Solved

Enabled DNS scavenging and now 3 of my 5 reverse DNS zones were mostly deleted.

Posted on 2014-04-09
7
407 Views
Last Modified: 2014-04-14
I enabled DNS scavenging and now three of the five reverse DNS zones had most of the clients removed. I am not sure why the other two are OK. They just had old records removed but the other three had pretty much everything removed. Why did this happen? How can I make sure reverse DNS is going to update correctly from now on? This is for 2008 windows server DNS integrated zones.

Thanks,


Justin
0
Comment
Question by:JustinGSEIWI
  • 3
  • 2
7 Comments
 
LVL 13

Assisted Solution

by:Santosh Gupta
Santosh Gupta earned 250 total points
ID: 39990275
Hi,


lets enable the Tracking of DNS Record Deletion and see how and why records are getting deleted.

http://blogs.technet.com/b/networking/archive/2011/08/17/tracking-dns-record-deletion.aspx

Also check the below options.

dsn
0
 

Author Comment

by:JustinGSEIWI
ID: 39991706
I enabled the recommended setting on my scavenging DNS server. The settings are the same as your picture above except I changed it "always dynamically update." Should I do this on all five of my DNS servers? I am thinking I will need to, especially the ones that have mostly empty reverse DNS zones at the moment.

Someone else told me to wait because DHCP clients only update reverse DNS every 24 hours or so. Do you agree with this?

Also, the records disappeared after I told the server to scavenge DNS records. The event log below was logged when this happened.

Event Type:      Information
Event Source:      DNS
Event Category:      None
Event ID:      2501
Date:            4/9/2014
Time:            2:46:57 PM
User:            N/A
Computer:      DC01.ad.gs.org
Description:
The DNS server has completed a scavenging cycle:
Visited Zones     = 9,
Visited Nodes     = 693,
Scavenged Nodes   = 259,
Scavenged Records = 264.
 
This cycle took 1 seconds.
 
The next scavenging cycle is scheduled to run in 168 hours.
 
The event data will contain the error code if there was an error during the scavenging cycle.



I am thinking the "always dynamically update" setting will eventually fix this if I give it a couple of days. What do you think?

Thank you,

Justin
0
 
LVL 39

Accepted Solution

by:
footech earned 250 total points
ID: 39992215
I would definitely give it a few days to let it populate.  If you look in the DNS Management console, you should see the timestamps for all the records being updated.  The records are refreshed depending on your configured refresh and no-refresh intervals.  So once a record is refreshed, you shouldn't see another update to the record until at least the no-refresh interval has passed.  The following link should help you understand how this works.
http://blogs.technet.com/b/networking/archive/2008/03/19/don-t-be-afraid-of-dns-scavenging-just-be-patient.aspx
0
Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

 
LVL 39

Expert Comment

by:footech
ID: 39996934
I got a notification that an administrative comment was posted in this thread, but there is no comment, and the thread is re-opened.  What's going on?
0
 
LVL 39

Expert Comment

by:footech
ID: 39997716
Very well, no objection.
0
 
LVL 13

Expert Comment

by:Santosh Gupta
ID: 39998977
Pleased to help you..
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
LINUX, CPANEL & WHM 5 21
Expand C partition 13 20
Folder NTFS Permissions 14 68
Understanding Security Log Events 2 12
Occasionally you run into the website or two that will not resolve properly using your own DNS servers.  Some people simply set up global forwarders for their DNS server.  I don’t recommend doing this because it can cause problems resolving addresse…
Resolve DNS query failed errors for Exchange
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now