Re: DNS not updating



Dynamic update was set to secure. Now I need to know what happens if something is wrong with the security. What would be an "insecure" action? Temporarly going to change it to any and see if that has any effect. Error in event log of one of the machines with problem:

Event Type: Warning
Event Source: DnsApi
Event Category: None
Event ID: 11163
Date: 2/1/2007
Time: 8:53:57 AM
User: N/A
Computer: BED-ECOX-LT
Description:
The system failed to register host (A) resource records (RRs) for network adapter
with settings:

Adapter Name : {D4831D98-7F2F-4BE0-BE27-72A39CDAxxxx}
Host Name : BED-ECOX-LT
Primary Domain Suffix : skynet.com
DNS server list :
172.20.65.20, 172.20.64.12
Sent update to server : 172.1.1.1
IP Address(es) :
172.20.67.89

The reason the system could not register these RRs was because the DNS server failed the update request. The most likely cause of this is that the authoritative DNS server required to process this update request has a lock in place on the zone, probably because a zone transfer is in progress.

You can manually retry DNS registration of the network adapter and its settings by typing "ipconfig /registerdns" at the command prompt. If problems still persist, contact your DNS server or network systems administrator.

On Thu, 1 Feb 2007, Herb Martin wrote:
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 2d 23 00 00 -#..


#####
Sent update to server: 172.1.1.1 does not exist. Not sure where this info is coming from.


<poohba@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:Pine.LNX.4.64.0702011030090.32540@xxxxxxxxxxxxxxxxxxx
When a user goes home and logs on via VPN they are assigned a ip of
course. When they come back into the office they get a different ip of
course but usually the one they had last time they were in the office
depending on how long ago that was.

Why? Machines don't typically need the old IP.

Use Dynamic DNS to get them registered in DNS with current IP.

The problem is that the name cannot be resolved. ping resolves to the ip
they had while on the VPN and the DNS record has the vpn ip address but
DHCP has the correct ip address.


Why is DNS not updating and how do I make it update and/or should I be
looking somewhere else?

Do the machines have their CORRECT DNS name in the Primary DNS
Suffix in SYSTEM Control Panel?

Are the machines or the DHCP server expected to register these stations?

DHCP server should also configure the scope with DNS name and bet set
to do the registration if you wish it to handle this.

Would a login script that does ipconfig /flushdns

Irrelevant since that is about the cache.

ipconfig /registerdns nbtstat -RR do the trick?

Probably not if the machines are already registering themselves.

MAYBE so if the machines are not being restarted, but in that case the
users are probably not logging on either. (Just sleep/wake machine.)

Do I need to go through all of that or is there a setting in DNS that I
need to fix?

Check the DNS server is allowing ANY dynamic updates. Check that
some machines can register.

If this is the case then likely the problem is with a (BASIC) DNS problem
(not the dynamic stuff per se) that is actually preventing domain
authentication,
or some firewall/router issue, or time sync. Something preventing
authentication
of the workstations. (Again, DHCP dynamic registration might get around
this
but such problems need to be fixed too.)

--
Herb Martin, MCSE, MVP
http://www.LearnQuick.Com
(phone on web site)



.



Relevant Pages

  • Re: external DNS
    ... How would I get my DNS server registered? ... Please reply with the corresponding IP addresses and I will register ... > creating a DNS host, and create a DNS host named NS1 in the ...
    (microsoft.public.win2000.dns)
  • Re: Event ID 1812 on AV server
    ... Failed to Register Host A Records ... DNS server list: ... have been a problem negotiating valid credentials with the DNS server ... No DNS Name Resolution If DHCP Client Service Is Not Running ...
    (microsoft.public.windows.server.networking)
  • Re: Domain workstation cannot see the domain for adding user permi
    ... use only domain controllers as their preferred DNS servers because in an AD ... access to also obtain their DNS server automatically as the rest of the ... The network has a dsl router which only some machines are allowed to use ...
    (microsoft.public.windowsxp.security_admin)
  • Re: machines with root domains DNS suffix vs Child domains
    ... You should therefore correctly register systems in the zone corresponding to their domain membership. ... Since we don't manage our own DNS server, we register each and every machine ... The machines were registered as hostname.kon.kaum.com format before Active ... The child domain qin.kon.kaum.com is the domain that the machines were ...
    (microsoft.public.windows.server.active_directory)
  • Re: Home webserver...
    ... DNS server. ... This is GOOD but irrelevant to the functioning of the DNS server. ... DNS Zone which is set to allow dynamic registrations but not ... going to register the www.swvoice.com.au. ...
    (microsoft.public.windows.server.dns)