SBS 2003 - Required DNS Records?


Recommended Posts

Hello,

Im trying to setup a test version of SBS 2003 R2, using VMware Workstation 7 (Windows 7 x64 is the host).

I have gone through the install fine, i then went on to using the configuartion wizards to set up email, VPN and RWW. In the connect to internet and email wizard, i created the web server certificate as: servername.domain.co.uk

I have set up appropiate port forwarding rules in my router (Netgear DG834PN).

I set up the SBS VM with the, say, domain.local. The domain that i want to use with this (for email, VPN and RWW) is domain.co.uk. On the host where domain.co.uk is hosted, i have setup the following DNS records (see attached).

First of all, do these look correct? Do i need any more?

Can someone explain, the @ in the MX record (and the @ in the A record)? Further, i do not see understand if i have to have my mail.domain.co.uk match my servername.domain.co.uk - does that make sense?

Sorry for the confusing question, please ask anything that i didnt make clear.

Cheers

post-225317-1259089090_thumb.png

Link to comment
https://www.neowin.net/forum/topic/848850-sbs-2003-required-dns-records/
Share on other sites

The broken english is a little hard to understand when asking a question. I will answer to the best of my understanding the way the questions were asked.

Everything looks fine with your DNS, you don't need any more entries. VPN, mail, and webmail are all going to go through your mail.x.x.

MX record = Mail eXchange, this is how the internet knows where to route mail. The MX record has to point to an A record. The @ is your main domain ip address, if you just type in domain.co.uk it will direct to that IP Address.

"Further, i do not see understand if i have to have my mail.domain.co.uk match my servername.domain.co.uk - does that make sense?" <---- I don't really understand this question but will give it my best, The A record is just a friendly name on the internet, it has absolutly nothing to do with your internal naming conventions. In otherwords, it does not have to match your computer name as it doesn't resolve to an internal address, it resolves to your external address (external to your network or vmware network).

Hi,

Thanks for the reply (and appologies for the confusion in my question). The problem is i was just not sure what was wrong!

I understand the DNS record setup now (i think!). What i was trying to ask was whether in the SBS CEICW, where you create the webserver certificate and have to supply the FQDN of the server, does this (say servername.domain.co.uk) have to match what you have setup the MX record as. I now undertsand that the FQDN that you set in the CEICW is kinda arbitrary, because as long as you setup a matching A record in the DNS then it will all be fine to access RWW etc (so you can then have a separate MX record, say mail.domain.co.uk for mail - as long as that also has a matching A record to the external IP).

I have attached a screenshot of my new DNS records for clarity (78.xxx.xxx.xxx is the external IP of the router. 195.xxx.xxx.xxx is the IP used for web hosting - which is unrelated to any of this)

Now the problem... When i type: https://portal.domain.co.uk/remote all i get is a Server Not Responding page. I have setup the port forwarding correctly (i believe), as when i try to reach this address, i then see a log entry in the router control panel along the line of:

Wed, 2009-11-25 19:55:34 - TCP Packet - Source:192.168.0.2,63874 Destination:78.***.***.***,443 - [HTTPS rule match]

So the DNS is obviously routing correctly. Ive confirmed the internal IP of the server (192.168.0.10) is set, and this matches the port forwarding rules. Ive disabled the firewall on the Windows 7 host, and the SBS 2003 guest doesnt have a firewall becuase it only has one NIC (?). So why doesnt it work?!

Once again, sorry for the long windedness and any confusion i am / have caused!

post-225317-1259179574_thumb.png

You will need to have your certificate reflect the outside fqdn. If you want you can have the inside fqdn so you don't get the certificate errors on the inside of the network, completely up to you in this regard if only a select amout of users are going to be accessing it from the inside.

If you are trying to access the server from the inside (behind the firewall) with the outside address (trying to go out the in or in the out, however way you want to see it), your router is going to have an issue with that. It drops the packet. Easiest way is to make a dns forward entry for domain.co.uk and an A record under that for portal pointing to the internal ip address.

Thanks for the reply.

I appreciate what you say about trying to access the VM inside the router (loopback?) Anyways, i tried on a couple of other computers (not behind the router) and the request still times out... yet i still get the requests logged in the router? For example:

Thu, 2009-11-26 22:50:06 - TCP Packet - Source:87.127.***.***,52785 Destination:78.***.***.***,443 - [HTTPS rule match] - source is not inside the network!

My port forwarding rules are correct, and the 192.168.0.10 that they forward to (the server) is the IP of the server - what am i missing?!

It has to be outside the inside interface of the router. In other words on the public ip segment. If you want it to answer behind the router, any pc behind the router not just behind the vmware server virtual ip range, you would have to put it in the internal DNS server.

I am attaching a very crude drawing but this is basically what you are trying to accomplish, and it is failing on coming back into the router.

post-118098-1259288857_thumb.jpg

Edited by sc302

Hey

I really appreciate all the help but I finally managed to crack it! I was going crazy because I knew my port forwarding rules were set up correctly, so I simply went to a previous snap shot of the SBS VM (before I ran CEICW) and ran it once more and suddenly every thing worked! Looks like rerunning the wizard over and over isn't the thing to do!

On a side note, just curious about how I would go

about setting up some dns so users could type:

owa.domain.co.uk and being sent to portal.domain.co.uk/reomote

rww.domain.co.uk and being sent to portal.domain.co.uk/exchange

Can this be done? Does it require CNAMEs?

Thanks again for all your help. Much appreciated.

