Werbung: SecurityConsole.de verwaltet Ihre Computer mit Security Essentails aus der Cloud!
30 Tage kostenfrei testen und 20% Rabatt für Ihre Bestellung mit Promocode: WBF2685582
(Promocode gültig bis 31.12.2011)

Group:  English: Windows Server » microsoft.public.windows.server.dns
Thread: DNS record audit

HTVi
TV Discussion Newsgroups

DNS record audit
Kamlesh 5/10/2007 12:03:00 PM
Hi,

Basically, we are facing some issue, where a record which was deleted keeps
reappering. We would like to know, how can we find out, who is creating it
again.
it seems it is created dynamically, as in advance property i can see..
creator as system and there is a aging period configured.

Thanks in advance for the help.

--
Kamlesh
Re: DNS record audit
"Ace Fekay [MVP]" <PleaseAskMe[ at ]SomeDomain.com> 5/10/2007 12:35:10 PM
In news:581CD50C-2F8A-4064-A28F-5C602127944F[ at ]microsoft.com,
Kamlesh <Kamlesh[ at ]discussions.microsoft.com> typed:
[Quoted Text]
> Hi,
>
> Basically, we are facing some issue, where a record which was deleted
> keeps reappering. We would like to know, how can we find out, who is
> creating it again.
> it seems it is created dynamically, as in advance property i can see..
> creator as system and there is a aging period configured.
>
> Thanks in advance for the help.

More then likely, and I'm willing to bet my paycheck on it, it's possibly
coming from one of your DCs or another machine with RRAS installed and/or
there are multiple NICs on the DC with one of them possibly simply unplugged
and not disabled. It could also be a VPN client.

--
Regards,
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft MVP - Directory Services
Microsoft Certified Trainer

Infinite Diversities in Infinite Combinations

Having difficulty reading or finding responses to your post?
Instead of the website you're using, try using OEx (Outlook Express
or any other newsreader), and configure a news account, pointing to
news.microsoft.com. Anonymous access. It's free - no username or password
required nor do you need a Newsgroup Usenet account with your ISP. It
connects directly to the Microsoft Public Newsgroups. OEx allows you
o easily find, track threads, cross-post, sort by date, poster's name,
watched threads or subject. It's easy:

How to Configure OEx for Internet News
http://support.microsoft.com/?id=171164

"Quitting smoking is easy. I've done it a thousand times." - Mark Twain


Re: DNS record audit
Kamlesh 5/10/2007 12:56:01 PM
the A record in question, belongs to a member server.
We dont have WINS configuration, and DHCP is configured to update PTR
records only.
I also suspect another DC,
by the way, i forgot to mention, the zone is AD integrated, and every DC is
DNS server.

So I also suspect the some other DC is doing it, how can we find out which
DC is creating it again and why ?

btw just curious, how unplugged NIC in DC can create problem for member
server A record, I thought it would be for DC records only.

Thanks for the quick response,

--
Kamlesh

"Ace Fekay [MVP]" wrote:

[Quoted Text]
> In news:581CD50C-2F8A-4064-A28F-5C602127944F[ at ]microsoft.com,
> Kamlesh <Kamlesh[ at ]discussions.microsoft.com> typed:
> > Hi,
> >
> > Basically, we are facing some issue, where a record which was deleted
> > keeps reappering. We would like to know, how can we find out, who is
> > creating it again.
> > it seems it is created dynamically, as in advance property i can see..
> > creator as system and there is a aging period configured.
> >
> > Thanks in advance for the help.
>
> More then likely, and I'm willing to bet my paycheck on it, it's possibly
> coming from one of your DCs or another machine with RRAS installed and/or
> there are multiple NICs on the DC with one of them possibly simply unplugged
> and not disabled. It could also be a VPN client.
>
> --
> Regards,
> Ace
>
> This posting is provided "AS-IS" with no warranties or guarantees and
> confers no rights.
>
> Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
> Microsoft MVP - Directory Services
> Microsoft Certified Trainer
>
> Infinite Diversities in Infinite Combinations
>
> Having difficulty reading or finding responses to your post?
> Instead of the website you're using, try using OEx (Outlook Express
> or any other newsreader), and configure a news account, pointing to
> news.microsoft.com. Anonymous access. It's free - no username or password
> required nor do you need a Newsgroup Usenet account with your ISP. It
> connects directly to the Microsoft Public Newsgroups. OEx allows you
> o easily find, track threads, cross-post, sort by date, poster's name,
> watched threads or subject. It's easy:
>
> How to Configure OEx for Internet News
> http://support.microsoft.com/?id=171164
>
> "Quitting smoking is easy. I've done it a thousand times." - Mark Twain
>
>
>
Re: DNS record audit
"Ace Fekay [MVP]" <PleaseAskMe[ at ]SomeDomain.com> 5/10/2007 1:04:27 PM
In news:6487220D-C0B8-4618-882C-13084C81BC6B[ at ]microsoft.com,
Kamlesh <Kamlesh[ at ]discussions.microsoft.com> typed:
[Quoted Text]
> the A record in question, belongs to a member server.
> We dont have WINS configuration, and DHCP is configured to update PTR
> records only.
> I also suspect another DC,
> by the way, i forgot to mention, the zone is AD integrated, and every
> DC is DNS server.
>
> So I also suspect the some other DC is doing it, how can we find out
> which DC is creating it again and why ?
>
> btw just curious, how unplugged NIC in DC can create problem for
> member server A record, I thought it would be for DC records only.
>
> Thanks for the quick response,

