DNS configured incorrectly

Posted on 2009-02-22
Last Modified: 2012-06-22
Something is broken with our DNS. I think the records are not being updated or refreshed. If I ping an internal computer by name a lot of the time it resolves to the wrong IP address. External addresses resolve fine. There aren't any errors in the DNS log. Although, looking at our local subnets under reverse lookup zones shows the inacurate IP records along with old computer names that have since been renamed.

Any pointers would be greatly appreciated.
Question by:BIZNETplus
    LVL 70

    Accepted Solution



    The kind of old records you mention are normally cleaned out by the Scavenging process (if Aging is configured).

    Any idea if either of those are set at the moment? You'll find the settings in the properties for each zone by clicking on the Aging button. That applies to both forward and reverse lookup zones.

    Ideally, we would want to set those intervals to work with your DHCP Lease duration That is, if your lease were 8 days, setting No-Refresh to 4 days and Refresh to 4 days is a good start.

    LVL 4

    Expert Comment

    did you mak sure that dynamic updates are enabled on you zone?

    is your zone AD integrated? are the dynamic updates set to secure and non-secure? did you try setting it to non-secure?

    is you dhcp server a windows dhcp server? did you check the settings for option 81:

    Author Comment

    The Scavenge stale resource records option was not checked. I checked that and set both no-refresh and refresh interval at 4 days. Im not sure how long the DHCP lease is, DHCP is handled by a SonicWall that I do not have access to. I will go ahead and contact the company that manages that and see if they will tell me.

    There were two places I saw to set scavenging that seemed independent of each other. Right clicking the dns server there was "Set Aging/Scavenging for All Zones", but also if you click Properties and the Advanced tab, at the bottom there is another option to enable automatic scavenging of stale records. I turned it on in both places.

    It is AD integrated, and dynamic updates is set to secure. I will try changing to unsecure if the scavenging doesnt correct the problem.
    LVL 70

    Expert Comment

    by:Chris Dent

    Just a quick note on Scavenging again.

    You have to be rather patient with it, with your current settings it will not allow Scavenging to execute against the zone for 4 days (the value of the Refresh Interval). This is to give AD, and all the network clients, time to think about correctly writing the Time Stamp information.

    You can see the value for that if you select View / Advanced, then re-open the Aging option.

    The Scavenging option under the DNS server Properties / Advanced, states how frequently the task itself runs. I recommend setting that to 1 day on one of your Domain Controllers.

    And if the lease time is really short...

    Whatever you do, don't set a Refresh Interval less than 1 day. Records only dynamically register once every 24 hours, having a shorter Refresh interval makes a real mess.


    Author Closing Comment

    This worked out great, thanks!

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Free Trending Threat Insights Every Day

    Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

    Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
    BIND is the most widely used Name Server. A Name Server is the one that translates a site name to it's IP address. There is a new bug in BIND (, affecting all versions of BIND 9 from BIND 9.1.0 (inclusive) thro…
    Need more eyes on your posted question? Go ahead and follow the quick steps in this video to learn how to Request Attention to your question. *Log into your Experts Exchange account *Find the question you want to Request Attention for *Go to the e…
    Hi everyone! This is Experts Exchange customer support.  This quick video will show you how to change your primary email address.  If you have any questions, then please Write a Comment below!

    760 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    8 Experts available now in Live!

    Get 1:1 Help Now