Some AD DNS Records Missing from 1 DC

917 views
Skip to first unread message

Charles F Sullivan

unread,
May 5, 2022, 6:17:31 PM5/5/22
to ntsys...@googlegroups.com

We have a duplicate of our Windows 2012 R2 AD (single domain and forest) in a closed off VLAN for testing. I have just added a Windows 2019 DC, which I have done in other iterations of this test domain without DNS (or any) issues.

This time I noticed that the IP address does not get listed when looking up Forestdnszones or Domaindnszones. (It does get listed as an NS for those zones.) Checking in AD DNS, I see that it is missing from the top nodes for Forestdnszones and Domaindnszones, but it is listed in all _tcp subzones. The A record is also missing from the root node for the domain, where these A records normally exist by IP address.

So in a nutshell, any AD record that contains and IP address isn't getting registered, it seems. It definitely is registering its reverse record.

I have never seen this before and there doesn't seem to be anything in the event logs that gives me a clue. Anyone know how I can fix this or what might cause it? It doesn't seem like creating a static A record for the IP address would be a good idea. 
--

Charlie Sullivan

Principal Windows Systems Administrator

Philip Elder

unread,
May 5, 2022, 6:58:53 PM5/5/22
to ntsys...@googlegroups.com

_msdcs grey stub zone in domain.com zone?

_msdcs.domain.com zone set up correctly?

Make sure there’s no NS settings that point to an old DC.

 

Philip Elder MCTS

Senior Technical Architect

Microsoft High Availability MVP

E-mail: Phili...@mpecsinc.ca

Phone: +1 (780) 458-2028

Web: www.mpecsinc.com

Blog: blog.mpecsinc.com

Twitter: Twitter.com/MPECSInc

Skype: MPECSInc.

 

Please note: Although we may sometimes respond to email, text and phone calls instantly at all hours of the day, our regular business hours are 8:00 AM - 5:00 PM, Monday thru Friday.

--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/CAEuHzzm777LDwWoO%2BXauPDOZT9HLZD8p5H0SXpbAhUq45qC__A%40mail.gmail.com.

James Iversen

unread,
May 6, 2022, 8:53:34 AM5/6/22
to ntsys...@googlegroups.com

Hi, Do you have any "non-Microsoft" DHCP servers?

I have found that DHCP devices which do not have authority to change DNS records will fail forward lookup, while the machine itself has authority to update reverse.

Weird stuff when we try to expand our scopes using non-Microsoft or non-authoritative DHCP servers...

Jim


From:        "Charles F Sullivan" <charles.s...@bc.edu>
To:        ntsys...@googlegroups.com
Date:        05/05/2022 06:17 PM
Subject:        [ntsysadmin] Some AD DNS Records Missing from 1 DC
Sent by:        ntsys...@googlegroups.com





ATTENTION: This email was sent from someone outside of NYCM.
--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit
https://groups.google.com/d/msgid/ntsysadmin/CAEuHzzm777LDwWoO%2BXauPDOZT9HLZD8p5H0SXpbAhUq45qC__A%40mail.gmail.com.









Join us on Facebook at
www.facebook.com/NYCMInsurance.


***CONFIDENTIALITY NOTICE***

This email and any attachments to it are confidential and intended solely for the individual or entity to whom it is addressed. Any unauthorized review, use, disclosure or distribution is prohibited. If you have received this email in error, please contact the sender by reply email and destroy all copies of the original message.




Charles F Sullivan

unread,
May 6, 2022, 12:01:14 PM5/6/22
to ntsys...@googlegroups.com
A previously orphaned DC (the other Windows 2019 server I had joined to this test version of our AD) still was listed as a name server. Its IP address was listed under gc._msdcs. Ran dcdiag /test:dns:
TEST: Records registration (RReg)
                Network Adapter [00000001] vmxnet3 Ethernet Adapter:
                     Warning:
                     Missing A record at DNS server 10.10.10.30:
                     gc._msdcs.foo.blah

                     Warning:
                     Missing A record at DNS server 10.10.10.31:
                     gc._msdcs.foo.blah


I removed the references to the old DC and that did it! Thanks so much for your help. All the records for the current Windows 2019 DC are present and dcdiag comes up clean.

In our production environment, it would have been different because I would have done the cleanup and we would not allow a DC to become orphaned as long as it was within our control. I'll have to treat this more like production.

Reply all
Reply to author
Forward
0 new messages