- Remove From My Forums
Дополнительный ДНС сервер не выполняет рекурсивные запросы
-
Вопрос
-
Имеется 2 контроллера домена с интегрированной в AD ролью ДНС сервера в обоих КД.
проблема: На втором КД не работает как должна служба ДНС. Сервера пересылки (провайдерские) не отвечают, сервера корневых ссылок также с крестиками. На первом КД с ролью PDC все ОК. Также пробовал делать тест на закладке наблюдение :
«простой запрос к этому ДНС серверу» тест проходит, а «рекурсивный запрос к другим ДНС» — отказ! Рекурсию не отключали, только в попытках исправить выключали, потом включали — не помогло. Пинги ко всему
есть: и провайдеру, и к корневым, и к первому КД. Репликация м/ду КД (репадмин /шоурепл) всё успешно! Разве что объекты GC реплицируются а зоны ДНС не хотят?
Много было прочитано, но так и не понятно, что делать….
Привожу ниже инфу. Настройки которые сейчас, были не такими при поднятии второго КД. На обоих КД ДНС сервера были: первый — айпи это свой, а второй — айпи соседнего, сейчас по другому…. Может из-за этого сразу неправильно зоны создались?…..Интернет подключен через компьютер-шлюз 192.168.18.1, через который выходят в интернет из других подсетей без КД (192.168.19.0, 192.168.20.0), для этого были настроены дополнительные адреса на том же физическом сетевом
интефейсе….-
Изменено
28 сентября 2014 г. 17:04
-
Изменено
Ответы
-
фаервол на шлюзе не пропускал именно 192.168.18.253. каким-то чудесным образом там появилось правило такое. ну отключением правила удалось все решить.
Про репликацию зон: не плохо..))) а проверки то все прошли кроме Forw. Удалось найти в логах что от Dcom, что не удалось подключиться. бедный ДНС был совсем не причем.
Насчет первый айпи это свой, а второй соседнего — это придумки, которые можно применять как бы. Но есть главные рекомендации, которые всегда изначально оставались: первый — соседнего, второй — петлевой.
Их применяют как бест практис-
Помечено в качестве ответа
Vector BCO
16 августа 2016 г. 6:49
-
Помечено в качестве ответа
We are troubleshooting a DNS related issue and it is specific to a internet domain (electionsmunicipales.gouv.qc.ca). I run NSLOOKUP electionsmunicipales.gouv.qc.ca and it returned DNS request timed out error. But it was able to resolve it if
I set default server to google DNS server(8.8.4.4) . I found our DNS server cached a list of NS records (name servers )for this domain. Then I picked up one of the name server in list (ns-1640.awsdns-13.co.uk) run NSLOOKUP
D2 against electionsmunicipales.gouv.qc.ca and it returned following results (truncated answer,connect failed: Result too large ,SendRequest failed). Can anyone tell what the results means and how to fix it or further troubleshooting?
Thanks in advance !
Default Server: ns-1640.awsdns-13.co.uk
Address: 205.251.198.104
> electionsmunicipales.gouv.qc.ca
Server: ns-1640.awsdns-13.co.uk
Address: 205.251.198.104
————
SendRequest(), len 65
HEADER:
opcode = QUERY, id = 35, rcode = NOERROR
header flags: query, want recursion
questions = 1, answers = 0, authority records = 0, additional = 0
QUESTIONS:
electionsmunicipales.gouv.qc.ca.xxx.com, type = A, class = IN
————
————
Got answer (65 bytes):
HEADER:
opcode = QUERY, id = 35, rcode = REFUSED
header flags: response, want recursion
questions = 1, answers = 0, authority records = 0, additional = 0
QUESTIONS:
electionsmunicipales.gouv.qc.ca.XXX.com, type = A, class = IN
————
————
SendRequest(), len 65
HEADER:
opcode = QUERY, id = 36, rcode = NOERROR
header flags: query, want recursion
questions = 1, answers = 0, authority records = 0, additional = 0
QUESTIONS:
electionsmunicipales.gouv.qc.ca.XXX.com, type = AAAA, class = IN
————
————
Got answer (65 bytes):
HEADER:
opcode = QUERY, id = 36, rcode = REFUSED
header flags: response, want recursion
questions = 1, answers = 0, authority records = 0, additional = 0
QUESTIONS:
electionsmunicipales.gouv.qc.ca.XXX.com, type = AAAA, class = IN
————
————
SendRequest(), len 49
HEADER:
opcode = QUERY, id = 37, rcode = NOERROR
header flags: query, want recursion
questions = 1, answers = 0, authority records = 0, additional = 0
QUESTIONS:
electionsmunicipales.gouv.qc.ca, type = A, class = IN
————
truncated answer
connect failed: Result too large
SendRequest failed
————
SendRequest(), len 49
HEADER:
opcode = QUERY, id = 38, rcode = NOERROR
header flags: query, want recursion
questions = 1, answers = 0, authority records = 0, additional = 0
QUESTIONS:
electionsmunicipales.gouv.qc.ca, type = AAAA, class = IN
————
————
Got answer (136 bytes):
HEADER:
opcode = QUERY, id = 38, rcode = NOERROR
header flags: response, auth. answer, want recursion
questions = 1, answers = 0, authority records = 1, additional = 0
QUESTIONS:
electionsmunicipales.gouv.qc.ca, type = AAAA, class = IN
AUTHORITY RECORDS:
-> electionsmunicipales.gouv.qc.ca
type = SOA, class = IN, dlen = 75
ttl = 900 (15 mins)
primary name server = ns-1640.awsdns-13.co.uk
responsible mail addr = awsdns-hostmaster.amazon.com
serial = 1
refresh = 7200 (2 hours)
retry = 900 (15 mins)
expire = 1209600 (14 days)
default TTL = 86400 (1 day)
————
*** ns-1640.awsdns-13.co.uk can’t find electionsmunicipales.gouv.qc.ca: Unspecified error
>
This posting is provided AS-IS with no warranties/guarantees and confers no rights.
We are troubleshooting a DNS related issue and it is specific to a internet domain (electionsmunicipales.gouv.qc.ca). I run NSLOOKUP electionsmunicipales.gouv.qc.ca and it returned DNS request timed out error. But it was able to resolve it if
I set default server to google DNS server(8.8.4.4) . I found our DNS server cached a list of NS records (name servers )for this domain. Then I picked up one of the name server in list (ns-1640.awsdns-13.co.uk) run NSLOOKUP
D2 against electionsmunicipales.gouv.qc.ca and it returned following results (truncated answer,connect failed: Result too large ,SendRequest failed). Can anyone tell what the results means and how to fix it or further troubleshooting?
Thanks in advance !
Default Server: ns-1640.awsdns-13.co.uk
Address: 205.251.198.104
> electionsmunicipales.gouv.qc.ca
Server: ns-1640.awsdns-13.co.uk
Address: 205.251.198.104
————
SendRequest(), len 65
HEADER:
opcode = QUERY, id = 35, rcode = NOERROR
header flags: query, want recursion
questions = 1, answers = 0, authority records = 0, additional = 0
QUESTIONS:
electionsmunicipales.gouv.qc.ca.xxx.com, type = A, class = IN
————
————
Got answer (65 bytes):
HEADER:
opcode = QUERY, id = 35, rcode = REFUSED
header flags: response, want recursion
questions = 1, answers = 0, authority records = 0, additional = 0
QUESTIONS:
electionsmunicipales.gouv.qc.ca.XXX.com, type = A, class = IN
————
————
SendRequest(), len 65
HEADER:
opcode = QUERY, id = 36, rcode = NOERROR
header flags: query, want recursion
questions = 1, answers = 0, authority records = 0, additional = 0
