Testing an ISA Server Rule, the recursive query to other DNS Servers test fails

Hello,
I am trying to configure the following infrastructure with ISA Server 2006 and two W2003 servers (called "Server1" and "Server2") . "Server1" is a domain controller, and in
"Server2" is the ISA Server installed, which also has
attached two network Ethernet cards, one called "Internal Ethernet Card", and the other one called
"External Ethernet Card".
The infrastructure would be:  "Internal Ethernet Card"---- ISA Server ----"External Ethernet Card"---"Router"----"Internet"
"Internal Ethernet Card" manages the internal package traffic of the infrastructure, the network segment which belongs is isolated from what we could called the Outbound traffic, which is linked to a router. "Internal Ethernet Card" it`s
a virtual network.
"Internal Ethernet Card" feature configuration is the following:
- IP address: 192.168.3.3
- Subnet Mask: 255.255.255.0
- DHCP Enabled: No
- DNS Server: 192.168.3.1 (Must point to the DC "Server1" which has the DNS Service installed)
- Default Gateway:  None  (because doesnt point to outside)
- Primary WINS Server: 192.168.3.1  
The "External Ethernet Card" provides, the outbound connection, and this card is connected to the physical router.
It`s feature configuration is the following:
- IP address: 192.168.1.50
- Subnet Mask: 255.255.255.0
- DHCP Enabled: No
- Default Gateway: 192.168.1.1
- DNS Servers: 192.168.3.1 (Must point to the DC "Server1" which has the DNS Service installed)
After configuring the network cards, I create the following rule in the ISA Server to allow the traffic towards outside from the server and the clients which have joined to the domain:
Action: Allow.  Protocol: DNS.  From:"Server2".  To : External.  Condition: All Users
After applying the changes to update the configuration, I enter in the Dns Server of "Server1" and in the "Monitoring" tab, I run a "recursive query to other DNS Servers" but fails.
Only works the "simple query against this DNS Server".
I don`t know why fails, but I`m stucked on this issue, because in the "Server1" DNS Server, in the "domain forward IP address list", I have added two DNS addresses which work OK.
I would appreciate some help to solve this issue.
Thanks
Regards 

Hello Ms. Long, 
Yes, you are right. In the Server1 is configured the DNS server, to use forwarders whose are set in the field "Selected domain`s forwarder IP address list", two DNS address numbers obtained from "Open DNS", which work well.
There is no DNS Server linked to the External NIC.
The Server1 belongs to a private network configured as "VMnet3", which it is set as follows:
IP address: 192.168.3.1
Subnet Mask: 255.255.255.0
Default Gateway: 192.168.3.3
DNS Server: 192.168.3.1
I have tried to test your suggested idea:
> set d2
> google.com
Server:  srv-dcfs-01.dominio.local
Address:  192.168.3.1
SendRequest(), len 42
    HEADER:
        opcode = QUERY, id = 2, rcode = NOERROR
        header flags:  query, want recursion
        questions = 1,  answers = 0,  authority records = 0,  additional = 0
    QUESTIONS:
        google.com.dominio.local, type = A, class = IN
Got answer (113 bytes):
    HEADER:
        opcode = QUERY, id = 2, rcode = NXDOMAIN
        header flags:  response, auth. answer, want recursion, recursion avail.
        questions = 1,  answers = 0,  authority records = 1,  additional = 0
    QUESTIONS:
        google.com.dominio.local, type = A, class = IN
    AUTHORITY RECORDS:
    ->  dominio.local
        type = SOA, class = IN, dlen = 46
        ttl = 3600 (1 hour)
        primary name server = srv-dcfs-01.dominio.local
        responsible mail addr = hostmaster
        serial  = 41
        refresh = 900 (15 mins)
        retry   = 600 (10 mins)
        expire  = 86400 (1 day)
        default TTL = 3600 (1 hour)
SendRequest(), len 28
    HEADER:
        opcode = QUERY, id = 3, rcode = NOERROR
        header flags:  query, want recursion
        questions = 1,  answers = 0,  authority records = 0,  additional = 0
    QUESTIONS:
        google.com, type = A, class = IN
DNS request timed out.
    timeout was 2 seconds.
timeout (2 secs)
SendRequest failed
*** Request to srv-dcfs-01.dominio.local timed-out
As you can see highlighted in bold, the problem remains in the "recursive query to other DNS Servers" check.
Maybe is better to put the issue on the "Windows Server General Forum" , because the issue has not nothing in common with the ISA Server, dont you?
Thanks
Best regards

