Solved

DNS Tracing

Posted on 2014-11-12
7
94 Views
Last Modified: 2014-12-09
I have an unusual issue where I have a DNS entry from a vmware server that seems to be getting a bad DNS entry. So at some point I imagine it had a bad entry. When I change the entry it seems to be good for a bit but then it reverts back to the old one. It's a pretty small IT team so it would appear it's like a server with the old entry is somehow publishing the old/bad entry as newer.

Is there any way to trace on a DNS server where an entry came from and see where things are going to?
0
Comment
Question by:Brandon_V
  • 4
  • 3
7 Comments
 
LVL 17

Expert Comment

by:OriNetworks
ID: 40437969
Where are you seeing the old dns entry? I'm not sure if you mean an old dns record is listed in a zone or if a client is getting a DNS server assigned via DHCP to use when looking up DNS records.

For loggings at the DNS Server level:
Open DNS, rightclick the root and select properties
Under Debug Logging tab select Log packets and select your required options from there.
0
 

Author Comment

by:Brandon_V
ID: 40438094
so for example I have
a record that looks like below

ServerA IP: 10.1.1.1

The DNS record SHOULD be ServerA IP: 10.1.1.2

So if I change the record so there is a static entry that says ServerA IP: 10.1.1.2 what is happening is say 2-3 hours later it is back to being ServerA IP: 10.1.1.1

just side bar info the DNS is an Active Directory integrated DNS zone
0
 
LVL 17

Expert Comment

by:OriNetworks
ID: 40440263
if you do ipconfig on serverA is 10.1.1.2 the only IP address assigned?

If any other network interfaces exists it may request a new address from DHCP. Also, if you have multiple DNS servers you should probably make sure it is deleted on all or make sure DNS is correctly synchronizing between DNS servers
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:Brandon_V
ID: 40447249
Nop single NIC, no other interfaces picking up  the bad IP.
0
 
LVL 17

Expert Comment

by:OriNetworks
ID: 40450677
Does the ipconfig command list any additional ip addresses assigned to the interface?
0
 

Author Comment

by:Brandon_V
ID: 40450813
No it doesn't. I did find the issue, which is someone had configured the servers ILO to have the same name as the host. So when it updated DNS it messed it up.

Still though is there a way to setup the logging so that I could have seen that an update from Server X had the update or that the update came from hardware Address XXXXXXXX in the environment for example ?
0
 
LVL 17

Accepted Solution

by:
OriNetworks earned 500 total points
ID: 40474424
The only way I am aware of being able to find that information is to setup debugging as I described. It is low level information and it would give you the information you are looking for. Additionally there may be other utilities out there to help parse the results.
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

BIND is the most widely used Name Server. A Name Server is the one that translates a site name to it's IP address. There is a new bug in BIND (https://kb.isc.org/article/AA-01272), affecting all versions of BIND 9 from BIND 9.1.0 (inclusive) thro…
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now