Link to home
Start Free TrialLog in
Avatar of compdigit44
compdigit44

asked on

Active Directory CName Records

We have a mix of Windows 2012 and 2016 DC's and have DNS auditing enabled and used by a third party application for auditing. I have noticed the DC's CNAME record get added then removed with the action being request by the DC the record is for. Is this normal?
Avatar of arnold
arnold
Flag of United States of America image

Which records are being added as CNAMES, not sure I can answer based on a general question.
DC's would usually have A records rather than CNAME records

There are GUID CNAME records in _msdcs, are there the records that you are referring to ?
_msdcs is managed dynamically, so adding and removing entries for services is nothing unusual there.
CNAME records contains DC GUID and should not change unless you demote / promote domain controllers, only time stamp should get updated time to time

Check if you have CNAME records for all DCs and if you ping them, each of them should be able to resolve to correct domain controller
Avatar of compdigit44
compdigit44

ASKER

Thank you for the feedback everyone. The CNAME records I am referring to are the DC GUID's and to see the timestamps on the as updated today. What I find interesting is that all DC's have static IP's of course yet the TTL is set to 10 minutes to delete the record when stall. What I am confused by is if the DC's are not reboot or another how are why are the CNAME GUID's getting updated?
Are u saying that GUID'S ARE. CHANGING ?

Expiring TTL WOULD only change caching period but record would not get stale
OR
are u saying that scavenging period is set to 10 minutes only?
In that case change scavenging period to at least one day and check else u may lose other important records as well due to low scavenging period
TTL of 10 minutes to handle should the DC become unavailable. you do not want a "stale" record for a DC i.e. you are updating it or it crashed, you want it excluded as soon as possible....
I need to confirm that GUID are not change but 95% certain it is only the DNS record getting refreshed
ASKER CERTIFIED SOLUTION
Avatar of Mahesh
Mahesh
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial