Please Help me with DNS :(

Matt
Valued Contributor

So I work in a messy flat environment and DNS and Mac's don't like each other very much. We use Infoblox.

I have a question about DNS. In the past I just setup the server, put in the Static IP given to me, and put the name in, bound to AD, disabled internal DNS, and bam that was it. server.mydomain.com<http://server.mydomain.com> would show up and it was happy days! With Lion however that is not the case. The servers keep reverting back to .local. I am not a DNS or server expert and I am racking my brain trying to figure out why all of the sudden after a reboot my server is no longer pingable and why it is now server.local again. Can someone give me some insight on why this happens and how do I get this to goto server.mydomain.com<http://server.mydomain.com>. We use DNS servers here already so my IP Forwarders are pointing to that and my server is pointing to them also.

Please help!
--
Matt Lee, CCA/ACMT/ACPT/ACDT
Senior IT Analyst / Desktop Architecture Team / Apple S.M.E / JAMF Casper Administrator
Fox Networks Group

17 REPLIES 17

Matt
Valued Contributor

Thanks for the response!

Computer name is just Server no .domain or anything
Server is bound to AD (could this be a Lion issue?)
* AD and Infoblox is integrated on the back end.

It is looking like this is a Lion AD issue because this all happened after we upgraded to Lion.

--
Matt Lee, CCA/ACMT/ACPT/ACDT
Senior IT Analyst / Desktop Architecture Team / Apple S.M.E / JAMF Casper Administrator
Fox Networks Group

Not applicable

Are you setting the name using the changeip command from terminal? I know that apple has recommended in the past that is the best and safest way to set the local name to match the name that is listed in DNS. Also make sure that there is only one A Record in dns. I have seen in the past where multiple A Records can cause hovac to a mac server.

Alan Hefner
alan-hefner at cherokee.orgapplewebdata://16DE2535-FDEC-4C39-836E-C6EDB5AB2802/alan-hefner@cherokee.org
918.453.5160
Multimedia Developer
Information Systems
Cherokee Nation

Matt
Valued Contributor

I don't have DNS running at all on the Server currently (nor on any of the other servers and they work). I did the changeip command and it says a DNS record error and the Infoblox guys say nothing is wrong on there end. Arg!

--
Matt Lee, CCA/ACMT/ACPT/ACDT
Senior IT Analyst / Desktop Architecture Team / Apple S.M.E / JAMF Casper Administrator
Fox Networks Group

Not applicable

Just curious, what is the output of changeip –checkhostname?

Alan Hefner
alan-hefner at cherokee.orgapplewebdata://16DE2535-FDEC-4C39-836E-C6EDB5AB2802/alan-hefner@cherokee.org
Multimedia Developer
Information Systems
Cherokee Nation

Matt
Valued Contributor

Primary address = X.X.X.X

Current HostName = server.domain.com<http://server.domain.com>

The DNS hostname is not available, please repair DNS and re-run this tool.

--
Matt Lee, CCA/ACMT/ACPT/ACDT
Senior IT Analyst / Desktop Architecture Team / Apple S.M.E / JAMF Casper Administrator
Fox Networks Group

Not applicable

Any way to have your DNS administrator manually insert / create an A Record in DNS for you?

Alan Hefner
alan-hefner at cherokee.orgapplewebdata://16DE2535-FDEC-4C39-836E-C6EDB5AB2802/alan-hefner@cherokee.org
Multimedia Developer
Information Systems
Cherokee Nation

Matt
Valued Contributor

They said they cannot. Infoblox seems to be crap.

--
Matt Lee, CCA/ACMT/ACPT/ACDT
Senior IT Analyst / Desktop Architecture Team / Apple S.M.E / JAMF Casper Administrator
Fox Networks Group

stevewood
Honored Contributor II
Honored Contributor II

Double check the DNS entries for your server using dig or nslookup, then
On Thu, Sep 1, 2011 at 12:51 PM, Matthew Lee <Matt.Lee at fox.com> wrote:
check the reverse entries for your server. I had that same error message
recently and it turned out to be a reverse lookup problem.

Steve Wood
Director of IT
swood at integer.com

The Integer Group | 1999 Bryan St. | Ste. 1700 | Dallas, TX 75201
T 214.758.6813 | F 214.758.6901 | C 940.312.2475

Not applicable

You mentioned in your original post that you were using lion and binding to AD. Im wondering if this may be a bug or something similar to the issues with lion client and binding to AD.

Hopefully someone else will chime in shortly and have an answer as I am now curious as well.

Alan Hefner
alan-hefner at cherokee.orgapplewebdata://16DE2535-FDEC-4C39-836E-C6EDB5AB2802/alan-hefner@cherokee.org
Multimedia Developer
Information Systems
Cherokee Nation

talkingmoose
Moderator
Moderator

Primary address = X.X.X.X
On 9/1/11 12:42 PM, "Matthew Lee" <Matt.Lee at fox.com<mailto:Matt.Lee at fox.com>> wrote:

Current HostName = server.domain.com<http://server.domain.com>

The DNS hostname is not available, please repair DNS and re-run this tool.

Host name would be something like: server1
DNS/FQDN would be something like: server1.example.com<http://server1.example.com>

Until you bind your server to AD, OD or whatever directory system you're using your server will be server1.local.

Only after your server is bound to a directory system will its name become server1.example.com<http://server1.example.com>. If your server appears to regress to server1.local then it's losing its binding. Verify that it is still bound in AD or that it's binding in the first place.

Don’t put server1.example.com<http://server1.example.com> in the Computer Name field if you're doing so. Put server1.

You also need to determine if your AD system is integrated with your Infoblox system. If not then you will need to manually create a DNS A record in Infoblox if that is what your organization is using for company-wide DNS.

A personal note and others are fine to disagree with me. I don't really mind occasional off-topic questions on a list for Casper. The expertise here is really excellent and diverse. But these types of questions would probably be better asked on the MacEnterprise list or a forum for the product you're discussing so that the signal to noise ratio is kept low here. I'm not a moderator and not trying to moderate; just a list member.

--

William Smith
Technical Analyst
Merrill Communications LLC
(651) 632-1492

bentoms
Release Candidate Programs Tester

Sorry to be that guy again.

BUT my lion servers have successfully changed/updated it's hostname using the changeip command.

Bound to AD but no infoblox.

Regards,

Ben.

leslie
Contributor II
Contributor II

I've been in other environment where infoblox is used and experience odd DNS behavior. However, they've also been able to add/remove DNS entries. Have a hard time believing a DNS appliance does not allow manual entry, unless they don't have the necessary permissions.

Leslie N. Helou
Senior Systems Engineer
Bell Techlogix
8888 Keystone Crossing, Suite 1700
Indianapolis, IN 46240

Matt
Valued Contributor

We are a shared service environment. All I can do is ask.
--
Matt Lee, CCA/ACMT/ACPT/ACDT
Senior IT Analyst / Desktop Architecture Team / Apple S.M.E / JAMF Casper Administrator
Fox Networks Group

jarednichols
Honored Contributor

We're in an infoblox environment and it seems to be fine. We have DynamicDNS enabled as well though so hosts register themselves with it and away you go.

j
---
Jared F. Nichols
Desktop Engineer, Client Services
Information Services Department
MIT Lincoln Laboratory
244 Wood Street
Lexington, Massachusetts 02420
781.981.5436

Matt
Valued Contributor

Thats how we have things set up. We have another department that handles all of that (very silo'd and hard to talk to!). I wonder what is making things harder for us. The worst is when a Mac gets an address assigned with a stale record, the Mac just assumes that DNS name and all hell breaks lose.

--
Matt Lee, CCA/ACMT/ACPT/ACDT
Senior IT Analyst / Desktop Architecture Team / Apple S.M.E / JAMF Casper Administrator
Fox Networks Group

donmontalvo
Esteemed Contributor III

Asking DNS folks to enable "scavenge stale records" is like pulling teeth. :(

We use scutil to force the Hostname in those environments, unless there's a compelling reason not to.

Don

--
https://donmontalvo.com

donmontalvo
Esteemed Contributor III

Asking DNS folks to enable "scavenge stale records" is like pulling teeth. :(

We use scutil to force the Hostname in those environments, unless there's a compelling reason not to.

Don

--
https://donmontalvo.com