Similar Messages

  • Proxy Error ( The ISA Server denied the specified Uniform Resource Locator

    Dear All,
       I am getting one error in ABAP proxy configuration,
      following is the error.
    ~response_line     HTTP/1.1 502 Proxy Error ( The ISA Server denied the specified Uniform Resource Locator (URL).  )
    ~server_protocol     HTTP/1.1
    ~status_code     502
    ~status_reason     Proxy Error ( The ISA Server denied the specified Uniform Resource Locator (URL).  )
    via     1.1 BLRSPRX10001
    connection     close
    proxy-connection     close
    pragma     no-cache
    cache-control     no-cache
    content-type     text/html
    content-length     4070
        suddenly one day this error occured.  proxy configuration was working earlier fine. SLDCHECK also working without any problem now also. but in SPROXY it is saying no connection to ESR. only local objects.
    Please help me.
    Regards
    Pradeep P N

    Hi Pradeep,
    What is this BLRSPRX10001?
    IF it is rfc destination, then check the user.
    This problem is related to user rights. The user used there might not have sufficient authorizations to invoke the proxy. (may be the authorization is expired)
    Regards
    Suraj

  • DHCP Server with the Static IP fill out DNS information

    When filling out the DHCP Server with the Static IP from ipconfig.exe in the "Preferred DNS server IPv4 address:
    192.168.1.199
    The same as in the static IP.  The IPv6 DNS one validates IPv4 does not.
    I tried using the IPv4 Address and that validated but gave an error at the end: 1059 and 1046.
    Gives an error:
    "The DNS Server at the specified IP address does not support the required TCP protocol."

    Hi,
    Firstly, would you please post the result of running “ipconfig/all” on the DHCP server and domain controller?
    It seems that the DHCP server cannot be authorized in AD DS. Please make sure that the DHCP server is a domain member and try to ping the domain controller on the DHCP server.
    Best regards,
    Susie

  • DNS server Error, it says I have no DNS Servers

    DNS server Error, it says I have no DNS Servers

    We cannot help you with that amount of info..
    It says you have no DNS servers on what??
    I presume it is an apple router. What one?? What firmware?
    Plugged into what modem? Is the modem also a router? What mode is the airport in?
    If you changed your network around and have a cable modem. Did you power cycle it for at least 20min.. this is necessary.
    If you want us to help you full disclosure of the whole network.. impossible to answer without.

  • Osx lion dns server, forward certain domain searches to other dns server

    Hi!
    i'm configuring the DNS service in OSX 10.7.1. I want to forward all queries to certain domain (f.e. *.special_domain.com) to certain dns server (f.e. 192.168.0.1 & 2)
    i remember in previous OSX Server versions that you can do that in an easy way:
    there were a /etc/resolver directory where you can place a text file in order to forward certain domain queries to certain dns server, like this:
    filename: /etc/resolver/special_domain.com
    content of this file:
    nameserver 192.168.0.1
    nameserver 192.168.0.2
    now in lion there is no such directory... someone knows how to do that??
    thanks for reading and regards!
    D

    i've just read about the "scutil" tool
    From the reply of the command "scutil --dns" i understand that is possible and also supported (i guess)
    Now i have to discover what files that tool reads, and which is the proper way to modify that
    I'll keep investigating tomorrot, now i'm saved by the bell!!

  • Java 1.5.0_04 and ISA server

    i dont have any programming knowledge , but can you tell me if ISA server supports the use of the drag and drop facility in the version stated abovePlease no techy stuff it will go in one ear and out the other.

