RE: Wierd DNS stuff...

  • From: "Uttam K. Malhotra" <uttamm@xxxxxxxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Wed, 10 Oct 2001 13:36:16 -0700

Hello

This as follows :

As the message is suggesting, the DNS server has received an invalid
domain name. By invalid it means that it contains invalid characters. MS
DNS only supports 0-9, a-z, A-Z, . (dot), and - (hyphen) as part of a
domain name. Some other DNS servers may not strictly enforce RFC 952
(DOD INTERNET HOST TABLE SPECIFICATION) so invalid names reach the DNS
server and the 5504 message is recorded. Usually this happens when
Forwarders are used by the DNS server. Microsoft suggested to one user
to turn off the forwarder in order to eliminate these messages. There
used to be a Knowledge Base article "Q246797 - DNS EVENT IDS 5504, 9999,
AND 5000 FILL EVENT VIEWER" but is no longer available.
Another condition that may generated these messages is when the Internet
connection is saturated or not working properly (losing packets).
Because of the poor Internet connection, the DNS may receive incomplete
or corrupted data and 5504 is generated. 

Might solve ur problem !

Uttam


-----Original Message-----
From: Bryan Andrews [mailto:bandrews@xxxxxxxxxxxxxxxxxx]
Sent: Tuesday, October 09, 2001 7:24 PM
To: [ISAserver.org Discussion List]
Subject: [isalist] Wierd DNS stuff...


http://www.ISAserver.org


Hello All,

I have been having dns trouble intermittently where emails are bouncing
back (exchange2000) and I clear my dns caches and everything is ok.

Quick note about my setup:

1. ISA server w/ 2 nics, no DNS, no IIS, no etc
2. internal AD, DNS (AD integrated), E2K server
3. internal AD, DNS (AD integrated)
4. other boxes that are not important.

In troubleshooting I have noticed that I have repeated entries in my dns
for:

Event Type:     Warning
Event Source:   DNS
Event Category: None
Event ID:       5504
Date:           10/2/2001
Time:           6:28:04 PM
User:           N/A
Computer:       TATL0S03
Description:
The DNS server encountered an invalid domain name in a packet from
209.235.102.18.  The packet is rejected.


AND

Event Type:     Warning
Event Source:   DNS
Event Category: None
Event ID:       5504
Date:           10/2/2001
Time:           6:28:04 PM
User:           N/A
Computer:       TATL0S03
Description:
The DNS server encountered an invalid domain name in a packet from
209.235.102.17.  The packet is rejected.

I have no idea why this is happening. I did digs and do not recognize
this address, and whats more, I don't really understand how dns would be
talking to this ip thru the firewall... often and repeatedly.

Has anyone else seen this before is this something I should worry about?

------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
uttamm@xxxxxxxxxxxxxx
To unsubscribe send a blank email to $subst('Email.Unsub')


Other related posts: