Solved

DNS domain records priority

Posted on 2011-02-18
5
354 Views
Last Modified: 2012-05-11
I am having an issue when a user in the home office pings the domain (ping test.org) the DNS response is NOT from the closest DC, or even one in the site.

How do I change this?

Thanks

0
Comment
Question by:ncfbins
  • 2
  • 2
5 Comments
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 34926722
How is the user connected, VPN of some sort? Make sure that in the vpn setup the domain DNS server (the DC?) is given as the first DNS server.
It's a little bit limited information so I can only give a limited anser :-~
0
 
LVL 1

Author Comment

by:ncfbins
ID: 34926903
The user is local, on the domain.
WIndows 2003 mode. AD integrated DNS.
0
 
LVL 42

Accepted Solution

by:
kevinhsieh earned 125 total points
ID: 34927293
Well, there are two things to consider. Do you have Active Directory Sites and Services configured for all of you sites and subnets?

Ping isn't the right test. DNS doesn't return the closest DC, it returns a list of all DCs in a rotating order. Better to run 'set' from command line and look for the value of logonserver, which should be the local DC.
0
 
LVL 1

Author Comment

by:ncfbins
ID: 34927373
Well, there are two things to consider. Do you have Active Directory Sites and Services configured for all of you sites and subnets?

Yes. Just ran through an AD risk assesment and analysis.

Ping isn't the right test. DNS doesn't return the closest DC, it returns a list of all DCs in a rotating order. Better to run 'set' from command line and look for the value of logonserver, which should be the local DC.

the logon server IS a local DC.

My issue is also with DFS name spaces. Which is where this all began.
0
 
LVL 42

Expert Comment

by:kevinhsieh
ID: 34928719
Is the problem that you hit the wrong DFS namespace server, or the wrong DFS namespace target? If you are browsing folders in a DFS namespace, you can right click on a folder, go to the DFS tab and see which server you are connected to. It should show that the active copy is on a local server. If it doesn't, you probably don't have Sites and Services properly configured, though it's possible that the DFS client will pick a server that isn't the closest, that normally doesn't happen if things are setup properly. I have no idea what you are talking about with "AD risk assessment and analysis". Here is a link to the Technet article for managing Sites and Services.

http://technet.microsoft.com/en-us/library/bb727051.aspx

The domain controller needs to be moved to the correct site.
http://technet.microsoft.com/en-us/library/bb727062.aspx#E05B0AA
0

Featured Post

DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Claiming a Domain Name 7 35
Export a GPO and import a GPO 3 44
MS Endpoint Protection 2 25
remove computer from using logon script 17 21
I've written instructions for one router type, but this principle may be useful for others of the same brand and even other brands of router. Problem: I had an issue especially with mobile devices that refused to use DNS information supplied via…
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question