If an unplugged NIC is not disabled in Windows, and is set to DHCP, it will
not attempt to register because it doesn't know what DNS server it is
registering into. But on a DC, yes, it will attempt to register.

Is RRAS installed anywhere?

Is there an unplugged NIC on a DC?

What does the IP address look like? Is is based on a number like 169.254.x.x
?

Ace


Re: DNS record audit
Kamlesh 5/10/2007 3:44:00 PM
no RRAS server is involved.
No unplugged NIC on member server, nor IP address is from 169.X series.
The IP address is configured static on member server.

I am trying to rephrase the question if it helps...
MemberServer has two records in DNS
Record1 : Member.domain.com : X.Y
Record2 : Member.domain.com : A.B

Here record with X.Y is the actual IP configured on server.
While A.B record was older one, it was deleted, but it reappered.
It was deleted twice but it reapperared again.



"Ace Fekay [MVP]" wrote:

[Quoted Text]
> In news:6487220D-C0B8-4618-882C-13084C81BC6B[ at ]microsoft.com,
> Kamlesh <Kamlesh[ at ]discussions.microsoft.com> typed:
> > the A record in question, belongs to a member server.
> > We dont have WINS configuration, and DHCP is configured to update PTR
> > records only.
> > I also suspect another DC,
> > by the way, i forgot to mention, the zone is AD integrated, and every
> > DC is DNS server.
> >
> > So I also suspect the some other DC is doing it, how can we find out
> > which DC is creating it again and why ?
> >
> > btw just curious, how unplugged NIC in DC can create problem for
> > member server A record, I thought it would be for DC records only.
> >
> > Thanks for the quick response,
>
> If an unplugged NIC is not disabled in Windows, and is set to DHCP, it will
> not attempt to register because it doesn't know what DNS server it is
> registering into. But on a DC, yes, it will attempt to register.
>
> Is RRAS installed anywhere?
>
> Is there an unplugged NIC on a DC?
>
> What does the IP address look like? Is is based on a number like 169.254.x.x
> ?
>
> Ace
>
>
>
Re: DNS record audit
"Ace Fekay [MVP]" <PleaseAskMe[ at ]SomeDomain.com> 5/10/2007 4:07:23 PM
In news:A59EF111-95E2-4662-A555-18CECD4310E5[ at ]microsoft.com,
Kamlesh <Kamlesh[ at ]discussions.microsoft.com> typed:
[Quoted Text]
> no RRAS server is involved.
> No unplugged NIC on member server, nor IP address is from 169.X
> series. The IP address is configured static on member server.
>
> I am trying to rephrase the question if it helps...
> MemberServer has two records in DNS
> Record1 : Member.domain.com : X.Y
> Record2 : Member.domain.com : A.B
>
> Here record with X.Y is the actual IP configured on server.
> While A.B record was older one, it was deleted, but it reappered.
> It was deleted twice but it reapperared again.

I would assume because the zone is AD integrated, if you delete it on one
DNS, it would propagate the change. I assume there are no errors in regards
to AD replication. Dumb question, if you delete the record on another DNS
server, does it come back? If it doesn't, I would assume probs with AD
replication.

Can you also look in the registry under TCPIP services to see if that is
hard coded in there as an additional IP that is not showing up in the GUI?

Ace


Home | Search | Terms | Imprint Contact
Newsgroups Reader - provided by WiredBox.Net
Suche nach Orten, Städten, Postleitzahlen, Vorwahlen, Kfz-Kennzeichen