We help IT Professionals succeed at work.

DNS reverse lookup records aren't getting updated from the DHCP server

KCATA
KCATA asked
on
Medium Priority
572 Views
Last Modified: 2012-08-14
We recently moved the DHCP server from an older Win 2000 box to a Win 2003 server.  The move seemed to go fine and DHCP itself is working but think i may have missed something related to DNS.  The DNS reverse lookup records do not seem to be being updated by the new DHCP server.  When i checked DNS for a specific workstation and then connect to it remotely by both the listed pc name and IP I ended up at two different machines.   I went into the DNSmgmt window in Admin tools, and it had at least half a dozen computers with that same IP listed.  There was another computer on there that had 15-20 PTR files with different IPs listed.  Any help with this would be greatly appreciated!
Comment
Watch Question

feptiasChief Dude
CERTIFIED EXPERT

Commented:
There are some settings within the Properties page of the DHCP server that set the way the DHCP server will interact with the DNS server. Is the DNS server running on Windows 2003 or on an older machine?

Open the DHCP Management Console on the server, then right click on the node that has the name of your server and select Properties. Now look at the settings in the DNS tab. Try ticking the option "Discard A and PTR records when lease is deleted". You may also find it useful to enable scavenging in the DNS server - this will remove stale DNS records after a set period of time. You may have to manually delete some of the stale DNS records at first just to get things tidy. After that the automated processes should keep it clean. If you want more details about scavenging, just say.

Author

Commented:
Thanks, looks like the "Discard A and PTR records when lease is deleted" was already checked on the DHCP server.  Can you give me more details on Scavenging?  The DNS server is running on a Windows 2000 machine at present, though it too will be updated to 2003 in the near future.  Did do the manual clean-up this morning but not sure if the problem will reappear over time yet or not.
Commented:
If you have dynamic updates set to "Only secure updates" then the new DHCP server will not have permission to modify DNS records created by the old server.  You have a few choices to fix this problem.

A. Manually delete all the records created by the old server.

B. Temporarily change the dynamic updates setting on the forward and reverse zones from "Only secure updates" to "Yes".

C. Add the new DHCP server to the DnsUpdateProxy security group.

Not the solution you were looking for? Getting a personalized solution is easy.

Ask the Experts

Author

Commented:
Ah, "Only Secure Updates" is set.  Since I did the manual cleanup this morning, will i still need to set that to "yes" for the future or should it update normally from this point forward?
Seelan NaidooMicrosoft Systems Admin

Commented:
delete your reverse DNS zone, and then recreate it..
Seelan NaidooMicrosoft Systems Admin

Commented:
also run ipconfig /flushdns on the DNS box..
Chief Dude
CERTIFIED EXPERT
Commented:
Here is a link to a reasonable description of DNS scavenging:
http://www.myitforum.com/articles/16/view.asp?id=6287

There may be differences between the DNS server in Windows 2000 is to the one in Windows 2003 (sorry, I only really know 2003). Scavenging settings on 2003 require that you enable it for the server as a whole and also it can be enabled/disabled for each DNS zone.
feptiasChief Dude
CERTIFIED EXPERT

Commented:
Also this earlier question, now PAQ'd, contains a lot of detail about scavenging and DDNS:
http://www.experts-exchange.com/Networking/Microsoft_Network/Q_22023097.html

Commented:
It should update normally from now on, assuming there are no other issues.

Author

Commented:
Thanks for all the help.  Think Shift-3 ultimately had the solution in this case, but appreciate the advice on scavenging from feptias as well.  Will split up the points a bit, but thank you both again.
Access more of Experts Exchange with a free account
Thanks for using Experts Exchange.

Create a free account to continue.

Limited access with a free account allows you to:

  • View three pieces of content (articles, solutions, posts, and videos)
  • Ask the experts questions (counted toward content limit)
  • Customize your dashboard and profile

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.