jacked up dns 'same as parent' host record

Posted on 2011-09-29
Medium Priority
Last Modified: 2012-05-12
Why / How could there be a Host (A) record in a DNS zone with a name (same as parent folder) that has a data value of

Environment is a single AD domain, DNS is integrated, multiple sites, multiple subnets for each site.
This happens to be a remote site that has 5 subnets.  One of which is

Before just deleting it, we'd love to understand how it came to be and how MS DNS would allow a 'Host' record to be x.x.x.0.  Maybe that's common, never done it before.
Question by:AdaMich
  • 3
  • 2
LVL 44

Accepted Solution

Adam Brown earned 1336 total points
ID: 36818515
MS DNS will let any IP address be a host record. If your subnet mask is you are probably safe to delete it (assuming there is another Same as Parent IP that points to a Domain Controller). DNS doesn't limit the IP addresses that can be associated to hosts. Only the Subnet Mask does that, and DNS doesn't pay attention to Subnet Masks. For instance, a Server *can* be assigned an IP of if it is on a subnet mask of (or some other). The only reason you can't use on a subnet is because that host address is set aside as the Network ID.
LVL 44

Assisted Solution

by:Adam Brown
Adam Brown earned 1336 total points
ID: 36818521
Note that the entry may have been added erroneously by an admin at some point if the subnet mask is on that subnet. Otherwise you should make sure you don't actually have a server on that IP address.

Author Comment

ID: 36818605
Yeah, each subnet has a /24 mask and no server on that particular network.  Just clients.
The  is the network ID, hence my suprise to see it listed as though we could use it in a query.
All the others are correct.

Thanks for the reminder on the host with ip ending in '0'...been using simple segmentation methods too long :)

I don't think it was an erroneous addition, and that is the part that concerns me.
I mean..it could have been, but if not, I'd like to know where it came from.
Easily Design & Build Your Next Website

Squarespace’s all-in-one platform gives you everything you need to express yourself creatively online, whether it is with a domain, website, or online store. Get started with your free trial today, and when ready, take 10% off your first purchase with offer code 'EXPERTS'.

LVL 44

Expert Comment

by:Adam Brown
ID: 36818612
hard to say where it came from without having audit information from when it was created. That's always one of the tricky parts of IT management :D
LVL 24

Assisted Solution

Sandeshdubey earned 664 total points
ID: 36889997
It seems the dns records were change manually.If you have not applied then some other administrator
has done the same.For future process enable Audit Directory Service Access on the DC if it is not enabled.If any addition or deletion is done you can track the same. It will also audit the changes to Active Directory.

For e.g if Audit Directory Service Access is enabled on the machines where DNS is running then in security log you will see the following events  for deleting a DNS record.If it is not enabled then the event will be not logged.

Event Type: Success Audit
Event Source: Security
Event Category: Directory Service Access
Event ID: 566
Date:  8/23/2006
Time:  7:28:30 PM
User:  [perp]
Computer: [dns server]
Object Operation:
  Object Server: DS
  Operation Type: Object Access
  Object Type: dnsNode
  Object Name: DC=Test,DC=zone.com,CN=MicrosoftDNS,CN=System,DC=zone,DC=com
  Handle ID: -
  Primary User Name: [computer name]$
  Primary Domain: [Domain]
  Primary Logon ID: (0x0,0x3E7)
  Client User Name: administrator
  Client Domain: [domain]
  Client Logon ID: (0x0,0x729EE07)
  Accesses: Write Property
 Write Property
  Default property set

  Additional Info:
  Additional Info2:
  Access Mask: 0x20


Author Closing Comment

ID: 36891376
Thanks for the responses.
I guess I was just fishing to validate, or invalidate, an automatic entry.
Off to delete the bogus bugger.

Featured Post

Easily manage email signatures in Office 365

Managing email signatures in Office 365 can be a challenging task if you don't have the right tool. CodeTwo Email Signatures for Office 365 will help you implement a unified email signature look, no matter what email client is used by users. Test it for free!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
You have missed a phone call. The number looks like it belongs to the bunch of numbers which your company uses. How to find out who has just called you?
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question