DNS Server not flushing Stale Records


i have 3  dc's active directory intergrated dns on them. have issues both forward , reverse lookup zones on both dns's server's.

i have security section complaining due poor name resolution because scavenging not happening. have set-up microsoft says open call them on year ago. ideas why have many records time stamp older month not scavenging.

i had microsoft ticket open year , half ago had me make these changes did not fix anything.  this had me change

scavenge setting made dns server

 

1.  scavenging should set 1 server (dc03 x.x.10.50). scavenging should turned off on second dns server (dc02 x.x.9.41). scavenging need turned on 31 days should 1 day longer dhcp lease.

 

2.  the following need done on dc03, x.x.10.50:

 

  a.  right click on server , click set aging , savaging on zones. make sure scavenge stale resource records checked. make sure no-refresh interval 15 days , refresh interval 16 days. (see below pic)

 

 

  b.  right click on server , click properties. make sure enable automatic scavenging of stale records checked. making scavenging period 1 days. (see below pic)

 

 

  c.  next right click on zone jtfb.local , click properties. click button aging , make sure no-refresh interval 15 days , refresh interval 16 days. (see 2 pics above).

 

 

  d.  now go second dns server (jtfb-dc02 172.17.9.41) , make sure these settings turned off.

 

the reasoning behind making sure turned off need scavenged on 1 server , replicate other server.

 

3.  scavenging must turned on reverse dns lookup zones. should done on (jtfb-dc03 172.17.10.50) also.  it must turned on every single zone.

 

  b. right click on first zone , click properties.

 

 

  c. click aging button on general tab. make sure scavenge stale resource records checked. make sure no-refresh interval 15 days , refresh interval 16 days. (see 1st pic)

hi defense backups,

thank posting in windows forum,

the design valid , suggestion provided microsoft valid, many customers forget turn on scavenging on zones , run problems. need set scavenging on both zone , server level taken care in scenario.

can test below command scavenge records

dnscmdservername/startscavenging


sainath !analyze


Windows Server  >  Platform Networking



Comments

Popular posts from this blog

Motherboard replacement

Cannot create Full Text Search catalog after upgrading to V12 - Database is not fully started up or it is not in an ONLINE state

Remote Desktop App - Error 0x207 or 0x607