Solved

A and CNAME records are being deleted.

Posted on 2009-05-14
9
546 Views
Last Modified: 2012-05-07
Hello,

We have 2 Server 2008 DNS servers that are pointing to each other for DNS. There are random records that are getting deleted or really assuming here that they are getting savaged. This leads me to believe that netlogon isn't refreshing the DNS records.

The A records are static and dynamic.

Zone is set for nonsecure and secure.

Scavenging is set to 7 days

Refresh interval is set to 1 hour.

These DNS/WINS servers are DC's.

Hope I didn't leave anything out.

Thanks!!!
0
Comment
Question by:WesterraCU
  • 5
  • 2
  • 2
9 Comments
 
LVL 9

Expert Comment

by:gregcmcse
Comment Utility
If your workstations are configured to register themselves in DNS, then they will unregister themselves when the workstation does a normal shutdown.
Is DHCP configured to register clients in DNS?
0
 

Author Comment

by:WesterraCU
Comment Utility
No DHCP server does not register the clients DNS the clients register themselves.

What's strange is that the CNAME went missing, that's a static entry as well as other A records that we're static. I've also made sure that they do not have the box checked "Delete this record when it becomes stale" on the static records.
0
 
LVL 9

Expert Comment

by:gregcmcse
Comment Utility
The CName is strange, you're right.  Unless some client is registering itself with that name.
How is DNS set up, AD Integrated?  Pointing a DNS server to another DNS server isn't the best idea, but it shouldn't cause the problems you're seeing.
Does your DNS do WINS lookups?  If so, is it possible some user has a username that is the same as the CNAME records?
Also, how are you determining that the records are missing?  Are you using NSLookup or the GUI?  Try NSLOOKUP if they're missing in the GUI -- it may just be a display issue.
0
 

Author Comment

by:WesterraCU
Comment Utility
Yes DNS is AD intergrated.

I used to always point DNS servers to themselves but we recently had a consultant come in for a AD migration project and  he had explained that doing so isolates themselves like an island. Could you explain which is better and why. I've Googled this but get such mixed reviews.

DNS and WINS are both running and running on the same servers. How would I know if DNS is doing WINS lookups.

No username with the same name as the server.

This was determined an issue due to our 3rd party apps that rely on our DNS server for resolution and once the record was gone it caused many issues. Didn't check nslookup but we had multiple calls on issues and noticed record was gone from both DNS servers.
0
6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

 

Author Comment

by:WesterraCU
Comment Utility
I also ran a dcdiag /test:dns and came back with a few issues.

Thought this might help in the troubleshooting.

Thanks!!!



   Running partition tests on : ForestDnsZones

   Running partition tests on : DomainDnsZones

   Running partition tests on : Schema

   Running partition tests on : Configuration

   Running partition tests on : TEST

   Running enterprise tests on : test.local
      Starting test: DNS
         Test results for domain controllers:

            DC: TESTDC01.test.local
            Domain: test.local


               TEST: Basic (Basc)
                  Warning: The AAAA record for this DC was not found

               TEST: Dynamic update (Dyn)
                  Warning: Failed to delete the test record _dcdiag_test_record
in zone test.local

               TEST: Records registration (RReg)
                  Network Adapter [00000013] BASP Virtual Adapter:
                     Warning:
                     Missing AAAA record at DNS server 192.168.X.XXX:
                     TESTDC01.test.local

                     Warning:
                     Missing AAAA record at DNS server 192.168.X.XXX:
                     gc._msdcs.test.local

                     Warning:
                     Missing AAAA record at DNS server 192.168.X.XXX:
                     TESTDC01.test.local

                     Warning:
                     Missing AAAA record at DNS server 192.168.X.XXX:
                     gc._msdcs.test.local

                     Warning:
                     Missing AAAA record at DNS server ::1:
                     TESTDC01.test.local

                     Warning:
                     Missing AAAA record at DNS server ::1:
                     gc._msdcs.test.local

               Warning: Record Registrations not found in some network adapters

               TESTDC01                      PASS WARN PASS PASS WARN WARN n/a
         ......................... test.local passed test DNS
0
 
LVL 70

Expert Comment

by:Chris Dent
Comment Utility

> Refresh interval is set to 1 hour.

Really?

Way way too short. Most records only refresh once every 24 hours.

Records added by DHCP only refresh at the start of the lease and at the renewal interval (half way through the lease).

Chris
0
 

Author Comment

by:WesterraCU
Comment Utility
Chris - Do you think this could by why DHCP clients were not getting updated in DNS? This was a previous issue we had and the resolution was to set the clients to update their own DNS.

Also do you believe that extending the refresh interval would solve our issue here?
0
 
LVL 70

Accepted Solution

by:
Chris Dent earned 500 total points
Comment Utility

Without knowing more about it I'd say it would.

The minimum you should consider for the Refresh Interval is 24 hours. Longer is better as it allows room for mistakes.

If DHCP were updating for clients they would Refresh at intervals equal to half of the lease. For example, if the lease is 8 days, they refresh once every 4 days.

Chris
0
 

Author Closing Comment

by:WesterraCU
Comment Utility
Chris - Thanks so much!! It's all so clear to me now. :) Our consultant changed this setting for a temp fix and never changed it back.

Thanks for everyone's responses.
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Join & Write a Comment

You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now