• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Pages won't always load - DSN Server Problem?

Flapjack

2[H]4U
2FA
Joined
Apr 29, 2000
Messages
3,217
Hey everyone, I'm getting a "Problem loading page" in Firefox about 33-50% of the time I pull up a web page. I've tried IE, and I'm getting whatever the equivalent error message is as well. This happens on all computers on the network, so it would appear the DC is the culprit. Hitting "refresh" loads the page the 2nd time every time.

I suspect it's a DNS problem, but don't know what to do about it.

I'm running a home domain, and the load is incredibly light (usually only 1, max 2, computers accessing the net at any given time), so I'm fairly sure it's not the server itself being overloaded.

The home domain consists of a Win2k3 machine running DNS and acting as a domain controller. DHCP is handled by the router, but all the computers on the network have hardcoded IPs. I've also updated the firmware on the router just to be sure it wasn't it.

The only change I've made to DNS since I set the DC up this summer, was I removed my ISP's DNS server in regular TCP/IP properties and set it up as a forwarder. Before that, I was getting errors in the Event Viewer.

I don't know what else I can try, so if anyone has any suggestions, I'd appreciate it.

Oh yeah.... here's a screenshot:

DNS.jpg
 
So you think it's an issue with the Adelphia DNS server, not my DNS server?

I'll try them and see what happens.

Darthkim said:
Use different forwarding servers.
Personally I use these

4.2.2.2
4.2.2.3
 
Why not set your DNS server up so that it hits the root DNS servers directly? I believe WIn2k3 DNS does this by default. This way your DNS server will go up to the root and get the answer itself intsead of waiting for your ISP's lame DNS server to do it for you.

I have Win2k3 server running DNS and DHCP for me. All my DNS queries go through this box, which in turn goes to the root dns servers.

If you really want to find out what's going on, get a packet capture from your PC when the connection fails. If its 33-50% of the time that shouldn't be too difficult to get.
 
Just to check your TCP settings on the network, your DC is looking at itself (its own IP) as the one as only DNS server in TCP/IP properties, and your workstations are looking at your DCs IP as their one and only DNS server?

I usually setup networks where the DCs DNS service forwards to the ISPs 2x DNS servers. The theory here is that your ISPs DNS servers are only 1x hop away, hence quick response when your DCs DNS needs to go out and fetch something. However...as many here know, not all ISPs are created equal, some have crappy DNS servers. But overall, in my area, most ISPs are pretty solid.

I recently changed from a business DSL ISP at my house to Comcast...so I may be changing my tune there soon...and removing forwarding in my SBS box.

However ....I do note that I get timeout errors often on this forum ( several times a week), from where ever I am (several states per week, hence several ISPs), so I assume the VBulletin box acts up a bit and this error is normal.
 
So far, Darthkim's suggestion seems to have done the trick. I'll have to give it a few days to be sure, though.

So you're saying I don't even need to set up a forwarder, and that it'll automatically hit the root servers if my DNS doesn't have the information?

When I say 33-50% of the time, I mean the web request will return that error only. If I click "go" again, it'll work just fine.

Arch said:
Why not set your DNS server up so that it hits the root DNS servers directly? I believe WIn2k3 DNS does this by default. This way your DNS server will go up to the root and get the answer itself intsead of waiting for your ISP's lame DNS server to do it for you.

I have Win2k3 server running DNS and DHCP for me. All my DNS queries go through this box, which in turn goes to the root dns servers.

If you really want to find out what's going on, get a packet capture from your PC when the connection fails. If its 33-50% of the time that shouldn't be too difficult to get.
 
Before now, I had the DC pointing to itself as the DNS server (as it's running DNS), and my local ISP (Adelphia cable) as a forwarder.

All the machines on my network only have the DC as the DNS server. It happens on all systems, though... to include the DC.

YeOldeStonecat said:
Just to check your TCP settings on the network, your DC is looking at itself (its own IP) as the one as only DNS server in TCP/IP properties, and your workstations are looking at your DCs IP as their one and only DNS server?

I usually setup networks where the DCs DNS service forwards to the ISPs 2x DNS servers. The theory here is that your ISPs DNS servers are only 1x hop away, hence quick response when your DCs DNS needs to go out and fetch something. However...as many here know, not all ISPs are created equal, some have crappy DNS servers. But overall, in my area, most ISPs are pretty solid.

I recently changed from a business DSL ISP at my house to Comcast...so I may be changing my tune there soon...and removing forwarding in my SBS box.

However ....I do note that I get timeout errors often on this forum ( several times a week), from where ever I am (several states per week, hence several ISPs), so I assume the VBulletin box acts up a bit and this error is normal.
 
Oh yeah, I'm also moving from Adelpha cable (6mb/s down, 768kb/s up) to Qwest DSL (7mb/s down, 896kb/s up) on Friday.

Hopefully their DNS servers will be better.
 
Darthkim said:
Use different forwarding servers.
Personally I use these

4.2.2.2
4.2.2.3
hahaha. I loved when those had reverse DNS of dont.steal.dns.gte.net
 
Wow, I'm using the clspco dns servers and I'm running caching with no problems. Check your zones. Then check for a flakey router.
 
Flapjack said:
Before now, I had the DC pointing to itself as the DNS server (as it's running DNS), and my local ISP (Adelphia cable) as a forwarder.

"Before now" ? Meaning now it's not? Then your active directory will be broken...server should always look at the DC (often itself) as it's one and only DNS server, when looking at TCP/IP properties. And WINS if you unfortunately have to run that service too.

Clicky click to see what I mean...

The only thing that IMO can vary in the guide I linked above...is the "forwarding"...as you do have the option of not forwarding your DNS to your ISPs DNS servers, but IMO, and from my experience with the ISPs in my area, it works fine.
 
while DNS is a good place to start, don't forget other things that could cause it, I had the same exact symptons caused at one of our locations due to a failing Adtran TSU Ace unit.
 
Flapjack said:
So far, Darthkim's suggestion seems to have done the trick. I'll have to give it a few days to be sure, though.

So you're saying I don't even need to set up a forwarder, and that it'll automatically hit the root servers if my DNS doesn't have the information?

When I say 33-50% of the time, I mean the web request will return that error only. If I click "go" again, it'll work just fine.

Yes, you are not required to have a forwarder. In Windows 2k3 server goto the DNS admin page. Select your server from the left hand side, right click on it and select properties. Remove anything in the forwarders tab. Check the root hints tab, it should be filled with addresses. If it is, your DNS will go right to the root DNS servers to get the answer, thereby getting you a much faster response time.

If you use a forwarder the request goes something like:
your pc--->your dns--->your isps dns--->root dns server

If you don't use a forwarder and let your dns server do its own query you get:
your pc--->your dns--->root dns server

I find that this yields me a much faster response time than using RoadRunner's DNS server. I spend a lot less time "looking up...." and more time browsing.
 
I look at it differently. Using your ISP's DNS as forwarders,
your PC==>Your DNS...if it's not cached locally, only 1x QUICK hop to your ISPs DNS which usually will have it cached. (quick hop because that DNS request doesn't leave your ISPs backbone) If not cached, (rare..unless you have a crappily managed ISP) it'll then go to the roots.

If you don't use forwarders,
your PC==>your dns==> long trip across several hops to the root DNS servers

Your ISPs DSN servers are usually inside of 3x hops from your homes router. Root DNS servers however...can usually be in the mid-teens as far as hops away. Think latency.

Arch said:
If you use a forwarder the request goes something like:
your pc--->your dns--->your isps dns--->root dns server

If you don't use a forwarder and let your dns server do its own query you get:
your pc--->your dns--->root dns server
 
Yes. "Before now" means I've removed the Adelphia information and put in the 4.2.2.2 and 4.2.2.3.

The problem seems to have gone away!

YeOldeStonecat said:
"Before now" ? Meaning now it's not? Then your active directory will be broken...server should always look at the DC (often itself) as it's one and only DNS server, when looking at TCP/IP properties. And WINS if you unfortunately have to run that service too.

Clicky click to see what I mean...

The only thing that IMO can vary in the guide I linked above...is the "forwarding"...as you do have the option of not forwarding your DNS to your ISPs DNS servers, but IMO, and from my experience with the ISPs in my area, it works fine.
 
Flapjack said:
Yes. "Before now" means I've removed the Adelphia information and put in the 4.2.2.2 and 4.2.2.3.

The problem seems to have gone away!

If that's what's in your TCP properties, then your AD will not be functioning correctly, you probably have an interesting event viewer also. Since it's a home network, you may or may not care about that....since you probably don't really use domain controller functionality much. But if you wish to learn to do it right.....
 
Well, all I know is I'm getting snappier resolving of webpages, and I'm not getting that error anymore. It may be a quick hop to the DNS server, but they're obviously having trouble managing my requests...

YeOldeStonecat said:
I look at it differently. Using your ISP's DNS as forwarders,
your PC==>Your DNS...if it's not cached locally, only 1x QUICK hop to your ISPs DNS which usually will have it cached. (quick hop because that DNS request doesn't leave your ISPs backbone) If not cached, (rare..unless you have a crappily managed ISP) it'll then go to the roots.

If you don't use forwarders,
your PC==>your dns==> long trip across several hops to the root DNS servers

Your ISPs DSN servers are usually inside of 3x hops from your homes router. Root DNS servers however...can usually be in the mid-teens as far as hops away. Think latency.
 
YeOldeStonecat said:
I look at it differently. Using your ISP's DNS as forwarders,
your PC==>Your DNS...if it's not cached locally, only 1x QUICK hop to your ISPs DNS which usually will have it cached. (quick hop because that DNS request doesn't leave your ISPs backbone) If not cached, (rare..unless you have a crappily managed ISP) it'll then go to the roots.

If you don't use forwarders,
your PC==>your dns==> long trip across several hops to the root DNS servers

Your ISPs DSN servers are usually inside of 3x hops from your homes router. Root DNS servers however...can usually be in the mid-teens as far as hops away. Think latency.

One would imagine this would be the case, unfortunately for RoadRunner here in Raleigh, North Carolina, it isn't. The performance of their DNS server is laughable. Sometimes taking 2-3 seconds to resolve a name. My DNS server resolves everything in under 500 ms.
 
Back
Top