Unable to Resolve DNS Queries from RODC

Himanshu Dwivedi 40 Reputation points
2023-05-20T07:03:07.1666667+00:00

I have setup a new domain RWDC with name test.com and added one RODC in same domain.

Added one computer - Assigned Computer the domain IP, in primary DNS(RWDC) and Alternate DNS(RODC), and successfully joined to the domain.

Issue : When RWDC is online if I ping test.com it successfully pings RWDC IP, but in case of RWDC is office, I am getting request timeout. Normally it should ping RODC IP.

I want to know is it a normal behavior or some changes needed?

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
4,334 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Dave Patrick 353.3K Reputation points MVP
    2023-05-20T12:17:53.9233333+00:00

    No, not normal. Pinging the domain name results in one DNS server answering. There is no option to control which one reacts. Could be some routing or firewall issues between source and destination. I'd check the ports are flowing between networks and that the new DNS server is operational (event logs may provide clues)

    https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/config-firewall-for-ad-domains-and-trusts#windows-server-2008-and-later-versions

    --please don't forget to upvote and Accept as answer if the reply is helpful--


  2. Dave Patrick 353.3K Reputation points MVP
    2023-05-20T18:42:59.08+00:00

  3. Thameur-BOURBITA 16,591 Reputation points
    2023-05-20T22:09:02.8633333+00:00

    Hi @Himanshu Dwivedi

    When you ping the domain name , one of domain controller can respond.

    By default ,behind the domain name, there are the IP of domain controllers to ensure the high availability using DNS round robin mechanism.

    Run the following command,to display the list of domain controller can be contacted when you try to ping the domain name test.com , :

    neslookup
    test.com
    

    If the IP of RODC doesn't exist , so it's normal behavior.

    If the nslookup displays the both IPs ( RODC and RWDC) , It should be a normal behavior,because Round Robin mechanism doesn't switch automatically without restarting the computer you are using to ping test.com after the power down of RWDC.


    Please don't forget to mark helpful answer as accepted


    0 comments No comments