Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
Home
Discussion GroupsWindows Server 2003Windows 2000Windows NTSmall Business ServerVirtual ServerExchange ServerIISHost Integration ServerISA ServerSMSWSUSMOMWindows Media ServerSecurityCertification
Related Topics
SQL ServerMS WindowsMS OfficePC HardwareMore Topics ...

Windows Server Forum / Windows 2000 / DNS / February 2006

Tip: Looking for answers? Try searching our database.

Curious about this DNS entry

Thread view: 
Enable EMail Alerts  Start New Thread
Thread rating: 
Rob - 21 Feb 2006 12:08 GMT
We have a W2k network here upgraded some time ago from NT4
There are x2 DC's, one of which is the internal network DNS server.  Only
running fwd lookup zones.
I noticed on one of our member servers that there was a dnsapi entry in the
application log (event id 11157) where it could not update the PTR records.  
OK no problem as there is no reverse lookup.
What did puzzle me was that it appears to have sent an update to 192.175.48.1.
I had a look further back in the archived logs and it has been doing this
for at least a year.  This IP is 'pingable' and can be traced back to
prisoner.iana.org.
Can someone explain what this is about?
Thanks
Kevin D. Goodknecht Sr. [MVP] - 21 Feb 2006 13:51 GMT
> We have a W2k network here upgraded some time ago from NT4
> There are x2 DC's, one of which is the internal network DNS server.
[quoted text clipped - 9 lines]
> Can someone explain what this is about?
> Thanks

Since you don't have a reverse lookup zone, DNS clients that are trying to
register PTR records are sending updates to the internet server that holds
the Public SOA master server for the IP address. In you case, since it is in
a private IP address range, it goes to prisoner.iana.org.

If you will create a local reverse lookup zone on your DCs it will become
the local SOA master server, and it will take authority over the PTR record.

Signature

Best regards,
Kevin D. Goodknecht Sr. [MVP]
Hope This Helps
===================================
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
===================================
http://www.lonestaramerica.com/
http://support.wftx.us/
https://secure.lsaol.com/
===================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
===================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
===================================

Rob - 21 Feb 2006 14:26 GMT
Thanks Kevin.
Is this coded into the networkservice then and not configurable?

> > We have a W2k network here upgraded some time ago from NT4
> > There are x2 DC's, one of which is the internal network DNS server.
[quoted text clipped - 17 lines]
> If you will create a local reverse lookup zone on your DCs it will become
> the local SOA master server, and it will take authority over the PTR record.
Kevin D. Goodknecht Sr. [MVP] - 21 Feb 2006 15:33 GMT
> Thanks Kevin.
> Is this coded into the networkservice then and not configurable?

This is the way all DNS servers work. It does not matter what DNS server you
are using. If a DNS registration request is sent to a DNS server, the DNS
server will attempt to locate the Authoritative server for the record,
regardless of the record type, and send the update to that server.  If it is
an A record, it will attempt to locate the Authoritative DNS for the domain
name. If it is a PTR, DNS will attempt to locate the Authoritative server
for the reverse lookup and send the PTR registration request to it.. Then
the DNS update is always sent to the Master server for the record. You
cannot change this, and it is why all AD integrated DNS zones will have the
its own name on the SOA Master server, to reduce cross network registration
requests.

>>> We have a W2k network here upgraded some time ago from NT4
>>> There are x2 DC's, one of which is the internal network DNS server.
[quoted text clipped - 20 lines]
>> become the local SOA master server, and it will take authority over
>> the PTR record.

Signature

Best regards,
Kevin D. Goodknecht Sr. [MVP]
Hope This Helps
===================================
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
===================================
http://www.lonestaramerica.com/
http://support.wftx.us/
https://secure.lsaol.com/
===================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
===================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
===================================

Rob - 22 Feb 2006 14:46 GMT
Thanks kevin you've been very helpful.

> > Thanks Kevin.
> > Is this coded into the networkservice then and not configurable?
[quoted text clipped - 35 lines]
> >> become the local SOA master server, and it will take authority over
> >> the PTR record.
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2009 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.