Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

DHCP not updating DNS

Posted on 2010-09-14
24
Medium Priority
?
1,596 Views
Last Modified: 2012-05-10
Microsft Server 2003 DHCP Server
Microsoft Server 2003 DNS Server


Most of the time the DHCP server assigns an Address and then updates the associated DNS entry.  But other times it does not.    When I check the DHCP server, I see the icons to the left of the entry with a pen over the computer.  When I see that, that piticular entry does not show up in DNS, or has not been updated.

Anyone familiar with this problem.

I know the settings are right cause most of the time it works fine.

Sometimes if I Restart the DHCP and DNS Servers, and then renew the IP it will update.

See the attached image for what I see in my DHCP manager.

 DHCP Server Entries
0
Comment
Question by:NicholsSchool
  • 11
  • 5
  • 2
  • +4
23 Comments
 
LVL 5

Expert Comment

by:jhill777
ID: 33674846
How about an ipconfig /flushdns and then /registerdns and scavenging stale records on the DNS server?
0
 
LVL 20

Expert Comment

by:Michel Sakr
ID: 33674878
Did you check the DHCP log for errors?
Try to nslookup from such a client machine and see if you get results.. you maight be facing communication problems between the DHCP and DNS
0
 
LVL 24

Expert Comment

by:rfc1180
ID: 33674916
>Most of the time the DHCP server assigns an Address and then updates the associated DNS entry.
it is not the DHCP server that updates the DNS server, the client is the one that will need to update the DNS server (there is an option to select register with DNS in the TCP/IP properties dialog box [dynamic updates]). The methods that jhill777 should hopefully resolve the issue.

Billy
0
Prepare for your VMware VCP6-DCV exam.

Josh Coen and Jason Langer have prepared the latest edition of VCP study guide. Both authors have been working in the IT field for more than a decade, and both hold VMware certifications. This 163-page guide covers all 10 of the exam blueprint sections.

 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 33674951
Check to make sure your DHCP setting lease only internal DNS servers to the clients.

0
 

Author Comment

by:NicholsSchool
ID: 33675032
Should my aging be in days or hours?  I already had it set.  Maybe my aging is the issue?
dns1.JPG
dns2.JPG
0
 

Author Comment

by:NicholsSchool
ID: 33675096
I have DHCP set to automatically update DNS
dhcp2.JPG
0
 
LVL 24

Expert Comment

by:rfc1180
ID: 33675127
interesting, you learn something new everyday. I did not know that!
0
 

Author Comment

by:NicholsSchool
ID: 33675183
I did this on a client ... ipconfig /flushdns and then /registerdns....  No Change.  Still not registered in DNS
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 33675200
With clients running 2000 and above DDNS is not required since the clients update DNS on their own.
0
 
LVL 5

Expert Comment

by:jhill777
ID: 33675745
Did you scavenge the stale records?
0
 

Author Comment

by:NicholsSchool
ID: 33676071
Yes, I did scavenge the stale records.


Also I check Event Viewer, and really nothing in there explaining my errors.
0
 
LVL 6

Expert Comment

by:MISOperations
ID: 33676097
ipconfig /flushdns

ipconfig /renew
0
 

Author Comment

by:NicholsSchool
ID: 33676568
ried that also

ipconfig /flushdns

ipconfig /renew
0
 
LVL 5

Accepted Solution

by:
jhill777 earned 400 total points
ID: 33682782
How long has it been like that?  The pen icon means "Active lease, DNS dynamic update pending. This address is not available for lease by the DHCP server.  Is the DHCP server added to the DnsUpdateProxy Group?
0
 
LVL 5

Expert Comment

by:jhill777
ID: 33682840
Also:  This happens in cases where the client machine is not joined to the domain and has a missing or
different suffix than the zone in DNS. It can only register into a zone that exists on DNS and that zone updates have been configured to allow updates.  If this is the case, go into the client machine's IP properties, and on the DNS tab in TCP/IP properties, clear the "Register this connection's addresses in DNS" as well as the "Use this connection's DNS suffix in DNS registration" check boxes, the DHCP Server will fill these in for you and register using the domain name.
0
 

Author Comment

by:NicholsSchool
ID: 33744248
So I enabled DHCP Logging, and found this

1,09/23/10,09:47:19,Renew,192.168.107.187,USLIBRARY16.nicholsschool.org,0024217B3A1A,
31,09/23/10,09:47:23,DNS Update Failed,172.18.102.160,6730-MROCKWELL.nicholsschool.org,-1,
31,09/23/10,09:47:58,DNS Update Failed,172.18.110.78,lckipod.nicholsschool.org,-1,
31,09/23/10,09:48:33,DNS Update Failed,172.18.102.158,r60-tmaynor.nicholsschool.org,-1,
30,09/23/10,09:49:11,DNS Update Request,87.110.18.172,iPod-touch.nicholsschool.org,,
11,09/23/10,09:49:11,Renew,172.18.110.87,iPod-touch.nicholsschool.org,00224188B199,
30,09/23/10,09:49:24,DNS Update Request,79.110.18.172,BLACKBERRY-BE70.nicholsschool.org,,
11,09/23/10,09:49:24,Renew,172.18.110.79,BLACKBERRY-BE70.nicholsschool.org,0026FF40C316,
30,09/23/10,09:49:35,DNS Update Request,93.110.18.172,Shane-Lee.nicholsschool.org,,
11,09/23/10,09:49:35,Renew,172.18.110.93,Shane-Lee.nicholsschool.org,0026BBC84899,
31,09/23/10,09:49:44,DNS Update Failed,172.18.110.69,iPod-de-Elsa.nicholsschool.org,-1,
31,09/23/10,09:49:44,DNS Update Failed,172.18.110.95,Joshua-PC.nicholsschool.org,2,
30,09/23/10,09:49:44,DNS Update Request,95.110.18.172,Joshua-PC.nicholsschool.org,,
11,09/23/10,09:49:44,Renew,172.18.110.95,Joshua-PC.nicholsschool.org,002682B37741,

Numerous DNS Update Failed error messages.

Going to look into the DNS logging now
0
 
LVL 3

Expert Comment

by:elmagoal
ID: 33744521
Make sure that the register with DNS on th eclient is check and the suffix is correct.


DNS.JPG
0
 

Author Comment

by:NicholsSchool
ID: 33744614
So I see this in the DHCP Log

30,09/23/10,10:14:17,DNS Update Request,163.107.168.192,USLIBRARY18.nicholsschool.org,,
11,09/23/10,10:14:17,Renew,192.168.107.163,USLIBRARY18.nicholsschool.org,0024217B39F9,
31,09/23/10,10:14:19,DNS Update Failed,192.168.107.163,USLIBRARY18.nicholsschool.org,2,


and in the DNS LOG I see this


20100923 10:14:17 678 PACKET  01E258A0 UDP Rcv 192.168.107.163 7314   Q [0001   D   NOERROR] SOA   (11)USLIBRARY18(13)nicholsschool(3)org(0)
UDP question info
  Socket = 460, recvd on port (65535)
  Remote addr 192.168.107.163, port 63976
  Time Query=23942, Queued=0, Expire=0
  Buf length = 0x0500 (1280)
  Msg length = 0x002f (47)
  Message:
    XID       0x7314
    Flags     0x0100
      QR        0 (QUESTION)
      OPCODE    0 (QUERY)
      AA        0
      TC        0
      RD        1
      RA        0
      Z         0
      RCODE     0 (NOERROR)
    QCOUNT    1
    ACOUNT    0
    NSCOUNT   0
    ARCOUNT   0
    QUESTION SECTION:
    Offset = 0x000c, RR count = 0
    Name      "(11)USLIBRARY18(13)nicholsschool(3)org(0)"
      QTYPE   SOA (6)
      QCLASS  1
    ANSWER SECTION:
      empty
    AUTHORITY SECTION:
      empty
    ADDITIONAL SECTION:
      empty

20100923 10:14:17 678 PACKET  01E258A0 UDP Snd 192.168.107.163 7314 R Q [8085 A DR  NOERROR] SOA   (11)USLIBRARY18(13)nicholsschool(3)org(0)
UDP response info
  Socket = 460, recvd on port (65535)
  Remote addr 192.168.107.163, port 63976
  Time Query=23942, Queued=0, Expire=0
  Buf length = 0x0200 (512)
  Msg length = 0x007b (123)
  Message:
    XID       0x7314
    Flags     0x8580
      QR        1 (RESPONSE)
      OPCODE    0 (QUERY)
      AA        1
      TC        0
      RD        1
      RA        1
      Z         0
      RCODE     0 (NOERROR)
    QCOUNT    1
    ACOUNT    0
    NSCOUNT   1
    ARCOUNT   1
    QUESTION SECTION:
    Offset = 0x000c, RR count = 0
    Name      "(11)USLIBRARY18(13)nicholsschool(3)org(0)"
      QTYPE   SOA (6)
      QCLASS  1
    ANSWER SECTION:
      empty
    AUTHORITY SECTION:
    Offset = 0x002f, RR count = 0
    Name      "[C018](13)nicholsschool(3)org(0)"
      TYPE   SOA  (6)
      CLASS  1
      TTL    480
      DLEN   48
      DATA  
            PrimaryServer: (11)nichols-ad1[C018](13)nicholsschool(3)org(0)
            Administrator: (11)supportinfo[C018](13)nicholsschool(3)org(0)
            SerialNo     = 368641
            Refresh      = 900
            Retry        = 600
            Expire       = 3600
            MinimumTTL   = 480
    ADDITIONAL SECTION:
    Offset = 0x006b, RR count = 0
    Name      "[C03B](11)nichols-ad1[C018](13)nicholsschool(3)org(0)"
      TYPE   A  (1)
      CLASS  1
      TTL    480
      DLEN   4
      DATA   192.168.71.16

20100923 10:14:17 678 PACKET  02313AC0 UDP Rcv 192.168.107.163 7864   U [0028       NOERROR] SOA   (13)nicholsschool(3)org(0)
UDP question info
  Socket = 460, recvd on port (65535)
  Remote addr 192.168.107.163, port 56494
  Time Query=23942, Queued=0, Expire=0
  Buf length = 0x0500 (1280)
  Msg length = 0x0068 (104)
  Message:
    XID       0x7864
    Flags     0x2800
      QR        0 (QUESTION)
      OPCODE    5 (UPDATE)
      AA        0
      TC        0
      RD        0
      RA        0
      Z         0
      RCODE     0 (NOERROR)
    ZCOUNT    1
    PRECOUNT  1
    UPCOUNT   2
    ARCOUNT   0
    ZONE SECTION:
    Offset = 0x000c, RR count = 0
    Name      "(13)nicholsschool(3)org(0)"
      ZTYPE   SOA (6)
      ZCLASS  1
    PREREQUISITE SECTION:
    Offset = 0x0023, RR count = 0
    Name      "(11)USLIBRARY18(13)nicholsschool(3)org(0)"
      TYPE   CNAME  (5)
      CLASS  254
      TTL    0
      DLEN   0
      DATA   (none)
    UPDATE SECTION:
    Offset = 0x004c, RR count = 0
    Name      "[C023](11)USLIBRARY18(13)nicholsschool(3)org(0)"
      TYPE   A  (1)
      CLASS  255
      TTL    0
      DLEN   0
      DATA   (none)
    Offset = 0x0058, RR count = 1
    Name      "[C023](11)USLIBRARY18(13)nicholsschool(3)org(0)"
      TYPE   A  (1)
      CLASS  1
      TTL    1200
      DLEN   4
      DATA   192.168.107.163
    ADDITIONAL SECTION:
      empty

