Re: Reverse Lookup Zone causing conflicts, multiple records



Read inline please.

In news:E0103265-41C3-4077-8D97-5A9E9DECC4D9@xxxxxxxxxxxxx,
Jeff <Jeff@xxxxxxxxxxxxxxxxxxxxxxxxx> typed:
Hello all,

We're running 3 DNS servers in a Win2003, ADS network, using DHCP for
most of our client machines.

We noticed a problem with IP address conflicts and when running
nslookup, we get multiple DNS names for the same IP address.
Checking the reverse lookup zones on the particular subnet, we
noticed multiple records in DNS for different machines that are not
being scavanged in the 7 day time period.

For example, one machine was my own personal laptop that I bring in on
occasion for field work, file uploads, etc. I haven't brought it in
for about 3 months and yet, there is the PTR record for it,
conflicting with another machine. There are a few examples of this
happening, but not so much that we noticed machines having conflicts.

The configuration has been the same for a long time, it hasn't
changed. Scavenging is set for 7 days and Zone Transfers are
configured between the 3 DNS servers with 1 being primary and the
other 2 secondary, pulling updates from the first. All are 2003
Domain Controllers and ADS is running in Windows 2003 Functional
level.

DHCP leases are set to Dynamically update the A and PTR records in
DNS.

Does anyone have any suggestions?

This is a common issue on networks with laptops, because rarely (if ever)
does anyone release the IP lease on their laptop before disconnecting the
cable.

Configure all DHCP servers with a dedicated user account with a non-expiring
password to use for DNS registrations.
Then configure DHCP to remove A and PTR records when lease is deleted.
Always update DNS and register for clients that do not support DNS
registrations. Also, add Windows 2000 Advanced option for release lease on
shutdown. On laptops especially, clear the register this connection's
addresses in DNS. DHCP will register and own the records and therefore will
remove the records when the lease expires.

Host (A) records may contain incorrect IP addresses if you configure a
Windows Server 2003-based DHCP server to update A records and PTR records in
DNS: http://support.microsoft.com/default.aspx/kb/929587/en-us

How to configure DNS dynamic updates in Windows Server 2003:
http://support.microsoft.com/default.aspx?scid=kb;en-us;816592


--
Best regards,
Kevin D. Goodknecht Sr. [MVP]
Hope This Helps

===================================
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
===================================
http://www.lonestaramerica.com/
http://support.wftx.us/
http://message.wftx.us/
===================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
===================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
===================================


.



Relevant Pages

  • Re: Dynamic DNS, DNS Records & Scavenging
    ... There are two DHCP ... Both the servers are set to update A and PTR records for clients. ... DNS however this doesn't seem to be the case. ... DNSUpdateProxy and when i did this i saw my test laptop register its ...
    (microsoft.public.windows.server.dns)
  • Re: DHCP
    ... I do not intend to change DNS or DHCP servers. ... Since these machines are DHCP Client Windows Server 2003 machines with ...
    (microsoft.public.windows.server.general)
  • Re: DHCP
    ... I do not intend to change DNS or DHCP servers. ... Since these machines are DHCP Client Windows Server 2003 machines with ...
    (microsoft.public.windows.server.general)
  • Re: DHCP
    ... I do not intend to change DNS or DHCP servers. ... Since these machines are DHCP Client Windows Server 2003 machines with ...
    (microsoft.public.windows.server.general)
  • Re: Logon problems after beginning AD migration
    ... the machines that are logging into the non-2003 ... BDCs to the DNS servers in the 2003 domain, ... It was barely adequate for 2003 server, so after I had a BDC in place, I tried to transfer the FSMO roles to the BDC so I could demote and reload it. ...
    (microsoft.public.win2000.active_directory)