    "Agreed. This doesn't sound like it has anything to do with Java. Try to find a Microsoft (ISA) forum and ask there. Good luck."
    do you know of a link that i could see relating to ISA forums, so i can ask my question there.
    I too will suggest to them to try other servers. I asked a friend what reverting back to an old version of java would do. And they said it wouldnt solve the problem, but you would just need to copy and paste instead of having a drag n drop facility.
    My ex boyfriend use to about java all the time so i kind of know what you guys are on about.
    I guess my choices are:
    test it on another server;
    see to what extent ISA support java applets.
    try another port??? how do i do that?
    the obvious one ask in an ISA forum

  • BUG? ORA-01461 in Unit Tester when saving a long Dynamic Value Query

    I get an ORA-01461 "can bind a LONG value only for insert into a LONG column" error when saving a Test Implementation with a Dynamic Value Query whose length of the SQL statement is roughly 2,000 characters - I'm UNIONing ALL about 30 test case values together, but it seems to be choking on such a long SQL string for some reason....
    I am running version Early Adopter Release #2 (2.1.0.63), build MAIN-63.10.
    Thoughts?

    Confirmed.
    Bug 9119144: ORA-01461 IN UNIT TESTER WHEN SAVING A LONG DYNAMIC VALUE QUERY (OR OTHER CLOB)
    Brian Jeffries
    SQL Developer Team

  • ISA Server 2006 DNS error issue

    we are using ISA server 2006, and we are facing issue DNS Clients services, we need to restart its DNS client services in 10min or 15mins, 1st error event ID is 8003, Sources :-MRxSmb and 2nd event ID 11160, Source:- DNSApi.

    Hi,
    By default, ISA Server is configured to log requests that come through the Web Proxy Service. You can check by opening
    the ISA Management MMC and choosing Monitoring Configuration, and then clicking Logs. In addition,
    all log files are stored in the ISALogs folder found in the Microsoft ISA Server folder if you never specify the folder for storing the log file.
    You can check the IAS log files for troubleshooting since it is hard to say which would be the reason.
    Best regards,
    Susie

  • Authenticating via Microsoft ISA Server using Integrated protocol

    *** Cross-posted in Advanced Language Topics forum ***
    Does anyone know how to configure a URLConnection object to authenticate via a Microsoft ISA Server using the Integrated protocol?
    Authenticating using the Basic protocol is easy:
    URLConnection conn = <whatever>;
    String username = <whatever>;
    String password = <whatever>;
    String auth = username + ":" + password;
    String encodedAuth = new BASE64Encoder().encode(auth.getBytes());
    conn.setRequestProperty("Proxy-Authorization", "Basic " + encodedAuth);Does anyone know what to change to authenticate with the Integrated protocol?
    Thanks,
    Shaun

    Just visiting...
    Shaun

  • Why rowid has been used in the below query? What does it do

    SELECT BANK_CODE,COUNTRY_CODE,CITY_CODE,BANK_TYPE FROM TL_BANK WHERE rowid=(select rowid from TL_BANK
    where BANK_CODE||COUNTRY_CODE||CITY_CODE ='10377244910CNSHA' AND ACTION_FLAG ='D')

    Arun Kr Gupta wrote:
    You can change query to
    SELECT BANK_CODE,COUNTRY_CODE,CITY_CODE,BANK_TYPE
    FROM TL_BANK
    WHERE BANK_CODE||COUNTRY_CODE||CITY_CODE ='10377244910CNSHA'
    AND ACTION_FLAG ='D' ;Regards
    ArunI think that you'd do better changing it to something like:
    SELECT
      BANK_CODE,
      COUNTRY_CODE,
      CITY_CODE,
      BANK_TYPE
    FROM
      TL_BANK
    WHERE
      BANK_CODE = ... AND
      COUNTRY_CODE = ... AND
      CITY_CODE = ... AND
      ACTION_FLAG ='D' ;And then fire the person who wrote the orginal query.

  • Script to Change DNS Servers on Remote Server

    I am new to powershell and I am trying to construct a script to change the DNS servers settings on a whole list of machines remotely. I have the list of machines that I want to change in a txt file. I have read several posts on this and tried several different
    methods but I cannot seem to get it to work. Here is my code, any help is much appreciated.
    $servers = Get-Content C:\PathToFile\computers.txt
    foreach($server in $servers)
        Write-Host "Connect to $server..."
        $nics = Get-WmiObject Win32_NetworkAdapterConfiguration -ComputerName $server -ErrorAction Inquire | Where{$_.IPEnabled -eq "TRUE"}
        $newDNS = "10.1.1.1","10.2.2.2"
        foreach($nic in $nics)
            Write-Host "`tExisting DNS Servers " $nic.DNSServerSearchOrder
            $x = $nic.SetDNSServerSearchOrder($newDNS)
            if($x.ReturnValue -eq 0)
                Write-Host "`tSuccessfully Changed DNS Servers on " $server
            else
                Write-Host "`tFailed to Change DNS Servers on " $server

    http://blogs.technet.com/b/heyscriptingguy/archive/2012/02/28/use-powershell-to-configure-static-ip-and-dns-settings.aspx
    Ed Wilsons Blog.
    $computer = Get-Content C:\PathToFile\computers.txt
    $wmi = Get-WmiObject win32_networkadapterconfiguration  -computername "$computer" -filter "ipenabled = 'true'"
    $wmi.SetDNSServerSearchOrder("10.0.0.15", "255.255.255.0")
    I dont have the feasibility to check as of now. Please test and let me know.
    Thanks
    Azam
    Mark As an Answer if it answered your question or helpful if helped.

  • How do you setup a server to use multiple DNS servers that are not connect to each other?

    Is there a way to setup a server that connects to two different domains to use the proper DNS server for name resolution?
    Let say there are two DCs: serverA.subdomaina.domain.com and serverB.subdoamainb.domain.com.  The domains are independent and not connected.  Now you need a common server that is connected to both and need to resolve names from both
    domains.
    Is this possible?
    I have setup a server in a workgroup.  One NIC has the subdomaina.domain.com connection specific suffix and the other nic has the subdomainb.domain.com.  Each NIC has the DNS server listed for the domain it is connected to.
    This configuration will resolve FQDNs of one domain but not the other.  This I believe is due to the fact the server only querys one DNS server and doesn't try the other DNS server.
    Is there any way to make the server try another DNS server, if the first one doesn't have the entry?

    Hi,
    Thank you for posting in Windows Server Forum.
    Here adding to the words of “Tim”, a forwarder is a DNS server on a network used to forward DNS queries for external DNS names to DNS servers outside of that network. You can also forward queries according to specific domain names using conditional forwarders.
    A DNS server on a network is designated as a forwarder by having the other DNS servers in the network forward the queries they cannot resolve locally to that DNS server. You can refer information regarding forwarders and how to configure from beneath link.
    Understanding forwarders
    http://technet.microsoft.com/en-us/library/cc782142(v=ws.10).aspx
    Configure a DNS Server to Use Forwarders
    http://technet.microsoft.com/en-us/library/cc754941.aspx
    Hope it helps!
    Regards.

  • Oracle Test Manager or Other Third party Test management Tools

    Hi,
    Can Open Script be integrated with OTM or any other Test Management Tools available in the market to run scripts from that Test management tool.
    Thanks

    Hi
    Yes when you create a test you can define it to be an OpenScript Test, then all you need to do is point it to the script, then you can play them from OTM and also schedule them.
    Regards
    Alex

  • Cleanup of ISA rules in ISA server 2004 and 2006

    Hi Team
    how could i know, which rules are actively working and which rules are not being used in ISA server 2004 and 2006 . based on this we are going to disable the rule initially and delete the rules which is currently not being used in later stage. since we have
    lot rules in ISA , we need to segregate this 
    Could you please able to help me

    Hi,
    Please check the Creating Custom Reports parts in the following blog to see whether it can help you.
    Logging and Reporting in ISA Server 2006
    http://www.isaserver.org/articles-tutorials/configuration-general/Logging-Reporting-ISA-Server-2006.html
    Note:
    Microsoft provides third-party contact information to help you find technical support. This contact information may change without notice. Microsoft does not guarantee the accuracy of this third-party contact information.
    Best Regards,
    Joyce

  • In JDBC Sender Adapter , the server is Microsoft SQL .I need to pass current date as the input column while Executing stored procedure, which will get me 10 Output Columns. Kindly suggest me the SQL Query String

    In JDBC Sender Adapter , the server is Microsoft SQL .I need to pass current date as the input column while Executing stored procedure, which will get me 10 Output Columns. Kindly suggest me the SQL Query String , for executing the Stored Procedure with Current date as the input .

    Hi Srinath,
    The below blog might be useful
    http://scn.sap.com/community/pi-and-soa-middleware/blog/2013/03/06/executing-stored-procedure-from-sender-adapter-in-sap-pi-71
    PI/XI: Sender JDBC adapter for Oracle stored procedures in 5 days
    regards,
    Harish

Maybe you are looking for