QUESTIONS:
electionsmunicipales.gouv.qc.ca.XXX.com, type = AAAA, class = IN
————
————
Got answer (65 bytes):
HEADER:
opcode = QUERY, id = 36, rcode = REFUSED
header flags: response, want recursion
questions = 1, answers = 0, authority records = 0, additional = 0
QUESTIONS:
electionsmunicipales.gouv.qc.ca.XXX.com, type = AAAA, class = IN
————
————
SendRequest(), len 49
HEADER:
opcode = QUERY, id = 37, rcode = NOERROR
header flags: query, want recursion
questions = 1, answers = 0, authority records = 0, additional = 0
QUESTIONS:
electionsmunicipales.gouv.qc.ca, type = A, class = IN
————
truncated answer
connect failed: Result too large
SendRequest failed
————
SendRequest(), len 49
HEADER:
opcode = QUERY, id = 38, rcode = NOERROR
header flags: query, want recursion
questions = 1, answers = 0, authority records = 0, additional = 0
QUESTIONS:
electionsmunicipales.gouv.qc.ca, type = AAAA, class = IN
————
————
Got answer (136 bytes):
HEADER:
opcode = QUERY, id = 38, rcode = NOERROR
header flags: response, auth. answer, want recursion
questions = 1, answers = 0, authority records = 1, additional = 0
QUESTIONS:
electionsmunicipales.gouv.qc.ca, type = AAAA, class = IN
AUTHORITY RECORDS:
-> electionsmunicipales.gouv.qc.ca
type = SOA, class = IN, dlen = 75
ttl = 900 (15 mins)
primary name server = ns-1640.awsdns-13.co.uk
responsible mail addr = awsdns-hostmaster.amazon.com
serial = 1
refresh = 7200 (2 hours)
retry = 900 (15 mins)
expire = 1209600 (14 days)
default TTL = 86400 (1 day)
————
*** ns-1640.awsdns-13.co.uk can’t find electionsmunicipales.gouv.qc.ca: Unspecified error
>
This posting is provided AS-IS with no warranties/guarantees and confers no rights.
- Remove From My Forums
-
Question
-
Recursive query test on Domain Controller to external name servers fails, and yet NSLOOKUP queries are ok.
Our main DC (which holds all FSMO roles) is configured to use AT&T name servers (our ISP) for external queries (forwarders) and we have no obvious connectivity problems on our network at the moment. Except that this test is failing and I am concerned
that there is an underlying problem.Running NSLOOKUP on this DC works fine and I can query the AT&T name servers for any public lookup request. This shows that outbound internet access is unimpeded: servers have a perimeter firewall rule to allow all outbound access.
The only other sign of a DNS problem is that that DC doesn’t seem to ‘know itself’! running NSLOOKUP gives the following result and it shows
Server: unknown.Thanks in advance!
Answers
-
Yes, I can see that the reply is an IPV6 reply, but I cannot simply disable IPV6 for 2 reasons…
1) It is not recommended according to this article
https://support.microsoft.com/en-us/kb/9298522) I will need it for enabling DirectAccess.
In the binding order for the network cards, IPV4 is set to be higher than IPV6, but still it does not prioritize IPV4.
Changing the binding order on the stack will not help as unchecking IPv6 from the stack is not recommendedsupported.
However in your case an IPv6 DNS server address is specified which is ::1 (loopback)
You will simply need to select the option to obtain the IPv6 DNS server address automatically.
If you want to give precedence to Ipv4 over Ipv6 you will need to do the following:
In Registry Editor, locate and then click the following registry subkey:
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesTcpip6Parameters
Double-click DisabledComponents to change the DisabledComponents entry.If the DisabledComponents entry is unavailable, you must create it. To do this, follow these steps: a. In the Edit menu, point to New, and then click DWORD (32-bit) Value.
b. Type DisabledComponents, and then press Enter.
c. Double-click DisabledComponents.Type 0x20 to prefer IPv4 over IPv6 by changing entries in the prefix policy table.
-
Proposed as answer by
Wednesday, July 22, 2015 2:14 PM
-
Marked as answer by
Leo Han
Wednesday, July 29, 2015 9:22 AM
-
Proposed as answer by
-
No a reboot is not required.
You will only need to check «obtain DNS server automatically» under Ipv6
Click OK and then try nslookup again.
M:>nslookup www.ibm.com
Server: xxxxxxx.xxxxxx.com
Address: 10.130.162.31Non-authoritative answer:
Name: e2898.x.akamaiedge.net
Address: 23.64.123.219
Aliases: www.ibm.com
www.ibm.com.cs186.net
global.ibm.com.edgekey.net
global.ibm.com.edgekey.net.globalredir.akadns.net-
Proposed as answer by
Roy (MSFT)
Wednesday, July 22, 2015 4:15 PM -
Marked as answer by
Leo Han
Wednesday, July 29, 2015 9:22 AM
-
Proposed as answer by
-
When you click test now for recursive queries, a name resolution request to resolve a root hint server is sent to the forwarder configured on the DNS server.
In your case, the AT&T name server (under DNS server forwarder) is not able to resolve the root hint server and hence the query fails.
When you enable root-hint name resolution, the query is forwarded to the root-hint server after the forwarder fails to resolve it and hence you get a successful response.
To test, please remove the AT&T forwarder from the DNS server forwarder and test with 8.8.8.8
The behavior can be verified by taking a network monitor trace when trying to perform the test.
Hope the explanation makes sense
-
Proposed as answer by
Roy (MSFT)
Wednesday, July 22, 2015 4:15 PM -
Marked as answer by
Leo Han
Wednesday, July 29, 2015 9:22 AM
-
Proposed as answer by
- Remove From My Forums
-
Question
-
Recursive query test on Domain Controller to external name servers fails, and yet NSLOOKUP queries are ok.
Our main DC (which holds all FSMO roles) is configured to use AT&T name servers (our ISP) for external queries (forwarders) and we have no obvious connectivity problems on our network at the moment. Except that this test is failing and I am concerned
that there is an underlying problem.Running NSLOOKUP on this DC works fine and I can query the AT&T name servers for any public lookup request. This shows that outbound internet access is unimpeded: servers have a perimeter firewall rule to allow all outbound access.
The only other sign of a DNS problem is that that DC doesn’t seem to ‘know itself’! running NSLOOKUP gives the following result and it shows
Server: unknown.Thanks in advance!
Answers
-
Yes, I can see that the reply is an IPV6 reply, but I cannot simply disable IPV6 for 2 reasons…
1) It is not recommended according to this article
https://support.microsoft.com/en-us/kb/9298522) I will need it for enabling DirectAccess.
In the binding order for the network cards, IPV4 is set to be higher than IPV6, but still it does not prioritize IPV4.
Changing the binding order on the stack will not help as unchecking IPv6 from the stack is not recommendedsupported.
However in your case an IPv6 DNS server address is specified which is ::1 (loopback)
You will simply need to select the option to obtain the IPv6 DNS server address automatically.
If you want to give precedence to Ipv4 over Ipv6 you will need to do the following:
In Registry Editor, locate and then click the following registry subkey:
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesTcpip6Parameters
Double-click DisabledComponents to change the DisabledComponents entry.If the DisabledComponents entry is unavailable, you must create it. To do this, follow these steps: a. In the Edit menu, point to New, and then click DWORD (32-bit) Value.
b. Type DisabledComponents, and then press Enter.
c. Double-click DisabledComponents.Type 0x20 to prefer IPv4 over IPv6 by changing entries in the prefix policy table.
-
Proposed as answer by
Wednesday, July 22, 2015 2:14 PM
-
Marked as answer by
Leo Han
Wednesday, July 29, 2015 9:22 AM
-
Proposed as answer by
-
No a reboot is not required.
You will only need to check «obtain DNS server automatically» under Ipv6
Click OK and then try nslookup again.
M:>nslookup www.ibm.com
Server: xxxxxxx.xxxxxx.com
Address: 10.130.162.31Non-authoritative answer:
Name: e2898.x.akamaiedge.net
Address: 23.64.123.219
Aliases: www.ibm.com
www.ibm.com.cs186.net
global.ibm.com.edgekey.net
global.ibm.com.edgekey.net.globalredir.akadns.net-
Proposed as answer by
Roy (MSFT)
Wednesday, July 22, 2015 4:15 PM -
Marked as answer by
Leo Han
Wednesday, July 29, 2015 9:22 AM
-
Proposed as answer by
-
When you click test now for recursive queries, a name resolution request to resolve a root hint server is sent to the forwarder configured on the DNS server.
In your case, the AT&T name server (under DNS server forwarder) is not able to resolve the root hint server and hence the query fails.
When you enable root-hint name resolution, the query is forwarded to the root-hint server after the forwarder fails to resolve it and hence you get a successful response.
To test, please remove the AT&T forwarder from the DNS server forwarder and test with 8.8.8.8
The behavior can be verified by taking a network monitor trace when trying to perform the test.
Hope the explanation makes sense
-
Proposed as answer by
Roy (MSFT)
Wednesday, July 22, 2015 4:15 PM -
Marked as answer by
Leo Han
Wednesday, July 29, 2015 9:22 AM
-
Proposed as answer by
Обновлено 29.03.2019

Добрый день уважаемые читатели и подписчики канала, вы наверняка знаете, что работа всего интернета, по мимо маршрутизации трафика, зависит от DNS имен в ip адреса и обратно, и за это отвечают DNS сервера, работа которых должна быть беспрерывна. Бывают случаи, что случаются аварии, в результате которых у вас начинаются проблемы с доступом в интернет и причиной всему ДНС сервера, сегодня я вам расскажу про ошибку: DNS request timed out.
Симптомы ошибки
Ситуация такова, у пользователей перестал работать интернет, при попытке сделать ping google.com, в ответ выдалось сообщение, что данное имя не удается разрешить, если попытаться пропинговать 8.8.8.8, это публичные ДНС сервера Google, то пинг нормально шел, из чего можно сделать вывод, что есть проблемы с рекурсией DNS серверов. Для диагностики ДНС служб используется утилита nslookup, позволяющая выполнить запрос. Для примера я попытался разрешить имя mail.ru
В итоге я получил ошибку DNS request timed out. Превышено время ожидания запроса.
Исправляем ошибку: Превышено время ожидания запроса
Как я и писал выше существует три причины ошибки DNS request timed out:
- Не доступны рекурсивные сервера провайдера или публичные ДНС
- Не доступен основной шлюз на ДНС сервере
- Закрыты порты или требуется авторизация на прокси сервере.
Проверяем рекурсивные сервера
Первое с чего нужно начать это проверить работоспособность рекурсивных серверов, на WIndows Server 2012 R2 это делается в оснастке «Диспетчер DNS», выбираете имя сервера и щелкаете правым кликом, из контекстного меню выбираем свойства.

Переходим на вкладку «Сервер пересылки» и проверяем, чтобы добавленные адреса, нормально разрешались и не было предупреждений.

Для пущей уверенности нажмите кнопку изменить и удостоверьтесь, что в окне «Редактировать серверы пересылки» все зеленое. Если там не удается разрешить имена, то переходим к другим пунктам.

Проверка шлюза
После проверки рекурсии у вас может остаться ошибка DNS request timed out и связанна с неправильным шлюзом или ваш шлюз просто не доступен. Во первых откройте окно свойств TCP/IP через оснастку ncpa.cpl либо можно через командную строку и команду ipconfig /all.

Удостоверьтесь, что данный шлюз правильный и если да, то чтобы он был доступен с данного сервера. Далее обязательно посмотрите трассировку трафика и убедитесь, что идет через нужный шлюз, если нет, то убедитесь, что нет статических маршрутов, которые перекрывают метрикой ваш основной шлюз. Если ошибка DNS request timed out сохраняется, то у вас сто процентов закрыты порты на вашем прокси сервере или брандмауэре, убедитесь, что доступен порт 53.
Авторизация на прокси сервере
В моем случае оказалось, что был не доступен шлюз и еще сбросилась сессия на прокси сервере, после того как я на своем фаерволе Kerio Control авторизовал свои ДНС сервера у меня пропала ошибка DNS request timed out, при разрешении имен.
|
1 / 1 / 0 Регистрация: 25.12.2012 Сообщений: 89 |
|
|
1 |
|
|
Server 2008 01.03.2016, 16:54. Показов 4791. Ответов 9
Поднял сервер на Windows 2012 r2, установил компоненты DHCP, DNS, AD.