20100923 10:14:17 2A4 PACKET  02313AC0 UDP Snd 192.168.107.163 7864 R U [00a8       NOERROR] SOA   (13)nicholsschool(3)org(0)
UDP response info
  Socket = 460, recvd on port (65535)
  Remote addr 192.168.107.163, port 56494
  Time Query=23942, Queued=0, Expire=0
  Buf length = 0x0500 (1280)
  Msg length = 0x0068 (104)
  Message:
    XID       0x7864
    Flags     0xa800
      QR        1 (RESPONSE)
      OPCODE    5 (UPDATE)
      AA        0
      TC        0
      RD        0
      RA        0
      Z         0
      RCODE     0 (NOERROR)
    ZCOUNT    1
    PRECOUNT  1
    UPCOUNT   2
    ARCOUNT   0
    ZONE SECTION:
    Offset = 0x000c, RR count = 0
    Name      "(13)nicholsschool(3)org(0)"
      ZTYPE   SOA (6)
      ZCLASS  1
    PREREQUISITE SECTION:
    Offset = 0x0023, RR count = 0
    Name      "(11)USLIBRARY18(13)nicholsschool(3)org(0)"
      TYPE   CNAME  (5)
      CLASS  254
      TTL    0
      DLEN   0
      DATA   (none)
    UPDATE SECTION:
    Offset = 0x004c, RR count = 0
    Name      "[C023](11)USLIBRARY18(13)nicholsschool(3)org(0)"
      TYPE   A  (1)
      CLASS  255
      TTL    0
      DLEN   0
      DATA   (none)
    Offset = 0x0058, RR count = 1
    Name      "[C023](11)USLIBRARY18(13)nicholsschool(3)org(0)"
      TYPE   A  (1)
      CLASS  1
      TTL    1200
      DLEN   4
      DATA   192.168.107.163
    ADDITIONAL SECTION:
      empty
0
 

Author Comment

by:NicholsSchool
ID: 33744712
I have made sure on the client that Register this connection's addresses in DNS in Checked.
0
 

Author Comment

by:NicholsSchool
ID: 33744735
2 minutes later this cliient finally updated DNS

32,09/23/10,10:19:04,DNS Update Successful,192.168.107.163,USLIBRARY18.nicholsschool.org

but this is not true for all clients.
0
 

Author Comment

by:NicholsSchool
ID: 33746733

Here is little bits that seemed to solve my problem.


Add the DHCP server to the DnsUpdateProxy Group.

If your DHCP servers are Windows 2003 or WIndows 2008, Configure a dedicated the user account you created as credentials in DHCP by going into DHCP COnsole, DHCP server properties, and on the Advanced tab of the DHCP Server Properties sheet click the Credentials button, and provide this account info. The user account does not need any elevated rights, a normal user account is fine, however I recommend using a Strong non-expiring password on the account.

But more importantly, if DHCP is on a DC, it will not overwrite the original host record for a machine getting a new lease with an IP formerly belonging to another. To overcome this, add the DHCP server (the DC) to the DnsProxyUpdate group. This will force DHCP to own all records it will create moving forward and will update an IP with a new name in DNS.

I added the Dedicated user to each DNS forward and reverse lookup zones, with FULL permissions.



This seems to have solved my problem.
0
 
LVL 5

Assisted Solution

by:jhill777
jhill777 earned 400 total points
ID: 33772866
I  33682782:  Suggested adding server to the DnsProxyUpdate group.
0
 

Author Closing Comment

by:NicholsSchool
ID: 33778283
jhill777 solution was part of the issue.  It did nto fix the issue.  It took me adding the user account to all the DNS zones.
0

Featured Post

Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I've written instructions for one router type, but this principle may be useful for others of the same brand and even other brands of router. Problem: I had an issue especially with mobile devices that refused to use DNS information supplied via…
Learn about cloud computing and its benefits for small business owners.
When cloud platforms entered the scene, users and companies jumped on board to take advantage of the many benefits, like the ability to work and connect with company information from various locations. What many didn't foresee was the increased risk…
Enter Foreign and Special Characters Enter characters you can't find on a keyboard using its ASCII code ... and learn how to make a handy reference for yourself using Excel ~ Use these codes in any Windows application! ... whether it is a Micr…

575 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question