Score:2

SBS 2011 DNS server doesn't resolve forward lookup zones

vn flag

I recently started a new job and inherited an antique in an SBS2011 server (yes, I know all the security risks and have raised this at EVERY management meeting). I have an issue with the DNS not resolving forward lookup zones.

The domain hosting emails use split DNS; the SBS should resolve this to the internal IP address, but not from any clients. The strange part is that from the SBS itself, the DNS is resolved correctly, but when doing nslookup from any internal machine, the DNS (using the SBS) resolves the external reverse proxy and not the internal address.

I have tried researching the heck out of this in the last few weeks/months (in my massive amounts of free time due to COVID lockdown) and have found nothing. nslookup is definitely using the SBS for lookup, and I have tried removing and re-adding the zones to no effect (yep, sanity check).

Also, the DHCP is provided by the firewall, not the SBS. I know AD likes to do the DHCP and this can affect reverse DNS, but I wouldn't have thought it would affect forward lookup zones ... am I mistaken?

I am all ears if anyone has had a similar situation or has suggestions (other than replacing the SBS ... I'm already working on that).

TIA Jim.

Jim D avatar
vn flag
nobody wants a stab at helping ... huh so it's not just me ... this is an od one :)
in flag
Do you have any fallback servers, or are you targeting the server in the nslookups so as to not have other servers respond? You will normally lockdown which clients will be able to do which kind of lookups. DHCP is unlikely, but did you verify routing and firewalls? What about wireshark/tcpdump?
mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.