__________________
0 |
|
1882 / 1106 / 426 Регистрация: 22.01.2016 Сообщений: 3,050 |
|
|
01.03.2016, 17:09 |
2 |
|
Но когда я делаю рекурсивный запрос к другим dns-серверам, то я получаю отказ К каким другим — внутренним, внешним, корневым? Как точно выглядит ошибка?
0 |
|
1 / 1 / 0 Регистрация: 25.12.2012 Сообщений: 89 |
|
|
01.03.2016, 17:15 [ТС] |
3 |
|
Я немного неправильно описал проблему из-за глюка клавиатуры.
0 |
|
1882 / 1106 / 426 Регистрация: 22.01.2016 Сообщений: 3,050 |
|
|
01.03.2016, 18:31 |
4 |
|
Я пытаюсь поставить почтовый сервер (MailEnable) На тот же сервер, где AD и DNS или на другой?
при выборе домена автоматически определяется мой домен, но ip адрес 127.0.0.1 А в какой именно настройке вы указываете свой домен? И для чего — имя почтового домена сопоставляется с каким-то IP?
0 |
|
1 / 1 / 0 Регистрация: 25.12.2012 Сообщений: 89 |
|
|
01.03.2016, 18:53 [ТС] |
5 |
|
Сообщение от Dante4001 Да, на тот же сервер. Я бы с радостью выделил отдельный сервер, но по заданию всё находится на одном сервере
Сообщение от Dante4001 На скриншоте из видео инструкции показано Миниатюры
0 |
|
1882 / 1106 / 426 Регистрация: 22.01.2016 Сообщений: 3,050 |
|
|
01.03.2016, 19:04 |
6 |
|
На скриншоте из видео инструкции показано Теперь понятно, здесь задаётся IP DNS-сервера, который будет использоваться для поиска mx-серверов получателей. Вы ставите MailEnable на DC+DNS, а он как раз сам себе dns — 127.0.0.1 — посмотрите (ipconfig /all). Вот поэтому этот IP автоматом и подставляется. Можете здесь руками прописать IP вашего DC (если он умеет разрешать внешние имена) или указать любой другой (или несколько) DNS-сервер, например 8.8.8.8, но только если есть к нему доступ.
0 |
|
1 / 1 / 0 Регистрация: 25.12.2012 Сообщений: 89 |
|
|
01.03.2016, 20:35 [ТС] |
7 |
|
Вот сейчас чисто ради эксперимента решил всё по новой настроить. Миниатюры
0 |
|
1882 / 1106 / 426 Регистрация: 22.01.2016 Сообщений: 3,050 |
|
|
01.03.2016, 23:02 |
8 |
|
Если делать nslookup через диспетчер DNS, то вроде бы и всё нормально, но если делать nslookup через командную строку то уже видно, что что-то неладно Покажите: ipconfig /all И настойки самого DNS-сервера — вкладки «Интерфейсы», «Сервер пересылки», «Дополнительно»
0 |
|
1 / 1 / 0 Регистрация: 25.12.2012 Сообщений: 89 |
|
|
02.03.2016, 04:28 [ТС] |
9 |
|
Пожалуйста
0 |
|
1882 / 1106 / 426 Регистрация: 22.01.2016 Сообщений: 3,050 |
|
|
02.03.2016, 18:01 |
10 |
|
Пожалуйста Смущает, что все сервера пересылки указаны в виде IPv6 + на самом DC — IP первичного dns в v6-формате. У вас настроена и работает IPv6 сеть? Если нет, то замените все эти IP на v4 и отключите IPv6-протокол на DC
0 |
|
IT_Exp Эксперт 87844 / 49110 / 22898 Регистрация: 17.06.2006 Сообщений: 92,604 |
02.03.2016, 18:01 |
|
10 |
