Small Business Susan

Disabling DNS dynamic updates

From the mailbox… 

We have a few inherited SBS 2003 boxes, in addition to ones we have deployed ourselves. On two of the inherited ones, we were having problems with RWW making connections to specific client machines. It turned out that the machines had multiple DNS A records on the SBS box (accumulated over time when they had changed IP for whatever reason) so RWW was having trouble finding the right IP. This was solved by editing the properties on server in the DHCP MMC, and checking “Enable DNS dynamic updates…” on the DNS tab, thus having the client machines update the SBS DNS each time they pulled a lease. At first I assumed that this was an oversight in the original setup, but as I rolled out new SBS box last weekend I noticed that by default it didn’t have that boxed checked either, so that caused me to wonder if I had solved the original problem in “best practice” manner. So I guess the summary of this question is: Is there a reason why SBS 2003 does not by default “Enable DNS dynamic updates” via DHCP? I assume that the server that DHCP would be updating would be the SBS server, and we’re not talking about external ones (which would have obvious security concerns). One curious thing I did find while I was googling this was: made it appear that in fact the SBS setup specifically disables this…which really made me wonder if we had done the right thing…Any direction you could point me in would be very helpful!

Just to let Kris know that I’m still trying to get the official reason as to why SBS 2003 has “Enable DNS dynamic updates” unchecked.  Because we don’t have it enabled, you can be like Kris and end up in a situation where the DNS/A records are pointing to the wrong or non existent box.

I think it’s okay to enable that, but I’m checking and will let you know for certain.  The way to test for this is to ping the workstation by IP and name and see if it responds to the right IP address that it’s supposed to.  If not flush out the offending stale DNS/A workstation (just go into DNS and delete the workstation) and it will repopulate with the right one.

I think it will be okay to change this setting…but I’ll update this post when I know for certain.  I’m seeing this issue more and more as we get crustier and move around workstations.  Look in your DNS and see if there are workstation/A records that are old and just don’t belong anymore.

Disabling DNS dynamic updates

By disabling the Domain Name System (DNS) dynamic updates function, the responsibility of managing the DNS server is returned to the administrator. Disabling DNS dynamic updates might be suitable for networks where hosts rarely change locations, where growth and change are infrequent, and when stricter DNS server administration is required

1 comment so far ↓