I am assuming that you have an internal dns server (if you are using AD you have to), Put in another forward zone matching your external domain name, then put in an a record for portal, owa, and rww. it is not going to default to the subdirectory exchange or remote. you could put in a webpage at portal that has the links pointing to exchange or remote. You can have the default web page automatically point to one or the other when the page is hit, but that is about it.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Same Internet Archive seemed to grab the new version https://web.archive.org/web/20...d/Setup_MakeMKV_v1.18.4.exe Here's the link to an additional file it periodically downloads https://web.archive.org/web/20260213092148/https://www.makemkv.com/sdf.bin I think update's keys, etc. To manually trigger this update, put the sdf.bin file in the root of where the program is installed. When you launch the program it will pick up the file and import it. Typically put it here: C:\Program Files (x86)\MakeMKV\sdf.bin
    • Windows 11 KB5094126, KB5093998 bugging out Office apps but it may not be Microsoft's fault by Sayan Sen Microsoft last week released Windows 11 KB5094126 and KB5093998 as the latest Patch Tuesday updates. Following that the company also published the accompanying dynamic updates under KB5094149, KB5095971, and KB5094156. Although the tech giant did not acknowledge any major problems, some users online reported various issues ranging from OneDrive and Dropbox access problems, BitLocker recovery lockouts, to blue screens and BSODs. You can read about them in this dedicated piece. While there is still no confirmation about those problems from Microsoft the company has admitted to another bug which we did not report on. The tech giant has confirmed it has received reports of an issue in which certain third-party applications may be unable to launch Microsoft Office apps or open Office documents after installing the Patch Tuesday. This affects both Windows 11 as well as Windows 10. The company says the problem impacts a subset of applications that rely on OLE (Object Linking and Embedding) automation to communicate with Microsoft Office programs. According to Microsoft, affected scenarios involve third-party software attempting to open Office applications or documents from within their own interface. In such cases, the Office program may fail to launch altogether, or the requested document may not open. Oddly there may not be any error message, which probably makes the issue difficult to diagnose. The bug affects several Office products, including Word, Excel, PowerPoint, Access, and other apps in the Microsoft Office suite when they are launched through the affected software. These include tax and accounting software such as CCH Engagement and Workpaper Manager, dental practice management solutions like Dentrix and Softdent, as well as the popular research and reference management tool Zotero. Microsoft adds that other applications using similar Office integration methods could also experience the same problematic behavior. To understand the issue it is important to look at OLE, the Microsoft technology involved. OLE allows different applications to work together and share data, while its Automation feature lets one program control another. Thus this enables third-party software to launch Microsoft Office apps, open documents, and perform tasks automatically without requiring users to switch between programs. Because many accounting, healthcare, research, and business applications rely on OLE automation to interact with Word, Excel, PowerPoint, and other Office apps, any disruption can break those workflows. As a result, affected software may be unable to open Office documents or launch Office applications even though the programs themselves continue to work normally. At the moment the company has not provided a permanent fix though it has confirmed that engineers are actively working on a resolution, which will be delivered through a future Windows update. As such additional details will be shared once more information becomes available. In the meantime, Microsoft recommends a simple workaround for affected users whic is to open the Office application or document directly rather than launching it through the third-party program. For enterprise customers and organizations managing larger deployments, Microsoft says an additional mitigation is available. Admins experiencing the problem on their managed devices are advised to contact Microsoft Support for business to obtain and apply the workaround.
    • It saddens me when cars are such dull colours now. Mine is bright metallic blue and I absolutely adore it for standing out in contrast to that depressing backdrop of traffic.
    • Sparkle 2.20.0 by Razvan Serea Sparkle is a free, open-source Windows optimization tool designed to make your PC faster, cleaner, and more private. With Sparkle, you can easily debloat Windows by removing unnecessary apps and services, disable Microsoft tracking to enhance privacy, and apply performance tweaks to boost speed. Its cleaner removes junk and temporary files, while every change is safe and fully reversible. Sparkle also features a modern, user-friendly interface with automatic updates, making system maintenance simple. Explore over 39 tweaks, from disabling telemetry and hibernation to optimizing network and game settings, all aimed at customizing and enhancing your Windows experience. Sparkle supports Windows 10 and 11. Sparkle 2.20.0 changelog: Debloat Tweak has animated border New homepage loading UI New Tweak Modal (Markdown Supported) Refactored GPU Detection Added Tests with vitest Added foobar2000 to apps Added Localsend to apps Updated Modal Styles Added styles for disabled inputs Added Animated Border to debloat-windows tweak Bumped dependencies Refactor System info logic for speed Tweak info modals now support Markdown Added Clear System info cache to settings Redesigned Home Page Loading UI Changed Some Icons around the app Download: Sparkle 2.20.0 | Portable | ~100.0 MB (Open Source) Links: Sparkle Website | Github | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • lol it was a typo, fixed! haha imagine an actual 4TB Gen4 NVMe for $40 in 2026
  • Recent Achievements

    • Reacting Well
      Dys Topia earned a badge
      Reacting Well
    • Conversation Starter
      NovaEdgeX earned a badge
      Conversation Starter
    • One Year In
      Console General earned a badge
      One Year In
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      517
    2. 2
      +Edouard
      184
    3. 3
      PsYcHoKiLLa
      106
    4. 4
      Steven P.
      88
    5. 5
      ATLien_0
      68
  • Tell a friend

    Love Neowin? Tell a friend!