Solved

Exchange and PTR records - Question

Posted on 2011-02-28
7
893 Views
Last Modified: 2013-11-30
We run Exchange 2007 at our company.  One Exchange Oganization, with each division having at least a Hub/CA Exchange server at thier site. Our site is the primary location with MX records pointing to the A records that resolves to our mail gateway here. At the remote sites, they each route outbound mail through their Exchange server, but internal and received mail is all routed internally through our location here at the hub site.

We are moving to a MPLS WAN from our current VPN / multi IPS based WAN. We have had to work with each ISP to register PTR records to allow for reverse lookup's from those recipients who require this PTR record to be something other than blank or the generic arpa response.

With this migration we also acquired several large blocks of public IP's. We have our new provider advertising these IP's for us. However they say that they cannot create the pointer records because they do not own the IP's. They just advertise them for us.

Here is the question..  because we own the IP's but our MPLS provider advertises them, does this mean we need to set up a public DNS server and create our own PRT records? Or do they STILL NEED to be set up on the ISP's end ???

OR is there any way to do this with Exchange? How does a reverse lookup determine what FQDN is associated to that IP? Does it get this by looking up who owns the IP or by who advertises the IP?







0
Comment
Question by:munisee
7 Comments
 
LVL 6

Expert Comment

by:rnicolaus
ID: 34999116
The ISP must setup the reverse DNS for you.  They technically "own" the IP.
0
 

Author Comment

by:munisee
ID: 34999539
Ok, that is what I was struggling with. Sprint is saying that because we own the IP's, they can't set the PTR records for us.

Can I ask you do you have anything I can present as evidence to back this up? I have been in these back and forth struggles with providers before and I need to find something other than 'I was told' to back me up. Perhaps an RFC?






0
 
LVL 11

Accepted Solution

by:
MichaelVH earned 250 total points
ID: 34999983
Munisee;

where did you buy these IP's from? Normally the seller should be able to create the rDNS's for you.

Michael
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 
LVL 16

Expert Comment

by:Enphyniti
ID: 34999995
Are you sure you don't have a PTR for your IP?

Have you tried a "ping -a xxx.xxx.xxx.xxx" for your public IP?  If there is any type of PTR record setup for the IP it will say

"Pinging <your PTR record here>"

Otherwise ask to be escalated or to speak to a DNS administrator.  If it's an ISP then *someone* there has to understand how DNS works.
0
 
LVL 6

Assisted Solution

by:rnicolaus
rnicolaus earned 250 total points
ID: 35000498
The pertinent question might be then, who hosts your DNS?  If it's not Sprint, they could play that game.  But the ISP is the one who provisioned the IP block, correct? (Is that Sprint?) If so then they are responsible for the PTR records
0
 

Author Comment

by:munisee
ID: 35150534
Turns out, and thank you for helping, that we are stuck in limbo with Arin with the tranfer of ownership for these new IP's we own. It's tricky in the sense that we had about 20,000 of them and since we are keeping just a small portion and gave the rest back to Arin, they need to re-allocate the new, smaller block to us and with all paperwork in line we should be able to register whatever NS we want with Sprint. Or even Sprint for that matter.

So, thank you for helping. I have to close this and move on. I learned quite a bit about DNS function at the IPS/Arin level through this project. What a great experience.
0
 

Author Closing Comment

by:munisee
ID: 35150558
You are were correct, however the two I accepted helped the most. It all came down to Arin and getting the IP's registered as belonging to my company, not the previous owner. However, the previous owner still had a couple name servers that the IP's were registered with through Arin. So we just fired them up and are using those until the red tape crap is done. Thanks!
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
LAN or WAN ? 11 63
ESXi VLAN Lab 2 34
Connecting LAN to a new leased line 2 25
EIGRP on point-to-point vlan 14 27
I wrote this article to explain some important DNS concepts that should be known to avoid some typical configuration errors I often see in forums. I assume that what is described here is the typical behavior of Microsoft DNS client. I don't know …
Even if you have implemented a Mobile Device Management solution company wide, it is a good idea to make sure you are taking into account all of the major risks to your electronic protected health information (ePHI).
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now