Skip to main content

DNS Dynamic Updates & DNS Scavenging

I was encountering an issue at a customer's site where the DNS records of their client PCs often would be behind or out of sync with the records in DHCP.  Usually the IP address would be older in DNS and this was causing issues with scripts executing and network tools correctly resolving client PC hostnames to their correct IP addresses.

I realised I needed to make some changes to their dynamic DNS updating configuration.  After a lot of reading through Microsoft's documentation and various online forums, this is what I ended up configuring.  Hopefully this may help someone, some day:

- Make the DHCP server a member of the "DnsUpdateProxy" group














Create a new user account, in the "Users" OU, called "dnsdynamicupdates"

  - This new user only needs to be a member of the "Domain Users" group - no special privileges

  - Make the password strong and set it to never expire


- Set this new user as the credentials used by the DCHP server in IPv4 Properties | Advanced | Credentials









- Secure the DnsUpdateProxy group by running the following command with Admin privileges:

  - dnscmd /config /OpenAclOnProxyUpdates 0


- Set the DHCP server's DNS settings to "Always dynamically update DNS records" in IPv4 Properties | DNS














- Configure DNS Aging values on the DNS server (combined these should be less than the DHCP lease time):

  - NoRefresh: 3 days

  - Refresh:   3 days










- Set the scavenging period on the DNS server to 4 days (often recommended to be less than the DHCP lease time)















- Set the DHCP lease time to 7 days (as appropriate for your network)














Some good Resources:

- DNS Dynamic Updates: https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/configure-dns-dynamic-updates-windows-server-2003

- DNS Scavenging: https://lazyadmin.nl/it/dns-scavenging/

https://chrisbrown.au/techblog/how-dns-aging-and-scavenging-actually-work/

https://techit-services.com/best-practices-for-windows-dns-scavenging/#:~:text=In%20general%2C%20the%20total%20duration,is%20a%20well%2Drecognized%20practice.


Comments

Popular posts from this blog

Resolve WSUS Server issue that gives "Cannot save configuration because the server is still processing"

This is a pretty infuriating error and can sometimes crop up as a result of running a "wsusutil reset" command. First of all, give the server some time, and then a bit more...  but you've probably already done this. These steps may help to resolve the situation: - Install Microsoft SQL Management Studio (free download) - Run SQL Management Studio and start to connect to the WSUS database - Enter this in the "Server Name" box:  \\.\pipe\MICROSOFT##WID\tsql\query - Expand the "Databases" tree - Right-click on "SUSDB" and choose "New Query" - Paste this query in:     UPDATE tbSingletonData     SET ResetStateMachineNeeded = 0 - You should see a message like "1 row affected", which is good - Quit SQL Management Studio - Open "Services" and restart the "WSUS Service" - Now, open WSUS

Evolution MK-249C MIDI Keyboard Mac OS X Problem

Mac OS X generally seems capable of dealing with just about anything you can throw at it. However upon connecting my trusty Evolution MK-249C MIDI keyboard up to my 2nd generation MacBook it steadfastly refused to play ball. This keyboard has always been instantly recognised by Windows XP and so it was surprising to encounter this. The M-Audio website (M-Audio took over Evolution it appears) offered no real assistance. There was no driver available for Mac OS X 10.4.9 as the keyboard is supposed to be "Class Compliant" which apparently means it doesn't need one... strange. Eventually after consulting some forums I found the fix. The problem seems to be related to Mac OS on the Intel MacBooks. There is a patch on the M-Audio site but only for MacOS 10.1.5. This must be downloaded and installed. Here is the link: http://www.m-audio.com/index.php?do=support.drivers&f=596 Upon restarting the OS the keyboard was recognised by Mac OS and GarageBand had no trouble tal...

Jamf Pro DEP Enrollment Sync failed: Communication error. Awaiting next sync

 This error catches me out every so often when a customer of mine gets new iPads and I have to enrol them.  It's often been some time since I've last done this job and sometimes the MDM Server token needs to be refreshed (for want of a better term) before sync can re-commence between Apple School Manager and the customer's MDM (in this case Jamf Pro). Here are the list of steps to take: Log in to Apple School Manager (ASM) in one browser tab, and your MDM in another tab. In ASM, click your account name on the bottom left, and click "Preferences". Under "Device Management Services" click on your MDM service (Jamf Pro in my case). Click "Download Token" and allow the p7m file to download. In your MDM service, you'll need to upload the p7m file into its "Server token file" area. In Jamf Pro, click into "Settings" and then go into "Automated device enrollment", which is in the "Global Management" area. Cl...