Local and ISP DNS

Hi all,
i have a local DNS server for some local stuff like website,ldap and so on and the normal ISP DNS.
On Client i have entered the local DNS IP (xxx.xxx.xxx.xxx) and the ISP DNS IP (yyy.yyy.yyy.yyy).
So here is my problem when the Local DNS IP is on top of the table i can surf only the local websites but not the public. vice versa is it for when i have the ISP DNS IP on top. what can i do to surf all website, the local and the public.

MacPro, Mac OS X (10.6)

Posted on Sep 10, 2009 1:23 PM

Reply
9 replies

Sep 10, 2009 2:05 PM in response to Robert23

DNS servers listed in clients are assumed to be peers or clones or as having the same contents, and are not ordered lists. More than one DNS server can be listed to clients on the off chance that one of your DNS servers are inaccessible. But it's not a "look for a DNS translation here, then look here, then look here" case. Select your own local DNS server(s) here as being the DNS server(s) supplied by your DHCP and by your clients (where the DNS server(s)s are locally set), and configure your local DNS server up to forward any requests for which it is not authoritative along to your ISP DNS, and ensure that your local DNS server can get its requests out through to the ISP DNS server. Done.

Sep 11, 2009 7:46 AM in response to Robert23

i get in the log of the dns so many error's like
lame server resolving xxxxxx.xxx.xxx : xxx.xxx.xxx.xxx#53
what does it mean, since i use my local dns server as main dns for all computers the loopup is very slow and tonns of errors:
lame server resolving xxxxxx.xxx.xxx : xxx.xxx.xxx.xxx#53
lame server resolving xxxxxx.xxx.xxx : xxx.xxx.xxx.xxx#53
lame server resolving xxxxxx.xxx.xxx : xxx.xxx.xxx.xxx#53

i configured my router for forwarding the port 53 to my local dns, but it didn't solved the problem!

Sep 11, 2009 9:01 AM in response to Robert23

Your DNS is asking a "lame" server for DNS; you're not getting an authoritative response to the query.

The target DNS server for the query isn't configured correctly; the local DNS server has found a target DNS server for the domain as being authoritative for the zone, but the target DNS server is not configured as being authoritative for the zone.

i configured my router for forwarding the port 53 to my local dns, but it didn't solved the problem!


That's not what I'd choose here.

Your clients are aimed at your DNS server. Your DNS server is aimed at your ISP servers. Your firewall is set to pass DNS out, but (generally) to block inbound DNS requests. Your DHCP is set to serve your DNS server address. If you've been tossing configuration changes and such here within your clients and your DNS servers, then you may well have some stale stuff in the DNS caches, too.

Sep 11, 2009 10:17 AM in response to Robert23

Now i tested at www.speedtest.net my latency (ping) it is 700ms(with Local DNS Forwarder),without its around 45ms.


The DNS server here might be misconfigured or an otherwise slow box, or there's something up with the network or the local connection or the ISP DNS. What this speedtest tool is doing here or what it might be testing here, I don't know. I tend to use the integrated tools; ping and such. I also don't how the DNS server is configured, what the box involved is, or otherwise.

what shall i do?


You're going to have to do some detective work. Without poking around inside the DNS and the LAN and related, I'm not in a good position to figure out why the connectivity here is slow.

Sep 11, 2009 2:22 PM in response to MrHoffman

Open Terminal and write: sudo changeip -checkhostname

Post results here.

[quote]i configured my router for forwarding the port 53 to my local dns, but it didn't solved the problem![/quote]

Of course it did not, because your server can handle dns requests for his dns domain, and when he does not know the answer, it "forwards" the request to the forwarder.

Regards

Kostas

Sep 12, 2009 1:19 AM in response to Robert23

Thank you i got the error. I had to reconfig my rndc by *"sudo rndc-confgen -b256".*
Now everything is fine, the ping lookup 🙂
But there are many errors in named.log like:
*12-Sep-2009 10:11:32.124 permission denied resolving 'nserver.apple.com/AAAA/IN': xxxx:xxxx:xxxx:xxxx:xxxx:xxxx#53*
when i enter in terminal: *rndc start* i get the error:
*"rndc: connect failed: 127.0.0.1#953: connection refused"*

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Local and ISP DNS

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.