Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >

KB-0171: Troubleshooting DNS issues

Auditing and Monitoring Service ,   Authentication Service ,   Mac & PC Management Service ,  

12 April,16 at 11:11 AM

How to troubleshoot DNS issues? 

Here is a summary of the most common DNS issues, namely a UNIX box pointing to a DNS setup that knows nothing about the Windows domain. 
This is by far the most common issue. When entering "adjoin", the UNIX system must be able to see via DNS. 
If is a test domain, it is almost certain that the UNIX box will NOT be able to see the domain. 

How to tell if this is the case:
Running "ping" will help: 
[pmoore@caterpillar pmoore]$ ping 
PING ( 56(84) bytes of data. 
64 bytes from ( icmp_seq=1 ttl=128 time=0.142 ms 
64 bytes from ( icmp_seq=2 ttl=128 time=0.228 ms 
64 bytes from ( icmp_seq=3 ttl=128 time=0.233 ms 
The only time when it is acceptable that it doesn’t work is if the domain controller is not being used as the DNS server (i.e. using a UNIX DNS server). 
If that is the case, try "ping". Note that if a non AD DNS server is being used then there is a lot of work to do on the DNS Server (Please see the Admin Guide). 
How can this be fixed?:
Case A) 
Set /etc/resolv.conf to point to the domain controller. Note that if the UNIX box gets its IP address via DHCP, then it’s almost certain that the /etc/resolv.conf file is configured by DHCP to point to where-ever the DHCP server says the DNS should be; the DHCP will keep changing it back to the DHCP-preferred values even after manually editing.
Note that one cannot add a second entry in the /etc/resolv.conf file. These entries are not tried in sequence, it only tries the second entry if the first DNS server fails to answer at all; the assumption is that all the DNS servers have the same data .
Case B) 
Add an entry to the DNS server that the UNIX box does point to. This entry should delegate to the DC; however this is not the best practice in the deployed organizations. 
Case C) 
Put the domain controller in /etc/hosts and add it to the CDC configuration file. fixdns will also do this. 
In Case A) or B), ping should now work. 
Now run adinfo --diag and look for:
Locating global catalogs for from DNS 
Found SRV records: 
Locating domain controllers for from DNS 
Found SRV records: 
This shows that the DNS server was contacted and found the data needed. 
For Case C, there are no more tests to perform except trying to join the domain.