LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 12-07-2016, 08:58 AM   #1
nitinprabhu
LQ Newbie
 
Registered: Dec 2016
Posts: 3

Rep: Reputation: Disabled
dig command not working whereas ping and nslookup works fine


Hi,

My scenario is as below.

There are two Microsoft Active Directory Domain Controller's (one DC for parent domain with DNS server and another DC for child domain without DNS server.Child DC uses
parent DC's DNS server).

I have installed Univension Corporate server (which is an Linux based 64 bit OS derived from Debian OS) on a VMWare virtual environment.

I am able to ping and do a nslookup on the IP address of child Domain controller(DC) 10.181.1.11 but if I issue a dig command then it gives me below error.


dig @10.181.1.11

; <<>> DiG 9.8.4-rpz2+rl005.12-P1 <<>> @10.181.8.11
; (1 server found)
;; global options: +cmd
;; connection timed out; no servers could be reached


If I issue a dig command on the DNS server IP(10.181.1.111) then it works fine.

How can check whether it is a DNS issue or a network issue or something
else?

/etc/resolv.conf contains the DNS server IP(10.181.1.111) used by child DC(10.181.8.11)

Regards,
Nitin
 
Old 12-07-2016, 11:57 AM   #2
c0wb0y
Member
 
Registered: Jan 2012
Location: Inside the oven
Distribution: Windows
Posts: 421

Rep: Reputation: 74
Aren't you querying a child DC which happen to have no DNS server in it?

To me your DNS server is 10.181.1.111 and you seem to be querying x.x.x.11.
 
Old 12-07-2016, 04:47 PM   #3
nitinprabhu
LQ Newbie
 
Registered: Dec 2016
Posts: 3

Original Poster
Rep: Reputation: Disabled
Yes I am querying a child DC which uses parent domain's DNS server.
If my understanding is correct if I should be able to query child DC IP as it is using parent DC's DNS server.
 
Old 12-07-2016, 06:36 PM   #4
c0wb0y
Member
 
Registered: Jan 2012
Location: Inside the oven
Distribution: Windows
Posts: 421

Rep: Reputation: 74
So you basically wants your child DC to proxy dns requests? And you did not even state the listening ports, iptables rules.

Or, why not let the clients querry the DC directly?

You have to provide a lot of information.

Last edited by c0wb0y; 12-07-2016 at 06:37 PM.
 
Old 12-08-2016, 03:56 AM   #5
nitinprabhu
LQ Newbie
 
Registered: Dec 2016
Posts: 3

Original Poster
Rep: Reputation: Disabled
Sorry if I was not clear.Basically I want a host(UCS Server deployed on VMWare) to connect to Child Domain Controller Active Directory which is using DNS server of parent Domain controller.

I can issue a ping to IP address of Child Domain AD as well do a nslookup but UCS issues a dig command while establishing a connection to Child DC AD.
Even if I manually issue a dig @10.181.8.11(IP address of Child DC) it fails giving a connection timeout error.

I am able to ping ,do a nslookup as well dig to DNS server which is 10.181.8.111.

I can telnet to the port telnet 10.181.8.11 389 and it works fine.

Regarding IP tables I am not aware of any issues related to it but if you want me to share output of some commands then I am happy to do so.

I am not aware of networking,routing in detail so if could please help me with some commands then I would share the output of those.

Thanks for your help.
 
Old 12-08-2016, 10:34 AM   #6
c0wb0y
Member
 
Registered: Jan 2012
Location: Inside the oven
Distribution: Windows
Posts: 421

Rep: Reputation: 74
If you can ping from UCS to child DC, that's good. It verified connectivity.

Port 389 is irrelevant in this instance.

When you say you can "do a nslookup", can you show your exact command? Because I am certain that nslookup is not actually able to talk to child DC for the simple reason that there is NO dns server listening there at port 53. You have lots of tools available to confirm that.

I have no iptables rule to share.
 
Old 12-08-2016, 09:03 PM   #7
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,997

Rep: Reputation: 3628Reputation: 3628Reputation: 3628Reputation: 3628Reputation: 3628Reputation: 3628Reputation: 3628Reputation: 3628Reputation: 3628Reputation: 3628Reputation: 3628
Wonder if this is relevant?
http://serverfault.com/questions/434...but-dig-cannot
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Dig/NSLookup works ... ping doesn't ... but, it used to sundialsvcs Linux - Networking 7 06-15-2016 06:21 AM
nslookup/dig command not found Axion Slackware 8 02-11-2010 06:23 PM
Inconsistent results using ping, dig, nslookup, whois, host steelaz Linux - Networking 3 04-05-2009 07:50 AM
Command not working in cron job, but works fine in root Roosta21 Linux - Software 4 11-22-2007 08:08 AM
nslookup works, ping doesn't coolnicklas Linux - Networking 5 04-16-2005 08:23 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 08:12 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration