B
Barkley Bees
I am currently preparing to perform DNS scavenging on one of our Forward DNS
Zones (domain.local) and was hoping to get some words of advice. This is a
fully Windows 2003 domain with 3 DC's hosting DNS.
The goal here is to get rid of the old stale client computer records. A few
questions, if I may:
1. To ensure that A records for all our static servers don't get deleted
during the scavenging I will uncheck "Delete this record when it becomes
stale" for them. After unchecking this should I be changing the TTL from 20
mins to 1 hour for these records or leave them as is?
2. In addition to the server A records, I can see the "Service Location
(SRV)" records (_gc, _kerberos, _ldap, _kpasswd) buried in subfolders within
the forward zone I want to scavenge. These records have the option to be
scavenged/deleted when they become stale. Should they have this option
removed so they cannot be scavenged? I ask, because these SRV records are
all of course associated with our 3 domain controllers.
3. As our DNS is hosted by all 3 of our DC's should I be scavenging on all
of them or just the primary?
4. Since I will only be scavenging one of our forward zones I will set the
scavenging directly on it but do I then also need to enable it on the server
itself (dnsmgmt -> servername -> Advanced -> Enabled automatic scavening of
stale records)?
5. What are the best practice "No-refresh interval" and "Refresh interval"
to use? I am assuming 7 and 7 days should be fine.
6. I assume that scavenging is not something you keep enabled all the time
but rather set every so often to clean up the dns records. What general
practice do you follow for scheduling (once a moth, quarter, etc)?
Appreciate any helplful advice. Thanks very much.
Zones (domain.local) and was hoping to get some words of advice. This is a
fully Windows 2003 domain with 3 DC's hosting DNS.
The goal here is to get rid of the old stale client computer records. A few
questions, if I may:
1. To ensure that A records for all our static servers don't get deleted
during the scavenging I will uncheck "Delete this record when it becomes
stale" for them. After unchecking this should I be changing the TTL from 20
mins to 1 hour for these records or leave them as is?
2. In addition to the server A records, I can see the "Service Location
(SRV)" records (_gc, _kerberos, _ldap, _kpasswd) buried in subfolders within
the forward zone I want to scavenge. These records have the option to be
scavenged/deleted when they become stale. Should they have this option
removed so they cannot be scavenged? I ask, because these SRV records are
all of course associated with our 3 domain controllers.
3. As our DNS is hosted by all 3 of our DC's should I be scavenging on all
of them or just the primary?
4. Since I will only be scavenging one of our forward zones I will set the
scavenging directly on it but do I then also need to enable it on the server
itself (dnsmgmt -> servername -> Advanced -> Enabled automatic scavening of
stale records)?
5. What are the best practice "No-refresh interval" and "Refresh interval"
to use? I am assuming 7 and 7 days should be fine.
6. I assume that scavenging is not something you keep enabled all the time
but rather set every so often to clean up the dns records. What general
practice do you follow for scheduling (once a moth, quarter, etc)?
Appreciate any helplful advice. Thanks very much.