Mismatched Glue and Windows Server DNS
I host my own dns on server 2008 dns server. I have created a zone depotview.com. I use dnsstuff.com to check my config and it reports the following error. ERROR: Your nameservers report glue that is different from what the parent servers report. This will cause DNS servers to get confused; some may go to the IP provided by the parent servers, while others may get to the ones provided by your authoritative DNS servers. Problem record(s) are: ns01.adventinc.com.:Parent server (k.gtld-servers.net) says A record is 64.1.231.179, butauthoritative DNS server (64.1.231.179) says it is 64.1.231.147 I have deleted and recreated this zone, including going to the system32\dns folder and deleting the depotview.dns zone file that gets left behind but I cannot get rid of the mismatched glue error. Additionally, that host at 64.1.231.147 does not exist physically, nor is there a record for it in any of my existing DNS zones. This is driving me nuts...ANYONE got any pointers to fix this? Are there some kind of hidden records in MS DNS?
March 11th, 2010 12:44am

Hello,please describe your domain setup including the DNS domain name, name shown in AD UC and the NetBios name. Also list the zoens you have configured for your domain.Best regards Meinolf Weber Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
Free Windows Admin Tool Kit Click here and download it now
March 11th, 2010 2:18am

It appears that your server also hosts the zone adventinc.com, and in that zone is an A record for ns01.adventinc.com that lists it's IP as 64.1.231.147
March 11th, 2010 6:36am

Thanks for your replies,I do also host adventinc.com on 2 servers, dns1.adventinc.com and dns2.adventinc.com. The zone however has the correct record for ns01.adventinc.com = 64.1.231.179 listed when looking at the dns manager console and in the adventinc.com.dns file ... Therein lies the confusion. A query to dns2 returns the correct result but a query to dns1 returns the errant result. See the links below from dnssstuff.comdns1http://www.dnsstuff.com/tools/lookup?name=ns01.adventinc.com&type=A&server=dns1.adventinc.com&detail=0&token=17d190fd97e0333728b2780132a22019dns2http://www.dnsstuff.com/tools/lookup?name=ns01.adventinc.com&type=A&server=dns2.adventinc.com&detail=0&token=1721a0b906653c7328f2860d3665c018So what I need to know is where on earth can I look for this non existent record on dns1.adventinc.com. As I said, looking in DNS manager displays a record with the correct IP address. Looking in the adventinc.com.dns file also shows the correct IP address...see below.;; Database file adventinc.com.dns for adventinc.com zone.; Zone version: 2009043041; @ IN SOA dns1.adventinc.com. hostmaster.adventinc.com. ( 2009043041 ; serial number 3600 ; refresh 600 ; retry 1209600 ; expire 3600 ) ; default TTL ;; Zone NS records; @ NS dns1.adventinc.com.@ NS dns2.adventinc.com. ;; Zone records; @ A 64.1.231.162@ MX 20 server509.appriver.com.@ MX 10 server508.appriver.com.@ TXT ( "v=spf1 a:mail.adventinc.com ~all" )@ TXT ( "spf2.0/pra" "mx" "mx:mail.adventinc.com" "mx:mail2.adventinc.com" "ip4:64.1.231.161" "ip4:64.1.231.171" "+all" )ahweb01pr A 209.123.81.3aplrtls A 64.1.231.152arcisqa A 64.1.231.156chassisdemo A 64.1.231.177dns1 A 64.1.231.161dns2 A 12.173.91.104edisite A 64.1.231.166face A 64.1.231.187ftp A 64.1.231.173globalaceprototype A 64.1.231.183globalaceqa A 64.1.231.176 ;; Delegated sub-zone: hq.adventinc.com.;hq NS adv03.hq.adventinc.com.; End delegation ns01 A 64.1.231.179owa A 64.1.231.186pcs A 64.1.231.157pierpass A 64.1.231.185port-view A 64.1.231.157ppvtxws A 64.1.231.151prime A 64.1.231.169sslmnr A 64.1.231.173ssltis A 64.1.231.165ssrsqa A 64.1.231.167tfs A 64.1.231.164tms A 64.1.231.178vpn A 64.1.231.130webcam A 64.1.231.193webmail A 64.1.231.186webtos A 64.1.231.155www A 64.1.231.162 .....Help...its driving me nuts,ThanksColin
Free Windows Admin Tool Kit Click here and download it now
March 11th, 2010 7:04pm

That is wierd. Do you have any idea if ns01.adventic.com could have ever pointed to 64.1.231.147 in the past on any server? Could it have had a longer TTL in the past? What I'm getting at is, Have you checked Cached Lookups? If the problem server didn't always host the adventic zone, it may have put the record in the cache in the past. I can't think of any other reason it would return the wrong value for ns01...
March 11th, 2010 8:40pm

Brian / Meinolf thanks for looking at this. The problem server has always hosted the adventinc.com domain, it is our Primary. I have cleared the cache on the server and scavenged stale resource records, then stopped and restarted the DNS service...(all using the DNS snap in) Still it returns this phantom record...64.1.231.147 instead of 64.1.231.179 from the outside If i run nslookup on the box itself I get the correct answer returned... Are there any other steps I can take to see/clear this record>? Thanks C.
Free Windows Admin Tool Kit Click here and download it now
March 11th, 2010 10:58pm

cg123 said:"If i run nslookup on the box itself I get the correct answer returned..."That is strange. When you run nslookup are you setting the server you want to query or taking the default? By default nslookup is going to query the DNS server configured on the adapter tcpip settings on the machine it's running on. It sounds like the server isn't using itself as the primary DNS server. Make sure you specify 'SERVER 64.1.231.179' to nslookup before making your query. This isn't going to solve your real problem, but it should help you get consistent answers.
March 13th, 2010 4:26am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics