Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > DNS Server > Zone transfers refused

Reply
Thread Tools Display Modes

Zone transfers refused

 
 
Pierre
Guest
Posts: n/a

 
      05-14-2009
Hi we are unable to do zone xfers between 2 different domains.

domain abc.com is ad integrated and under name servers i added 2 server from
domain efg.com - indicated allow zone xfers and notify for 'name servers'
only.

The failure occurs in domain efg.com - which is setup as a secondary copy of
domain abc.com.

Both DNS servers are running w2k3 std sp2.

not sure what is happening -event log do not indicate much.
 
Reply With Quote
 
 
 
 
Ace Fekay [Microsoft Certified Trainer]
Guest
Posts: n/a

 
      05-14-2009
"Pierre" <> wrote in message news:A9D00C15-6A72-4410-A0ED-...
> Hi we are unable to do zone xfers between 2 different domains.
>
> domain abc.com is ad integrated and under name servers i added 2 server from
> domain efg.com - indicated allow zone xfers and notify for 'name servers'
> only.
>
> The failure occurs in domain efg.com - which is setup as a secondary copy of
> domain abc.com.
>
> Both DNS servers are running w2k3 std sp2.
>
> not sure what is happening -event log do not indicate much.



Are zone transfers Allowed in the zone properties?


--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSA Messaging, MCT
Microsoft Certified Trainer


For urgent issues, you may want to contact Microsoft PSS directly. Please
check http://support.microsoft.com for regional support phone numbers.

"Efficiency is doing things right; effectiveness is doing the right things." - Peter F. Drucker
http://twitter.com/acefekay

 
Reply With Quote
 
Pierre
Guest
Posts: n/a

 
      05-15-2009
Yes read above -

"Ace Fekay [Microsoft Certified Trainer]" wrote:

> "Pierre" <> wrote in message news:A9D00C15-6A72-4410-A0ED-...
> > Hi we are unable to do zone xfers between 2 different domains.
> >
> > domain abc.com is ad integrated and under name servers i added 2 server from
> > domain efg.com - indicated allow zone xfers and notify for 'name servers'
> > only.
> >
> > The failure occurs in domain efg.com - which is setup as a secondary copy of
> > domain abc.com.
> >
> > Both DNS servers are running w2k3 std sp2.
> >
> > not sure what is happening -event log do not indicate much.

>
>
> Are zone transfers Allowed in the zone properties?
>
>
> --
> Ace
>
> This posting is provided "AS-IS" with no warranties or guarantees and
> confers no rights.
>
> Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSA Messaging, MCT
> Microsoft Certified Trainer
>
>
> For urgent issues, you may want to contact Microsoft PSS directly. Please
> check http://support.microsoft.com for regional support phone numbers.
>
> "Efficiency is doing things right; effectiveness is doing the right things." - Peter F. Drucker
> http://twitter.com/acefekay
>
>

 
Reply With Quote
 
Ace Fekay [Microsoft Certified Trainer]
Guest
Posts: n/a

 
      05-16-2009
"Pierre" <> wrote in message news:519CFEF5-A5EB-42B3-A9E2-...
> Yes read above -
>



Sorry, I misunderstood the post.

Ok, just to test it, if you allowed any for a zone transfer, does it work?

Ace
 
Reply With Quote
 
Pierre
Guest
Posts: n/a

 
      05-22-2009
The problem was zone trasnfers were begin done to a location whose IP was
being natted -the solution was to add that firewall's IP address to the Zone
transfer allowed IP's. That fixed the problem.

When doing captures the only IP that would show on belhalf of the remote
server was the firewall IP.

"Ace Fekay [Microsoft Certified Trainer]" wrote:

> "Pierre" <> wrote in message news:519CFEF5-A5EB-42B3-A9E2-...
> > Yes read above -
> >

>
>
> Sorry, I misunderstood the post.
>
> Ok, just to test it, if you allowed any for a zone transfer, does it work?
>
> Ace
>

 
Reply With Quote
 
Ace Fekay [Microsoft Certified Trainer]
Guest
Posts: n/a

 
      05-22-2009
"Pierre" <> wrote in message news:352852CE-B0C7-4EB0-A991-...
> The problem was zone trasnfers were begin done to a location whose IP was
> being natted -the solution was to add that firewall's IP address to the Zone
> transfer allowed IP's. That fixed the problem.
>
> When doing captures the only IP that would show on belhalf of the remote
> server was the firewall IP.
>


Thanks for posting the scenario and resolution. I assumed it was a non-NAT firewall, but yes, for NATs, you have to port remap requests from the WAN interface to the internal private IP.

Glad you figured it out!

Ace



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Zone Transfers Yorgy DNS Server 3 04-14-2009 07:59 PM
Zone Transfers over WAN Darrick West DNS Server 3 01-10-2008 10:31 PM
DNS Zone Transfers SK-TECH Active Directory 1 07-20-2007 02:50 AM
Zone transfers? George DNS Server 1 02-20-2007 11:50 AM
Zone Transfers Chad Guiney DNS Server 3 02-12-2007 10:10 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59