Host A records only written when client reboots - NOT on ipconfig /registerdns


hello everyone,

this issue has been driving me insane couple weeks now.  hope able draw accurate picture of experiencing, have ton of testing notes , explanation might drowned out.  has idea me:

1.  noticed of our clients missing host (a) records in ad integrated dns zone.

      a.  configured sddns, clients writing own host records , dhcp writing ptrs.

      b.  not have scavenging enabled, aging configured @ zone level.

      c.  have several dhcp subnets , dhcp assigns , works flawlessly.

      d.  hosts not right host records in 1 subnet fail in others.  host right host record in 1 sn succeed in others.

      e.  windows 7 hosts not right host record have frequent dnsapi timeout error our domain

            i.  name resolution works both forward , reverse records records available

            ii. dns server service on :-)

2.   asked 1 of our consultants , suggested disable rss , chimney offloading - offloading disabled on our servers, , rss has since been configured disabled.  thing can appeared have come client consistantly register host records upon reboot (they didn't consistently prior change), still not perform registration ipconfig /registerdns

3.   have been testing registration manually deleting object dns , issuing registerdns command client.  stated doesn't work, know have issue.

4.   dns debug logging noticed registrations successful have tkey negotiation should after "refused" insecure update, registrations requests clients not written not refused, , therefore not have tkey negotiation.  indicates me there issue between dns , ad, clients in question have full permissions on object in windowsdns, don't think permission issue.

this of information, have bright ideas?

thanks

i see, explanation.

as stated, of machines (including ones not working) domain joined.  , when made mention "windows dns" in original post, indeed referring "microsoftdns" not software specific implementation of dns.  

i assume strictly using microsoft dns , not bind, or else?

i'm not sure why looking in aduc's system\microsoftdns container. sort of thing, it's recommended use adsi edit @ dns partitions. time suggest check if there duplicate zones in 3 possible spots, domaindnszones, forestdnszones, , domainnc partitions.

and mentioned you're looking @ domainnc container, , not domaindnszones or forestdnszones partitions. reason why zone stored in domainnc? that's 1 option windows 2000 backward compatibility in zone's replication scope settings.

i've seen inconsistent results when duplicates exist. example, when 1 admin places zone in domainnc partition, yet 1 on server tries changing domaindnszones (the middle button), or when perhaps new dc gets added , admin impatient , manually adds zone not realizing auto-appear after ad replication has completed.

matter of fact, while on subject, let's @ least eliminate possibility. can use adsi edit. looking are any zone names have "inprogress...{guid}" of "cnf...{guid}" in of 3 partitions. if find any, dupes , must deleted. here's quick tutorial:

using adsi edit resolve conflicting or duplicate ad integrated dns zones
http://msmvps.com/blogs/acefekay/archive/2009/09/02/using-adsi-edit-to-resolve-conflicting-or-duplicate-ad-integrated-dns-zones.aspx 

.

that said, assume you've made sure there no blocked ports? av software that, too.

.

as dns record permissions, default here's how works:

  • by default, windows 2000 , newer statically configured machines
    register record (hostname) , ptr (reverse entry) dns.
  • if set dhcp, windows 2000 or newer machine request dhcp allow
    machine register own record, dhcp register ptr
    (reverse entry) record.
  • the entity registers record in dns, owns record.

.

so if dhcp involved, dhcp (without configure credentials), allow client register record, dhcp update reverse. owner of record in case client. however, if have multiple dhcp servers, such in 80/20 scenario, won't hold true, , credentials must used both servers can register record, own record, , update record later when changes. preferred method whether single or multiple dhcp scenario.

.

it vlan ports doing it. i've heard of in past. can't remember actual setting, timing issue bootp, or spanning tree. eliminate possibility, if have vlans, please check docs on it.

.

ace


ace fekay
mvp, mct, mcitp enterprise administrator, mcts windows 2008 & exchange 2007 & exchange 2010, exchange 2010 enterprise administrator, mcse & mcsa 2003/2000, mcsa messaging 2003
microsoft certified trainer
microsoft mvp - directory services
complete list of technical blogs: http://www.delawarecountycomputerconsulting.com/technicalblogs.php

this posting provided as-is no warranties or guarantees , confers no rights.

facebook twitter linkedin



Windows Server  >  Directory Services



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS