unauthorized Same as parent entry

G

Guest

Guest
Archived from groups: microsoft.public.win2000.dns (More info?)

We're running MS Server 2003 flavor of DNS.
Configured Dynamic but not AD enabled.

Question is this: Is there a way to block a system from being added as
a Host A - Same as parent entry in DNS?

We keep getting an address that doesn't even belong to our address
space sho
wing up in our DNS.

Thanks



--
dodes1
------------------------------------------------------------------------
Posted via http://www.webservertalk.com
------------------------------------------------------------------------
View this thread: http://www.webservertalk.com/message455062.html
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.dns (More info?)

In news:dodes1.1f2gex@mail.webservertalk.com,
dodes1 <dodes1.1f2gex@mail.webservertalk.com> commented
Then Kevin replied below:
> We're running MS Server 2003 flavor of DNS.
> Configured Dynamic but not AD enabled.
>
> Question is this: Is there a way to block a system from
> being added as a Host A - Same as parent entry in DNS?
>
> We keep getting an address that doesn't even belong to
> our address space sho
> wing up in our DNS.

The (same as parent folder) record is registered by Netlogon and should only
be created for Domain Controllers. If you are not running an AD domain then
there is nothing I can tell you to stop the record because the Netlogon
service which creates the record does not run without a domain. If you are
getting one of these records created then you should track down the machine
that is creating it. I have seen cases of XP clients registering Netlogon
registrations, but you stated you do not have a domain, and as I stated the
Netlogon Service only runs when it is a member of a domain. Otherwise, the
Netlogon service is disabled and will not start, even if you try.



--
Best regards,
Kevin D4 Dad Goodknecht Sr. [MVP]
Hope This Helps
===================================
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
===================================
http://www.lonestaramerica.com/
===================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
===================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
===================================
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.dns (More info?)

Let me clarify Kevins post.
the same as parent records are helper records for DNS queries that only
specify the domain. abc.com
The query result will be a domain controller host record. I don't know the
extent to which these records are queried. I suspect they are not used
much, but would would not want to remove them and force the system to not
register them, then see what systems break.
The netlogon service is responsible for registering these records based on
the contents of the netlogon.dns file.
The netlogon.dns file is created/modified when the domain controller is
promoted or demoted. This includes promoting and demoting to GC status.
There is nothing preventing you from manually editing this file (its just a
text file) and removing the same as parent entries.
Better yet scan all your netlogon.dns files (one on every DC) to locate the
bogus record and remove it.
Then investigate why it was there in the first place.
You may find the NIC (on that DC) has 2 logical IP addresses assigned. Or
perhaps it has a loopback adapter installed with the bogus IP address.

--
Glenn L
CCNA, MCSE 2000, MCSE 2003 + Security


"Kevin D. Goodknecht Sr. [MVP]" <admin@nospam.WFTX.US> wrote in message
news:eYTjDRJwEHA.2016@TK2MSFTNGP15.phx.gbl...
> In news:dodes1.1f2gex@mail.webservertalk.com,
> dodes1 <dodes1.1f2gex@mail.webservertalk.com> commented
> Then Kevin replied below:
> > We're running MS Server 2003 flavor of DNS.
> > Configured Dynamic but not AD enabled.
> >
> > Question is this: Is there a way to block a system from
> > being added as a Host A - Same as parent entry in DNS?
> >
> > We keep getting an address that doesn't even belong to
> > our address space sho
> > wing up in our DNS.
>
> The (same as parent folder) record is registered by Netlogon and should
only
> be created for Domain Controllers. If you are not running an AD domain
then
> there is nothing I can tell you to stop the record because the Netlogon
> service which creates the record does not run without a domain. If you are
> getting one of these records created then you should track down the
machine
> that is creating it. I have seen cases of XP clients registering Netlogon
> registrations, but you stated you do not have a domain, and as I stated
the
> Netlogon Service only runs when it is a member of a domain. Otherwise, the
> Netlogon service is disabled and will not start, even if you try.
>
>
>
> --
> Best regards,
> Kevin D4 Dad Goodknecht Sr. [MVP]
> Hope This Helps
> ===================================
> When responding to posts, please "Reply to Group"
> via your newsreader so that others may learn and
> benefit from your issue, to respond directly to
> me remove the nospam. from my email address.
> ===================================
> http://www.lonestaramerica.com/
> ===================================
> Use Outlook Express?... Get OE_Quotefix:
> It will strip signature out and more
> http://home.in.tum.de/~jain/software/oe-quotefix/
> ===================================
> Keep a back up of your OE settings and folders
> with OEBackup:
> http://www.oehelp.com/OEBackup/Default.aspx
> ===================================
>
>
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.dns (More info?)

In news:%237u0YUOwEHA.2196@TK2MSFTNGP14.phx.gbl,
Glenn L <the.only@gmail.com> commented
Then Kevin replied below:
> Let me clarify Kevins post.
> the same as parent records are helper records for DNS
> queries that only specify the domain. abc.com
> The query result will be a domain controller host record.
> I don't know the extent to which these records are
> queried. I suspect they are not used much,

Let me clarify further, he stated he didn't have AD, but it is only domain
controllers that register these records. They are required and are used
quite regularly by group policies. The IP of the record must point to the
interface on a domain controller that has file sharing enabled so the SYSVOL
DFS share at \\dnsdomainname\SYSVOL can be resolved. Group policies are
applied from the \\dnsdomainname\SYSVOL\dnsdomainname\policies share. Group
policies are not applied from the machine name IP address. Changing this so
the record points to say a web server, will cause errors and the inability
for GPOs to be applied.



--
Best regards,
Kevin D4 Dad Goodknecht Sr. [MVP]
Hope This Helps
===================================
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
===================================
http://www.lonestaramerica.com/
===================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
===================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
===================================
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.dns (More info?)

I think he meant his zone is not AD integrated rather than not having an AD
domain inplace when he said "We're running MS Server 2003 flavor of DNS.
Configured Dynamic but not AD enabled.", .



"Kevin D. Goodknecht Sr. [MVP]" <admin@nospam.WFTX.US> wrote in message
news:%23zNeIpOwEHA.1260@TK2MSFTNGP12.phx.gbl...
> In news:%237u0YUOwEHA.2196@TK2MSFTNGP14.phx.gbl,
> Glenn L <the.only@gmail.com> commented
> Then Kevin replied below:
>> Let me clarify Kevins post.
>> the same as parent records are helper records for DNS
>> queries that only specify the domain. abc.com
>> The query result will be a domain controller host record.
>> I don't know the extent to which these records are
>> queried. I suspect they are not used much,
>
> Let me clarify further, he stated he didn't have AD, but it is only domain
> controllers that register these records. They are required and are used
> quite regularly by group policies. The IP of the record must point to the
> interface on a domain controller that has file sharing enabled so the
> SYSVOL
> DFS share at \\dnsdomainname\SYSVOL can be resolved. Group policies are
> applied from the \\dnsdomainname\SYSVOL\dnsdomainname\policies share.
> Group
> policies are not applied from the machine name IP address. Changing this
> so
> the record points to say a web server, will cause errors and the inability
> for GPOs to be applied.
>
>
>
> --
> Best regards,
> Kevin D4 Dad Goodknecht Sr. [MVP]
> Hope This Helps
> ===================================
> When responding to posts, please "Reply to Group"
> via your newsreader so that others may learn and
> benefit from your issue, to respond directly to
> me remove the nospam. from my email address.
> ===================================
> http://www.lonestaramerica.com/
> ===================================
> Use Outlook Express?... Get OE_Quotefix:
> It will strip signature out and more
> http://home.in.tum.de/~jain/software/oe-quotefix/
> ===================================
> Keep a back up of your OE settings and folders
> with OEBackup:
> http://www.oehelp.com/OEBackup/Default.aspx
> ===================================
>
>
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.dns (More info?)

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<body>
<blockquote type="cite"
cite="mid%237u0YUOwEHA.2196@TK2MSFTNGP14.phx.gbl">
<p>I don't know the extent to which these records are queried. </p>
</blockquote>
<p><a
href="http://homepages.tesco.net./%7EJ.deBoynePollard/FGA/dns-ms-dcs-overwrite-domain-name.html#LocalFix">You
do now.</a>  (-:</p>
</body>
</html>
 

TRENDING THREADS