Solved

Importing DNS Records

Posted on 2009-07-09
8
286 Views
Last Modified: 2012-05-07
Issue:

My company has about 150 remote sites that connect to company HQ via vpn.  Each site has a router that is managed by a third party.  This third party has set up nating on the routers so that, for example, a computer at a site has an internal IP of 10.61.198.178, and the site router nats it to another internal IP of 172.16.20.10 .  And so while the 10.61.198.178 address is unique to the device at that site, the 172.16.20.10 is used across the board for all 150 sites.  This is problematic when trying to push updates to computers at these sites because the dns records for all 150 sites are going to be 172.16.20.10 and the update does not know where to go.  Previously, I had manually entered in 150 A records into DNS for the unique IP addresses at each site and that worked - updates were able to be pushed.  A couple of days ago though, all of the records reverted to 172.16.20.10 across the board - I have no idea why.  I do have a dns backup with the A records I created, but I don't know what will happen if I import them back into DNS.  I'm afraid that may hose our network.  So I guess the question is two-fold:

1.  Is there a way for the A records to not randomly revert to the generic IP address?  Is there a reason why this would occur when the records had been in place for several weeks?

2.  Is there a way to re-import the A records for just these sites without overwriting DNS records for the entire network?
0
Comment
Question by:NRL71
  • 5
  • 3
8 Comments
 
LVL 70

Expert Comment

by:Chris Dent
Comment Utility

Which DNS system are we dealing with here?

It's very difficult to say how the zone changed. Do you allow dynamic updates on the zone?

2 has an easy answer though. Pretty much every DNS system will allow you to bring records in without having to resort to a one-at-a-time approach. Kind of need to know which DNS system to be more specific though.

Chris
0
 

Author Comment

by:NRL71
Comment Utility
It is Microsoft Windows Server 2003 R2.  DNS is set up to dynamically update.

In regards to Q2, I think I need to import the records one at a time because wouldn't importing in the entire backup I have overwrite all records?  I think that could cause network issues.  
0
 
LVL 70

Expert Comment

by:Chris Dent
Comment Utility

It depends how you make the change. If I were to do it I'd only alter the set of records relating to this. Is that likely to cause a problem?

Secure Updates or secure and non-secure?

Chris
0
 

Author Comment

by:NRL71
Comment Utility
Secure updates.
0
What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 

Author Comment

by:NRL71
Comment Utility
Also, how would you import individual DNS records?  I've looked around but the only way I have found is to import the entire backup which I don't want to do.
0
 

Author Comment

by:NRL71
Comment Utility
I resolved the issue of importing just the 150 A records by using dnscmd and scripting it out for the records I neeedd.  I'm still curious as to why it changed all of the records after they had been in place for several weeks.  
0
 
LVL 70

Accepted Solution

by:
Chris Dent earned 500 total points
Comment Utility

Sorry had to head home. I'm curious about how it did that as well. Were the records previously dynamically added?

Chris
0
 

Author Comment

by:NRL71
Comment Utility
The original records were updated dynamically.  I manually overrode them by adding in the A records which lasted for a few weeks and then reverted back to the generic nat address.
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

Suggested Solutions

One of the most often confused topics in the area DNS is the idea of GLUE records. Specifically, what they are, when they are needed, when they are provided, and how they are created. First, WHAT IS GLUE? To understand GLUE, you must first under…
Resolve DNS query failed errors for Exchange
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now