Skip to main content

DNS Dynamic Updates & DNS Scavenging

I was encountering an issue at a customer's site where the DNS records of their client PCs often would be behind or out of sync with the records in DHCP.  Usually the IP address would be older in DNS and this was causing issues with scripts executing and network tools correctly resolving client PC hostnames to their correct IP addresses.

I realised I needed to make some changes to their dynamic DNS updating configuration.  After a lot of reading through Microsoft's documentation and various online forums, this is what I ended up configuring.  Hopefully this may help someone, some day:

- Make the DHCP server a member of the "DnsUpdateProxy" group














Create a new user account, in the "Users" OU, called "dnsdynamicupdates"

  - This new user only needs to be a member of the "Domain Users" group - no special privileges

  - Make the password strong and set it to never expire


- Set this new user as the credentials used by the DCHP server in IPv4 Properties | Advanced | Credentials









- Secure the DnsUpdateProxy group by running the following command with Admin privileges:

  - dnscmd /config /OpenAclOnProxyUpdates 0


- Set the DHCP server's DNS settings to "Always dynamically update DNS records" in IPv4 Properties | DNS














- Configure DNS Aging values on the DNS server (combined these should be less than the DHCP lease time):

  - NoRefresh: 3 days

  - Refresh:   3 days










- Set the scavenging period on the DNS server to 4 days (often recommended to be less than the DHCP lease time)















- Set the DHCP lease time to 7 days (as appropriate for your network)














Some good Resources:

- DNS Dynamic Updates: https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/configure-dns-dynamic-updates-windows-server-2003

- DNS Scavenging: https://lazyadmin.nl/it/dns-scavenging/

https://chrisbrown.au/techblog/how-dns-aging-and-scavenging-actually-work/

https://techit-services.com/best-practices-for-windows-dns-scavenging/#:~:text=In%20general%2C%20the%20total%20duration,is%20a%20well%2Drecognized%20practice.


Comments

Popular posts from this blog

Evolution MK-249C MIDI Keyboard Mac OS X Problem

Mac OS X generally seems capable of dealing with just about anything you can throw at it. However upon connecting my trusty Evolution MK-249C MIDI keyboard up to my 2nd generation MacBook it steadfastly refused to play ball. This keyboard has always been instantly recognised by Windows XP and so it was surprising to encounter this. The M-Audio website (M-Audio took over Evolution it appears) offered no real assistance. There was no driver available for Mac OS X 10.4.9 as the keyboard is supposed to be "Class Compliant" which apparently means it doesn't need one... strange. Eventually after consulting some forums I found the fix. The problem seems to be related to Mac OS on the Intel MacBooks. There is a patch on the M-Audio site but only for MacOS 10.1.5. This must be downloaded and installed. Here is the link: http://www.m-audio.com/index.php?do=support.drivers&f=596 Upon restarting the OS the keyboard was recognised by Mac OS and GarageBand had no trouble tal...

Copying NTFS Permissions with RichCopy

 Microsoft's RichCopy is a fantastic tool for copying/moving files.  It's multithreaded so moves things along quicker and has a nice log so you can see what's working and what's going wrong. It's kind of like a GUI on top of RoboCopy and you can get it here... However, I always forget that it doesn't copy file/folder NTFS permissions by default.  This is what you need to do if you want permissions to copy across to the destination: - Click the "View" menu and then click on "Advanced". - Then click the "Option" button on the right below the "Source" and "Destination" buttons. - Click on "File attributes, Error Handling" - Tick the relevant boxes under the "Security information" section. Hope this helps.

XP Startup Issues - The Recovery Console

The Windows Recovery Console is a fantastically useful tool if you find yourself with a PC that will not boot Windows. There are many useful Windows startup tools such as Last Known Good Configuration and the many different flavours of Safe Mode but all of these rely on a bootable Windows system. System Restore is completely useless in this scenario since it relies on one being in Windows to use it. The kinds of things that could couse an unbootable Windows system could be: Corrupted boot files - e.g. NTLDR, NTDETECT.COM Corrputed Windows system files - NTOSKRNL.EXE, HAL.DLL The Recovery Console allows you to boot into an environment "underneath" that of your Windows installation (by using the Windows CD or by choosing it at boot time if you pre-installed it) and so you can perform major low level repairs to your Windows installation. Follow the link below to find out how to use the Recovery Console: http://support.microsoft.com/kb/314058/