DNS based ACLs failing

From: Dawn (dawn.m.connelly_at_usace.army.mil)
Date: 07/01/04


Date: 1 Jul 2004 10:17:06 -0700

Starting some time in early June, we started getting reports of the
uber annoying "I can't get to xyz webpage". Most of the time, those
are PEBCAK errors, but the complaints keep mounting. When I started
digging in to it, it looks like they are legit. The users were getting
403'd on webpages that they should have access to. It's cross
platform....mickeysoft and sun. So far reports have been for Netscape
Enterprise and again, mickeysoft webservers. The one common thread
that I'm seeing is that it looks like the Denies happen when the https
acl references a DNS query rather than an IP range. So any acl saying
*.gov is good ain't working. But if the class b is there, users are
saling. Reports have been from here in Portland and in
Chicago...totally different networks, different sysadmins, different
DNS servers. Has anyone else been seeing this recently? I dug through
the config file of one of the servers, and everything looks fine. That
particular server is also a email bridge head- if DNS were really
failing on it, about 3000 people be gripping about not getting their
SPAM. Any suggestions?



Relevant Pages

  • GPO and server down errors
    ... and one NT4 BDC. ... 1058 errors on a regular basis and the DC reports nothing ... this is the same on all W2K3 servers. ... itself for DNS and it passes all DNS testing. ...
    (microsoft.public.windows.group_policy)
  • Re: Adding Servers to 2003 Domain
    ... The server i removed from the domain was not one of the A/D - DNS servers. ... I used DNSlint with the /ad switch and it reported all looked OK ... DCdiag passes the frssysvol test but reports frsevents. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Access to two websites
    ... Although I can access both sites without any problems(WinXP pro) their dns ... These are the links for the dns reports for both sites. ... settings that are preventing this. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Monitoring Software
    ... It worked perfectly with windows and linux severs i tested, ... information is amazingly accurate but it doesnt produce reports like ... or monthly usages of all servers' CPUs for example.. ... thats the kind of report im seeking and so far nagios doesnt seems to ...
    (Security-Basics)
  • Re: Since the Security patch
    ... You can get the report from WSUS, but you might need to download to generate and read the reports. ... I am having all kinds of issues on my servers (at different client ... google search page dislpays We're sorry... ... See what SBS support is working on ...
    (microsoft.public.windows.server.sbs)