HCHTech
Well-Known Member
- Reaction score
- 4,210
- Location
- Pittsburgh, PA - USA
I've got a client with a single DC, running Server 2019. I got a complaint that their users couldn't download content from a vendor site. The site itself comes up fine, but when selecting an item to download, the browser displays the "the connection has timed out" error.
Trying this site from my computer works just fine, so I start looking for problems there. Not being blocked by the firewall or content filtering or GEO-IP filtering, anything like that. Looking in the DNS logs, I see error 5504:
"The DNS server encountered an invalid domain name in a packet from 9.9.9.9. The packet will be rejected. The event data contains the DNS packet."
Hmm. searching this error talks about clearing the DNS cache and restarting the DNS service, which didn't change the symptom in my case. I changed the DNS forwarders so that quad9 wasn't primary, cleared the cache again and restarted both the netlogon and dns services, no change. Now I get the same error listing the new primary forwarder in the message.
I'm the only one that accesses their servers, and I didn't change anything recently.
Running dcdiag, I get all passes except one:
"Dynamic registration or deletion of one or more DNS records associated with DNS domain 'theirADdomain' failed. These records are used by other computers to locate this server as a domain controller or as an LDAP server. "
It's been a couple of years since I set this server up, but I know I had clean dcdiag runs then. Also, they aren't reporting any other problems with browsing or access, so this seems to be a narrow problem. I would say it's a problem with the site itself, but it works from my office and a laptop there works when you connect it to a cellphone hotspot. So it's definitely a problem with the infrastructure there.
How should I diagnose this further?
Trying this site from my computer works just fine, so I start looking for problems there. Not being blocked by the firewall or content filtering or GEO-IP filtering, anything like that. Looking in the DNS logs, I see error 5504:
"The DNS server encountered an invalid domain name in a packet from 9.9.9.9. The packet will be rejected. The event data contains the DNS packet."
Hmm. searching this error talks about clearing the DNS cache and restarting the DNS service, which didn't change the symptom in my case. I changed the DNS forwarders so that quad9 wasn't primary, cleared the cache again and restarted both the netlogon and dns services, no change. Now I get the same error listing the new primary forwarder in the message.
I'm the only one that accesses their servers, and I didn't change anything recently.
Running dcdiag, I get all passes except one:
"Dynamic registration or deletion of one or more DNS records associated with DNS domain 'theirADdomain' failed. These records are used by other computers to locate this server as a domain controller or as an LDAP server. "
It's been a couple of years since I set this server up, but I know I had clean dcdiag runs then. Also, they aren't reporting any other problems with browsing or access, so this seems to be a narrow problem. I would say it's a problem with the site itself, but it works from my office and a laptop there works when you connect it to a cellphone hotspot. So it's definitely a problem with the infrastructure there.
How should I diagnose this further?