Results 1 to 3 of 3

Thread: DNS cilent won't update its HOST A record in DNS AD INTEGRATED ZONE

  1. #1
    boxer Guest

    DNS cilent won't update its HOST A record in DNS AD INTEGRATED ZONE

    Hi,

    I have this situation:

    Windows 2003 native mode domain
    2 DCs
    2 DNS servers on 2 DCs (Active Directory Integrated Zones)
    Dynamic Updates (Secure only)

    When I change IP address (static or dynamic (it doesn't matter) )DNS client
    (either XP PRO or SERVER 2003)
    failed to update itself HOST A record (old IP remains in DNS).

    Event ID DNSAPI 11166 is recorded in event log:
    The system failed to register host (A) resource records (RRs) for network
    adapter...

    I disovered that dns client (machine name) doesn't have permission to update
    its HOST A record.

    How to resolve this in security?
    Do I need to add Domain Computers perrmission to change(update) their HOST A
    records?
    What are defaults (recommend) in security regarding this problem(issue) ?

    Thanx in advanced

    Boxer





  2. #2
    JohnB Guest

    Re: DNS cilent won't update its HOST A record in DNS AD INTEGRATED ZONE

    Pre-Windows 2000 computers are not able to dynamically update their records.
    However, a DHCP server can perform dynamic updates on the behalf of those
    computers if the server is configured to do so. But, because the DHCP
    server updated the records on the client's behalf, it is considered the
    owner of those records, and the clients can't update the records themselves.
    That is even true, after a pre-2000 machine us upgraded to XP, etc.
    Or, you could have a situation where a DHCP server was updating records for
    pre-2000 machines, and that DHCP sever fails or is replaced, those clients
    would then not get updated by other DHCP servers.
    Not sure if that is your probelem thoough.

    For more info, do a Google on; dns update proxy


    "boxer" <a@g.com> wrote in message
    news:ukA4MmlSJHA.4680@TK2MSFTNGP06.phx.gbl...
    > Hi,
    >
    > I have this situation:
    >
    > Windows 2003 native mode domain
    > 2 DCs
    > 2 DNS servers on 2 DCs (Active Directory Integrated Zones)
    > Dynamic Updates (Secure only)
    >
    > When I change IP address (static or dynamic (it doesn't matter) )DNS
    > client (either XP PRO or SERVER 2003)
    > failed to update itself HOST A record (old IP remains in DNS).
    >
    > Event ID DNSAPI 11166 is recorded in event log:
    > The system failed to register host (A) resource records (RRs) for network
    > adapter...
    >
    > I disovered that dns client (machine name) doesn't have permission to
    > update its HOST A record.
    >
    > How to resolve this in security?
    > Do I need to add Domain Computers perrmission to change(update) their HOST
    > A records?
    > What are defaults (recommend) in security regarding this problem(issue) ?
    >
    > Thanx in advanced
    >
    > Boxer
    >
    >
    >
    >




  3. #3
    boxer Guest

    Re: DNS cilent won't update its HOST A record in DNS AD INTEGRATED ZONE

    Thanx JohnB but this is not my problem.

    Suppose that....

    If I have clear new pc, joined in domain... it creates its HOST A record in
    DNS and thats ok. (This works fine)

    but

    if you change IP of this pc it should update its HOST A record in DNS with
    this new IP address.

    I can get this to work only if I give security permission on this pc HOST A
    record - "pcname" (not user)

    Then it update HOST A record to new IP add.

    Regards
    "JohnB" <jbrigan@yahoo.com> wrote in message
    news:%232eSMAmSJHA.1484@TK2MSFTNGP03.phx.gbl...
    > Pre-Windows 2000 computers are not able to dynamically update their
    > records. However, a DHCP server can perform dynamic updates on the behalf
    > of those computers if the server is configured to do so. But, because the
    > DHCP server updated the records on the client's behalf, it is considered
    > the owner of those records, and the clients can't update the records
    > themselves.
    > That is even true, after a pre-2000 machine us upgraded to XP, etc.
    > Or, you could have a situation where a DHCP server was updating records
    > for pre-2000 machines, and that DHCP sever fails or is replaced, those
    > clients would then not get updated by other DHCP servers.
    > Not sure if that is your probelem thoough.
    >
    > For more info, do a Google on; dns update proxy
    >
    >
    > "boxer" <a@g.com> wrote in message
    > news:ukA4MmlSJHA.4680@TK2MSFTNGP06.phx.gbl...
    >> Hi,
    >>
    >> I have this situation:
    >>
    >> Windows 2003 native mode domain
    >> 2 DCs
    >> 2 DNS servers on 2 DCs (Active Directory Integrated Zones)
    >> Dynamic Updates (Secure only)
    >>
    >> When I change IP address (static or dynamic (it doesn't matter) )DNS
    >> client (either XP PRO or SERVER 2003)
    >> failed to update itself HOST A record (old IP remains in DNS).
    >>
    >> Event ID DNSAPI 11166 is recorded in event log:
    >> The system failed to register host (A) resource records (RRs) for network
    >> adapter...
    >>
    >> I disovered that dns client (machine name) doesn't have permission to
    >> update its HOST A record.
    >>
    >> How to resolve this in security?
    >> Do I need to add Domain Computers perrmission to change(update) their
    >> HOST A records?
    >> What are defaults (recommend) in security regarding this problem(issue) ?
    >>
    >> Thanx in advanced
    >>
    >> Boxer
    >>
    >>
    >>
    >>

    >
    >




Similar Threads

  1. Replies: 6
    Last Post: 15-10-2011, 11:39 AM
  2. Create Active Directory integrated zone in DNS
    By Brruno in forum Networking & Security
    Replies: 3
    Last Post: 12-11-2010, 06:17 AM
  3. How to update a parent zone
    By Santiaago in forum Technology & Internet
    Replies: 5
    Last Post: 04-03-2010, 12:44 PM
  4. host 'A' record is not creating dynamically in DNS
    By shappy in forum Operating Systems
    Replies: 2
    Last Post: 25-06-2009, 11:45 PM
  5. Windows DNS server - force A record to update PTR record
    By Peter Cumming in forum Windows Server Help
    Replies: 1
    Last Post: 27-05-2006, 07:00 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,714,043,286.67489 seconds with 17 queries