Dns Issue on Multi Valued Records
In a large scale environment there is a known issue which has been experienced by several customers of SRV Domain Controller records disappearing from the DNS Zone File. This is caused by the following issue;
As DNS is AD Integrated, the DNS data is stored in AD as separate objects for each record. One of the attributes of each record object is called “dnsRecord” which basically holds the information for every DC which registers that DNS record – so, this is a mulitvalued attribute with one value per DC – so, for the site-specific records, there are only a few values – dependant on the number of DC’s in the site (in most cases only 1). However, the other records will have a value in the dnsRecord attribute for every DC – so potentially this could be a large number of records in a large enterprise environment. The dnsRecord attribute contains information on the server name and the timestamp for the record (amongst other things). The timestamp is what is used to determine if this particular value within the record is stale (and hence can be scavenged as part of the DNS scavenging process) – e.g. if a DC is removed, we’d want the SRV record information to be removed from DNS accordingly.
The update of these values in AD is controlled by the Netlogon service on each DC which, by default, attempts to refresh the record data every 24 hours – however, once a record is refreshed (and the timestamp changed), the record cannot be refreshed again until the DNS NoRefresh interval has passed (7 days by default) – this is effectively to reduce replication traffic.
However, the issue we have been seeing reported from customers, is that because there are a high number of values in the dnsRecord attribute, and each DC only attempts an update every 24 hours, we have sometimes seen an issue where one DC updates the record with its own data, but before replication has completed to all other DC’s in the Domain, another DC also updates the record with its own data – and because the first change hasn’t replicated to the second DC, the dnsRecord attribute is superseded by the later one (last update wins). Because AD replication is at the attribute level, this is standard behaviour.
The recommended “fix” to alleviate this situation and which has helped several customers is the following;
- Recommendation to effectively set DnsRefreshInterval to 1 hour (back to Windows 2000 default) rather than 24 hours
- GPO: “Computer Configuration > Administrative Templates > System > Net Logon > DC Locator DNS Records” - - - “Refresh Interval of the DC Locator DNS Records” to 3600 (in seconds – i.e. 1 hour).
This recommendation may appear in a KB article in the future however, time of publishing is not know at this time.
Comments
- Anonymous
July 02, 2015
http://forums.civfanatics.com/showthread.php?p=13204419
http://www.astrologyweekly.com/forum/showthread.php?t=67144
http://talk.maemo.org/showthread.php?t=19947
http://forums.fourtitude.com/showthread.php?5094369-FlashZilla-Loader-and-ECU-Tunes&s=5071ae5eeb2e26cc76c848646e81db40
http://data-recovery-pro.tumblr.com/
http://www.anintroductiontodata.sitew.org/
http://datarecoverypro.soup.io/
http://datarecoverypro.yolasite.com/
http://www.snowatch.com.au/forum/entries/36-What-would-be-the-very-first-thing-you-would-do-if-you-won-the-lottery
http://www.britishcarforum.com/bcf/entry.php?47-So-you-are-lucky-enough-to-have-won-the-lottery - Anonymous
September 16, 2015
http://www.screencast.com/t/PDYlQFqhbU
https://www.facebook.com/1493892944265852
https://www.facebook.com/1493841417604338
http://www.screencast.com/t/c2snzVep4
http://www.screencast.com/t/HgjThXgB
https://www.pinterest.com/pin/50665564535278971/
https://www.facebook.com/1491517111167448
https://www.pinterest.com/pin/19421842120361815/
https://www.facebook.com/1485704191754503
http://www.screencast.com/t/RPKOmnXdLL
https://www.facebook.com/1485728395085416
http://www.screencast.com/t/VrHim0T7pR
https://www.facebook.com/1492524721066687
http://www.screencast.com/t/wmzKTw4Vm4ws
http://www.screencast.com/t/p5VnnWAe
https://www.pinterest.com/pin/19421842120361802/
https://www.facebook.com/1491429957842830
https://www.facebook.com/1488539544802235
https://www.facebook.com/1487874028202120
http://www.screencast.com/t/nycJrwP6
https://www.pinterest.com/pin/50665564535279254/
https://www.facebook.com/1497198907268732
http://www.screencast.com/t/oWn51kl0N
https://www.facebook.com/1483244055331527
https://www.pinterest.com/pin/19421842120367692/
http://www.screencast.com/t/vPvQ7LoIFBLz
http://www.screencast.com/t/ZBBMao54UT3
https://www.facebook.com/1483749715280961
https://www.facebook.com/1493416294310043
https://www.pinterest.com/pin/19421842120361883/
http://www.screencast.com/t/sCagFQ9u
https://www.pinterest.com/pin/350647520966517887/
https://www.facebook.com/1483693878619878
https://www.pinterest.com/pin/160511174196348277/
http://www.screencast.com/t/OCN2px9yF
http://www.screencast.com/t/6FTBOU0pQQ
https://www.pinterest.com/pin/84583299228832143/
https://www.facebook.com/1484679185190337
https://www.facebook.com/1494564907531989
http://www.screencast.com/t/8nH5GWAkkif
https://www.pinterest.com/pin/50665564535280306/
https://www.pinterest.com/pin/50665564535278743/
http://www.screencast.com/t/eJb4pzZmq
http://www.screencast.com/t/ufg5CGqMJ
https://www.facebook.com/1485740631750859
https://www.pinterest.com/pin/350647520966517724/
https://www.facebook.com/1493432030975136
http://www.screencast.com/t/cyqxfSrK5zo
http://www.screencast.com/t/5p6sqJGCTL
https://www.pinterest.com/pin/148478118942137391/