Some DNS Name Queries Are Unsuccessful After You Upgrade Your DNS Server to Windows Server 2003 (832223)
The information in this article applies to:
- Microsoft Windows Server 2003, Datacenter Edition
- Microsoft Windows Server 2003, Enterprise Edition
- Microsoft Windows Server 2003, Standard Edition
SYMPTOMSAfter you upgrade your Microsoft Windows 2000-based DNS server to Microsoft Windows Server 2003, DNS queries to some domains may not be resolved successfully.
CAUSEThis issue occurs because of the Extension Mechanisms for DNS (EDNS0) functionality that is supported in Windows Server 2003 DNS.
ENDS0 permits the use of larger User Datagram Protocol (UDP) packet sizes.
However, some firewall programs may not permit UDP packets that are larger than 512 bytes.
As a result, these DNS packets may be blocked by the firewall.RESOLUTIONTo resolve this issue, update the firewall program to recognize and permit UDP packets that are larger than 512 bytes. For additional information about how to do this, contact the manufacturer of your firewall program.
For information about how to contact computer hardware and program vendors, click the appropriate article number in the following list to view the article in the Microsoft Knowledge Base:
65416
Hardware and Software Third-Party Vendor Contact List, A-K
60781
Hardware and Software Third-Party Vendor Contact List, L-P
60782
Hardware and Software Third-Party Vendor Contact List, Q-Z
Microsoft provides third-party contact information to help you find technical support. This contact information may change without notice. Microsoft does not guarantee the accuracy of this third-party contact information.
WORKAROUNDTo work around this issue, turn off the EDNS0 feature in Windows Server 2003. To do this, follow these steps: - Install the Dnscmd.exe program from the Windows Server 2003 Support Tools. To install the Windows Support Tools, right-click Suptools.msi in the Support\Tools folder on the Windows Server 2003 CD-ROM, and then click Install. Follow the steps in the Windows Support Tools Setup Wizard to complete the installation of the Windows Support Tools.
- At a command prompt, type the following command, and then press ENTER:
dnscmd /config /enableednsprobes 0 Note Type a 0 (zero) and not the letter "O" after "enableednsprobes" in this command.
The following information appears:Registry property enableednsprobes successfully reset.
Command completed successfully.
After you run this command, Windows Server 2003 DNS no longer advertises its EDNS0 capabilities.
As a result, the Windows Server 2003 DNS server will not be sent UDP packets that are larger than 512 bytes.
Modification Type: | Major | Last Reviewed: | 11/17/2003 |
---|
Keywords: | kbprb KB832223 kbAudITPRO |
---|
|