Re: Win2k Ras/VPN and a SCO Unix Machine and some difficulty getting to the SCO Machine [LONG]



In article <VA.000012c0.01ce9bea@xxxxxxxxxxxxxxxxxxxxx>,
Brian Keener <bkeener@xxxxxxxxxxxxxxxxxxxxx> wrote:
Bill Vermillion wrote:
All of my comments will be SWAGs as it's sort of hard to envision
everything. I'm a hands on type person :-)

I understand completely - SWAG's are perfectly acceptable and it
is hard to picture - I've seen it several times and still had to
get them to confirm a couple things for me even though I had it
diagramed notes. And its real hard to explain visually.

[ huge hunks deleted - wjv]


Why is the W2K machine using itself for DNS and not the .254
address as all other machines are. Could the DNS in the machines
not be consitant. That could cause problems.

That was one of my concerns as well and with the way they are
cabled and to be on the same subnet and then one is supposed to
be a WAN and one a LAN connection they really blow my mind.

I've seen some bizarre things too. But everything is working at
times - so the cabling should be OK.

I run a pair of name-servers for a small ISP. On my machine I use
to access the net I put those in first position in the resolver
files. I trust them. But I also have 4 other DNS machines
in there, so I can just comment out mine to test with others.
I've also been known to ssh into a client machine to check.

When someone has a connectivity problem I'll perform lookups
through my servers, Sprint/Earthlink servers, and one client's
RoadRunner servers.

I've found inconsistancies among them - such as some not being
updated correctly - and others being reachable through one
connection and not another. So that's why I suggest
one DNS.

When you have problems why not perform a lookup using first one
server, and then use the other DNS server.

I also am conservative on my name servers - even though one is
listed as a secondary I really have two primaries.

I do this so that when I add or change things, I can restart one
and make sure things are OK, and then I'll just send the files to
the other machine. If I had the second as a secondary then any
error on the primary will get proagated to the secondary and then
nothing works.

This scenario has been seen when major tranport providers upgrade
their routers all at one time, and the entrie network falls over.

The ONLY time I had a problem was when one of our clients who had
about 1000 domains he was serving wanted a name added for a site
that had a European registrar - and when they tested they found
that my secondary was not a true secondary so they wouldn't point
to our DNS. Since the client was selling $9.95 sites he just
blew that one off.

...

I'd personally go for ONE DNS - so you can always check it's
integrity.

I can do that - I thought about doing it last time I was looking
at it but got cold feet. Their network does work although not as
well as it should

Depending on what you use to test with it's easy to point to
another NS. If you use a Unix system it's just a matter of
commenting out the nameserver line and trying again. Testing via
the MS way takes a bit more effort.

Bill

--
Bill Vermillion - bv @ wjv . com
.



Relevant Pages

  • Re: 1058 and 1030 errors revisited
    ... Are you sure about the symptoms ie when the11th or 12th user logs ... Does the issue occour only on some machines? ... We have four servers to ... There are about sixty client ...
    (microsoft.public.windows.group_policy)
  • Re: Logon problems after beginning AD migration
    ... the machines that are logging into the non-2003 ... BDCs to the DNS servers in the 2003 domain, ... It was barely adequate for 2003 server, so after I had a BDC in place, I tried to transfer the FSMO roles to the BDC so I could demote and reload it. ...
    (microsoft.public.win2000.active_directory)
  • Security Concerns with Windows DNS
    ... I am working in an environment where we manage hundreds of client servers in ... We currently use an old version of Cisco DNS, ... resource records are being accepted there, the servers do not successfully ... AD integration and dynamic updates to eliminate the windows error messages ...
    (microsoft.public.windows.server.dns)
  • Re: Losing network shares across multiple machines on Windows 2003
    ... Are you running a firewall on either the clients or the servers? ... while all other machines can continue to happily use the network. ... Network shares map to more than just one file server - ie, ... On the client, it just notes which activity failed - ie, ...
    (microsoft.public.windows.server.general)
  • Re: Network logins take too long!
    ... Have you been at one of these client machines when one of the longer delays ... if you have been changing the DNS configuration, ... "Domain Controller servers are two Dell PowerEdge2950 servers one with ...
    (microsoft.public.windows.server.active_directory)