DNS records are not 100% correct


for while we've been noticing dns records not correct. records pointing incorrect ip addresses. 1 one open record, update ip, replicate across domain controllers.

what cause hostname of 1 machine point ip address?

i believe you're seeing dhcp-dns registration. may have duplicates, or incorrect data records can't updated dhcp service or dhcp client due permissions on record. may not have scavenging in place.

in summary:

  • configure dhcp credentials. credentials need plain-jane, non-administrator, user account. give strong password.
  • set dhcp update everything, whether clients can or cannot.
  • set zone secure & unsecure updates. not leave unsecure only.
  • add dhcp server(s) active directory, built-in dnsupdateproxy security group. make sure other non-dhcp servers not in dnsupdateproxy group. example, believe dns servers or other dcs not running dhcp should in it. must removed or won't work. make sure no user accounts in group, either. (i hope that's crystal clear - surprised how many respond asking if dhcp credentials should in group.)
  • on windows 2008 r2 or newer, disable name protection.
  • if dhcp co-located on windows 2008 r2 or windows 2012 dc, can , must secure dnsupdateproxy group running following:
    dnscmd /config /openaclonproxyupdates 0
  • configure scavenging on 1 dns server. scavenges replicate others anyway. set scavenging norefresh , refresh values combined equal or greater dhcp lease length.

*

for specifics , step steps, , discussions on what's going on in background , expect:


dhcp service configuration, dynamic dns updates, scavenging, static entries, timestamps, dnsupdateproxy group, dhcp credentials, prevent duplicate dns records, dhcp has "pen" icon, , more...
http://msmvps.com/blogs/acefekay/archive/2009/08/20/dhcp-dynamic-dns-updates-scavenging-static-entries-amp-timestamps-and-the-dnsproxyupdate-group.aspx  

good summary
how dynamic dns behaves multiple dhcp servers on same domain?
http://social.technet.microsoft.com/forums/en-us/winservernis/thread/e9d13327-ee75-4622-a3c7-459554319a27

another summary:
thread: "dns problem" december 18, 2013
http://social.technet.microsoft.com/forums/windowsserver/en-us/37b8b6b3-6cb1-496c-8492-09ded13bab18/dns-problem?forum=winservernis


ace fekay
mvp, mct, mcitp/ea, mcts windows 2008/r2 & exchange 2007, exchange 2010 ea, mcse & mcsa 2003/2000, mcsa messaging 2003
microsoft certified trainer
microsoft mvp - directory services
technical blogs & videos: http://www.delawarecountycomputerconsulting.com/

this post provided as-is no warranties or guarantees , confers no rights.

facebook twitter linkedin



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2