DNS
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me

The Shed is going Social! Join us on FaceBook and Twitter and chime in on the conversation.

Go Back   Dev Shed ForumsSystem AdministrationDNS

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old June 8th, 2011, 08:53 AM
chsystem chsystem is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2011
Posts: 1 chsystem User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 34 m 14 sec
Reputation Power: 0
Bad DNS record getting into DNS Client Cache

Hello,

my question
Is there a way to check or record from where the Windows XP pro workstation is getting the wrong IP address and placing it into its DNS cache?

Scenario
We are connected to a multiple forest/domain network. All of our user workstations run Windows XP using DHCP and DNS Client. There are two databases our users access that are not on our domain. Through DHCP we append these DNS suffixes:
OurCompany.net
OurCompany.com
Company_A.com
Company_B.net
Company_B.com

About 100 of our users must access a database multiple times a day on Company_A.com network.
Company_A is not on a trusted domain. Via group policies we map a V. to \\databaseserver1.Company_A.com\DatabaseRecord
We also have OBDC setup to access the database above.

Our users are accessing records and images of documents on the database above. Most of the time there is no problem accessing the images. About 5 times a week we get a call from one of our users where they no longer can access the images on this server. The user have already looked at 3 document images in the last 2 minutes and when they go to look at image 4 nothing happens.
We have discovered if we flush the DNS cache the user can start accessing the images on this database.
For example purposes the correct IP address for the server above would be 172.16.99.100 but when the workstation starts having the problem and we ping databaseserver1 it is sending the ping request from 198.140.240.14 .
Is there a way to check or record from where the Windows XP pro workstation is getting the wrong IP address and placing it into its DNS cache?

Thanks for your assistance,
Greg

Reply With Quote
  #2  
Old June 8th, 2011, 05:26 PM
CaptPikel CaptPikel is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2010
Location: Florida
Posts: 248 CaptPikel User rank is Lance Corporal (50 - 100 Reputation Level)CaptPikel User rank is Lance Corporal (50 - 100 Reputation Level)CaptPikel User rank is Lance Corporal (50 - 100 Reputation Level) 
Time spent in forums: 3 Days 15 h 26 m 11 sec
Reputation Power: 3
The tool best used in Windows would be "nslookup" on the command line. It can be used to simulate queries to the name servers. You can find the name servers the PC is using by the "ipconfig /all" command.

The Windows resolver will only query the name servers listed in the ipconfig section. If none are listed, queries are broadcasted, so that can cause some confusion if DHCP was not set up properly and missing DNS data. That can also cause conflicting or inconsistent answers. Now if a program is set to query a specific server, that will bypass what Windows has for DNS servers altogether.

Reply With Quote
  #3  
Old June 9th, 2011, 01:51 AM
Eddie_D Eddie_D is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2011
Posts: 15 Eddie_D User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 6 h 59 m 32 sec
Reputation Power: 0
If you really want to see queries and responses at the network level you should use a packet capture/analysis tool like wireshark.

This will show you exactly what is being queried for and where the response is coming from. Wireshark is a very good protocol decoder and should display your DNS packets in a meaningful way.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationDNS > Bad DNS record getting into DNS Client Cache

Developer Shed Advertisers and Affiliates



Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 


Powered by: vBulletin Version 3.0.5
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.

© 2003-2013 by Developer Shed. All rights reserved. DS Cluster - Follow our Sitemap