Problem Ping & Tracert issue

Discussion in 'Networks' started by mcbro, Jun 27, 2012.

  1. mcbro

    mcbro Byte Poster

    136
    0
    23
    Hi guys

    I came across an interesting problem today at a customers site. It turns out no matter what you ping or tracert you get a response from an external IP. Always the same IP address which i don't recognise.

    So anyone got any pointers? My guess is that the DNS servers are sticking the domain suffix on everything and then sending it out to the web.

    (i did have fun thinking of words to ping or tracert such as ping pongmerrilyonhigh) :biggrin

    Cheers in advance
     
    Certifications: MCITP:EA, CCNA
  2. GSteer

    GSteer Megabyte Poster

    627
    31
    109
    Simple questions first:

    Are the machines DNS servers what you expect them to be?
    Is the hosts file clean?

    I've seen mDNSResponder causing DNS issues on client machines so check for iTunes. You can disable the service and test.

    Additionally:

    Does it matter where you ping from or is this happening on all clients/servers?
    If you do a manual nslookup do you get a different response using the internal DNS server vs Googles or OpenDNS ?
     
    Last edited: Jun 27, 2012
    Certifications: BSc. (Comp. Sci.), MBCS, MCP [70-290], Specialist [74-324], Security+, Network+, A+, Tea Lord: Beverage Brewmaster | Courses: LFS101x Introduction to Linux (edX)
    WIP: CCNA Routing & Switching
  3. Sparky
    Highly Decorated Member Award 500 Likes Award

    Sparky Zettabyte Poster Moderator

    10,718
    543
    364
    Same problem if you ping an IP address?
     
    Certifications: MSc MCSE MCSA:M MCSA:S MCITP:EA MCTS(x5) MS-900 AZ-900 Security+ Network+ A+
    WIP: Microsoft Certs
  4. mcbro

    mcbro Byte Poster

    136
    0
    23
    Yeah the same ip address responds to ping or tracert. Im in the office tomorrow so ill have time to have a proper look then.
     
    Certifications: MCITP:EA, CCNA
  5. Sparky
    Highly Decorated Member Award 500 Likes Award

    Sparky Zettabyte Poster Moderator

    10,718
    543
    364
    So if you ping any IP address it comes back with the same IP?!?

    Trying pinging an IP address on the LAN and then one on the WAN (e.g 8.8.8.8 )
     
    Certifications: MSc MCSE MCSA:M MCSA:S MCITP:EA MCTS(x5) MS-900 AZ-900 Security+ Network+ A+
    WIP: Microsoft Certs
  6. mcbro

    mcbro Byte Poster

    136
    0
    23
    If the hostname is in DNS the server will respond with the correct ip (ping mail ........10.10.10.1)
    If the hostname isnt in DNS the server reponds with an external ip (ping .........pleasedontrespond 72.1.5.1) The external ip that responds is always the same and looking it up online it appears to be a hosting company. The hostname of the ip looks correct ie myclient.hostingcompany.com.

    This is the same from both of the main DNS servers. However there is a 3rd DNS server on site that behaves normally.
    Its active directory intergreated DNS and i couldnt see any differences in the config.
    I feel like theres a setting in DNS im forgetting about.
     
    Certifications: MCITP:EA, CCNA
  7. dales

    dales Terabyte Poster

    2,005
    51
    142
    Probably a daft question but whats the internal domain name is it company.local and not company.com or similar is it.
     
    Certifications: vExpert 2014+2015+2016,VCP-DT,CCE-V, CCE-AD, CCP-AD, CCEE, CCAA XenApp, CCA Netscaler, XenApp 6.5, XenDesktop 5 & Xenserver 6,VCP3+5,VTSP,MCSA MCDST MCP A+ ITIL F
    WIP: Nothing
  8. mcbro

    mcbro Byte Poster

    136
    0
    23
    Hi Dales, the internal domain is company.companyname.org
     
    Certifications: MCITP:EA, CCNA
  9. kevicho

    kevicho Gigabyte Poster

    1,219
    58
    116
    We had a similar issue a while back, it turned out that the firewall was misconfigured for Proxy ARP and was responding on behalf of our VMWare hosts, that was a fun day!
     
    Certifications: A+, Net+, MCSA Server 2003, 2008, Windows XP & 7 , ITIL V3 Foundation
    WIP: CCNA Renewal
  10. GSteer

    GSteer Megabyte Poster

    627
    31
    109
    Are the DNS forwarders identical across all three boxes?
     
    Certifications: BSc. (Comp. Sci.), MBCS, MCP [70-290], Specialist [74-324], Security+, Network+, A+, Tea Lord: Beverage Brewmaster | Courses: LFS101x Introduction to Linux (edX)
    WIP: CCNA Routing & Switching
  11. mcbro

    mcbro Byte Poster

    136
    0
    23
    Yep the same on all 3
     
    Certifications: MCITP:EA, CCNA
  12. Sparky
    Highly Decorated Member Award 500 Likes Award

    Sparky Zettabyte Poster Moderator

    10,718
    543
    364
    Just to confrim. You have three DNS servers in the same LAN subnet on the same site – all three have the same default gateway and all three also have the same DNS forwarders.

    If this is the same case do all three DNS servers NAT out on the same published IP address?
     
    Certifications: MSc MCSE MCSA:M MCSA:S MCITP:EA MCTS(x5) MS-900 AZ-900 Security+ Network+ A+
    WIP: Microsoft Certs

Share This Page

Loading...
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.