gserver2
    Server:  gserver2.g2.intra
    Address:  192.168.240.6
    g2.intra
            primary name server = gserver2.g2.intra
            responsible mail addr = hostmaster.g2.intra
            serial  = 443
            refresh = 900 (15 mins)
            retry   = 600 (10 mins)
            expire  = 86400 (1 day)
            default TTL = 3600 (1 hour)
    > wikipedia.org
    Server:  gserver2.g2.intra
    Address:  192.168.240.6
    Non-authoritative answer:
    wikipedia.org   MX preference = 10, mail exchanger = polonium.wikimedia.org
    wikipedia.org   MX preference = 50, mail exchanger = lead.wikimedia.org
    polonium.wikimedia.org  internet address = 208.80.154.90
    polonium.wikimedia.org  AAAA IPv6 address = 2620:0:861:3:208:80:154:90
    lead.wikimedia.org      internet address = 208.80.154.89
    lead.wikimedia.org      AAAA IPv6 address = 2620:0:861:3:208:80:154:89
    Final benchmark results, sorted by nameserver performance:
     (average cached name retrieval speed, fastest to slowest)
      192.168.240.  6 |  Min  |  Avg  |  Max  |Std.Dev|Reliab%|
      ----------------+-------+-------+-------+-------+-------+
      + Cached Name   | 0,001 | 0,002 | 0,003 | 0,001 | 100,0 |
      + Uncached Name | 0,027 | 0,076 | 0,298 | 0,069 | 100,0 |
      + DotCom Lookup | 0,041 | 0,048 | 0,079 | 0,009 | 100,0 |
      ---<-------->---+-------+-------+-------+-------+-------+
                 gserver2.g2.intra
                    Local Network Nameserver
      195.186.  4.162 |  Min  |  Avg  |  Max  |Std.Dev|Reliab%|
      ----------------+-------+-------+-------+-------+-------+
      - Cached Name   | 0,022 | 0,023 | 0,025 | 0,000 | 100,0 |
      - Uncached Name | 0,025 | 0,071 | 0,274 | 0,065 | 100,0 |
      - DotCom Lookup | 0,039 | 0,040 | 0,043 | 0,001 | 100,0 |
      ---<-------->---+-------+-------+-------+-------+-------+
                         cns8.bluewin.ch
               BLUEWIN-AS Swisscom (Schweiz) AG,CH
      195.186.  1.162 |  Min  |  Avg  |  Max  |Std.Dev|Reliab%|
      ----------------+-------+-------+-------+-------+-------+
      - Cached Name   | 0,022 | 0,023 | 0,026 | 0,001 | 100,0 |
      - Uncached Name | 0,025 | 0,072 | 0,299 | 0,066 | 100,0 |
      - DotCom Lookup | 0,039 | 0,042 | 0,049 | 0,003 | 100,0 |
      ---<-------->---+-------+-------+-------+-------+-------+
                         cns7.bluewin.ch
               BLUEWIN-AS Swisscom (Schweiz) AG,CH
        8.  8.  8.  8 |  Min  |  Avg  |  Max  |Std.Dev|Reliab%|
      ----------------+-------+-------+-------+-------+-------+
      - Cached Name   | 0,033 | 0,040 | 0,079 | 0,011 | 100,0 |
      - Uncached Name | 0,042 | 0,113 | 0,482 | 0,097 | 100,0 |
      - DotCom Lookup | 0,049 | 0,079 | 0,192 | 0,039 | 100,0 |
      ---<-------->---+-------+-------+-------+-------+-------+
                 google-public-dns-a.google.com
                     GOOGLE - Google Inc.,US
      UTC: 2014-11-03, from 14:33:12 to 14:33:29, for 00:17,648
    15: 40
    192.168.240.  6 |  Min  |  Avg  |  Max  |Std.Dev|Reliab%|
      ----------------+-------+-------+-------+-------+-------+
      + Cached Name   | 0,001 | 0,002 | 0,004 | 0,000 | 100,0 |
      + Uncached Name | 0,025 | 0,074 | 0,266 | 0,063 | 100,0 |
      + DotCom Lookup | 0,042 | 0,048 | 0,075 | 0,007 | 100,0 |
      ---<-------->---+-------+-------+-------+-------+-------+
                 gserver2.g2.intra
                    Local Network Nameserver
      195.186.  1.162 |  Min  |  Avg  |  Max  |Std.Dev|Reliab%|
      ----------------+-------+-------+-------+-------+-------+
      - Cached Name   | 0,022 | 0,024 | 0,029 | 0,001 | 100,0 |
      - Uncached Name | 0,024 | 0,073 | 0,289 | 0,067 | 100,0 |
      - DotCom Lookup | 0,039 | 0,041 | 0,043 | 0,001 | 100,0 |
      ---<-------->---+-------+-------+-------+-------+-------+
                         cns7.bluewin.ch
               BLUEWIN-AS Swisscom (Schweiz) AG,CH
      195.186.  4.162 |  Min  |  Avg  |  Max  |Std.Dev|Reliab%|
      ----------------+-------+-------+-------+-------+-------+
      - Cached Name   | 0,022 | 0,024 | 0,029 | 0,001 | 100,0 |
      - Uncached Name | 0,025 | 0,073 | 0,286 | 0,065 | 100,0 |
      - DotCom Lookup | 0,041 | 0,066 | 0,180 | 0,037 | 100,0 |
      ---<-------->---+-------+-------+-------+-------+-------+
                         cns8.bluewin.ch
               BLUEWIN-AS Swisscom (Schweiz) AG,CH
        8.  8.  8.  8 |  Min  |  Avg  |  Max  |Std.Dev|Reliab%|
      ----------------+-------+-------+-------+-------+-------+
      - Cached Name   | 0,033 | 0,038 | 0,077 | 0,009 | 100,0 |
      - Uncached Name | 0,042 | 0,105 | 0,398 | 0,091 | 100,0 |
      - DotCom Lookup | 0,049 | 0,066 | 0,141 | 0,025 | 100,0 |
      ---<-------->---+-------+-------+-------+-------+-------+
                 google-public-dns-a.google.com
                     GOOGLE - Google Inc.,US
      UTC: 2014-11-03, from 14:39:59 to 14:40:12, for 00:13,363

  • Configure DNS on Snow Leopard Server for Web Hosting

    Hi Everyone,
    I put together an article on my blog about Snow Leopard DNS setup for web hosting. http://www.mkahn.com/?p=279
    I'll be revising it over the next few weeks to make it more informative based around feedback. Let me know if you have any questions or trouble setting up DNS on Snow Leopard Server for web hosting.

    Thanks for your replies. I realize I'm not making clear the way this network is configured . Also, the only services running on the Snow Leopard server are (at this time):
    dhcpd - in the 10.136.31.x range;
    dns - same as before;
    planned to add are:
    Open Directory (for network logins)
    Software update;
    Web (only on the 10.136.31.x Ethernet);
    mySQL (localhost only - for moodle);
    NAT is not set up on the Snow Leopard server itself. We have an outside router, a Cisco 2811. This router provides routing for both the public IP range, and the NAT range is configured in this router. The forwarding dns is located in LR and Fayetteville. So what I need is dns on Snow Leopard to forward outside queries to the state DNS servers, and resolve the local NAT IP only for Open Directory and a set of Snow Leopard clients.
    Is this going to be possible?

Maybe you are looking for

  • Copying apps from one itunes account to another

    I have been using my moms account to buy apps for the past couple of years(as has my whole family) but im moving out and need to get my own account, will i be able to transfer my apps from her account to mine? It is on the same laptop already.

  • How can I "share" or "move" iPhoto content between two acounts on PowerBook

    I share my PowerBook with my wife and we both have separate accounts. Problem is that all iPhoto content and iTunes content is on "my" account and she is having to switch from her account to mine in order to utilize content. I rarely use both applica

  • Copying basic dates to forecast dates

    Hi Experts, I am using WBSE and activities in my project. I want to copy basic dates to forecast dates. But, when i am doing this in Edit>Reconcile date->Transfer basic dates to forecast dates. Then my Planning type in network header also gets change

  • Valuation type while creating BOM

    Hello Experts, My requirement is that, I should be able to select valuation type of material in BOM. Please let me know, if there any setting where I can enter valuation type, while creating BOM. We have two valuation types for my raw material - Loca

  • Portal Content Translation

    Hi All, I have a PDK iview.I created  a Worklist for translating the name of the iView and the text strings in the resource bundle.I changed the text in the resource bundle to German.Finally I Published the Worklist. I also placed a small peice of co