Solved

DHCP/DNS Conflicts

Posted on 2014-03-03
7
749 Views
Last Modified: 2014-03-05
We at times have issues with DNS IP conflicts. The IP that a client actually has in DHCP does not necessarily match what is in DNS. This means stale records in DNS. If I do an ipconfig /registerdns from a client experiencing the mismatch, there is no change to the client's DNS record. I would assume that it is always supposed to replace the existing DNS record, correct?

I know we need to tweak our DHCP lease times and maybe our DNS scavenging. Our clients are mostly desktops that do not change. Please give me your opinion on the ideal settings. Currently our DHCP leases are 1 day, our DNS no-refresh interval is 7 days, and our DNS refresh interval is 7 days.
0
Comment
Question by:MCSF
7 Comments
 
LVL 13

Expert Comment

by:Santosh Gupta
ID: 39901591
hi,

1. first delete all A records related to desktop from DNS.
2. set DHCP lease period to 21 days.
0
 

Author Comment

by:MCSF
ID: 39901601
The majority of our DNS records are correct. I would think deleting all desktop A records would create short-term chaos.

Just curious - how did you come up with 21 days?

Should an ipconfig /registerdns always replace the A record or only if there is no A record?
0
 
LVL 4

Expert Comment

by:aa-denver
ID: 39901663
I'm assuming this is a windows environment

You can turn on DNS registration on the DHCP server for all clients whether they attempt to register or not.  Have DHCP create, update, and or delete the A and PTR records.    This will start cleaning up DNS for you.

The other thing you can do to help clean up DNS is create a GPO for the clients to enable DNS client registration.  That way clients will also begin registering with DNS.

I would set the leases much shorter so that this all happens in a smaller time frame.  The default windows lease is 8 days.  You could set the lease to 2 days, or even 1 day.  You don't mention how big of an environment this is.  But if it is less than 1000 users or so, that should be fine and not overload DCs.

Then you could turn on DNS scavenging.   When you do turn on DNS scavenging set the lease back to 8 days.  Set the refresh interval to 7 days.  Also set the no-refresh interval to 7 days.  And also set the server scavenging cycle to 7 days.   All of these things come into play when scavenging.  Microsoft has set them that way for a reason.

Here's a reference on tricky things that can happen with scavenging.

https://blogs.technet.com/b/networking/archive/2008/03/19/don-t-be-afraid-of-dns-scavenging-just-be-patient.aspx


http://blogs.technet.com/b/askpfe/archive/2011/06/03/how-dns-scavenging-and-the-dhcp-lease-duration-relate.aspx
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 4

Assisted Solution

by:aa-denver
aa-denver earned 250 total points
ID: 39901689
I just reread your post.  You have DNS scavenging enabled.  One issue  is the 1 day lease, 7 day refresh, 7 day no refresh, etc.  Unless you are running short of IP addresses, put the lease back to 8 days.   What is the server scavenging interval?  7 days.

If you have to keep the leases at 1 day, set the refresh and no-refresh intervals to 2 days each and the scavenging interval to 2 days.  

Read those two articles that i referenced in my previous post.
0
 

Author Comment

by:MCSF
ID: 39903181
aa-denver - I think I will set the DHCP lease back to 8 days. I will start with a couple scopes and work my way up. I am pretty sure it was set to 1 day because we were running out of IPs several years ago. Our subnets have since expanded, so that is not a problem anymore.

Does anyone know the default behavior of running ipconfig /registerdns from a client? If we run this from a client that has a stale DNS record I would expect it to refresh the stale record, but it does not. Is it supposed to?
0
 
LVL 40

Accepted Solution

by:
footech earned 250 total points
ID: 39905302
Not necessarily.
Assuming you have zones which allow secure dynamic updates:  If a record with the same name does not exist, it will be created.  If a record with the same name does exist it will be updated if the security on the record allows it.  For records created by the DHCP server, the client may not have the permissions needed to update the record.
0
 

Author Comment

by:MCSF
ID: 39907626
We will work toward an 8 day DHCP lease on all scopes to start and will continue to monitor why our DNS isn't dynamically updating the way we would hope. Thanks for your advice!
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

One of the most often confused topics in the area DNS is the idea of GLUE records. Specifically, what they are, when they are needed, when they are provided, and how they are created. First, WHAT IS GLUE? To understand GLUE, you must first under…
Occasionally you run into the website or two that will not resolve properly using your own DNS servers.  Some people simply set up global forwarders for their DNS server.  I don’t recommend doing this because it can cause problems resolving addresse…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question