Odd activity

G

Guest

I've been working on this problem for many hours at a time for over a week
now, and I'm stumped, and am hoping that someone might be able to give me
some assistance.

I have 2 users (that I know of) that have persistent connection drops. I
can see the problem as odd as it would seem, yet I don't know where it's
coming from. I have been monitoring these users connections and running
Ethereal scans on their machines and I can see when they get dropped. When I
ping -a on their IP addresses they no longer show up as their regular machine
ID's.

The machine ID's that are showing up as these people's IP address are
machines that no longer exist!!! These machines aren't listed in the Active
Directory as computers and one of them is showing up in WINS with a
"tombstoned" state, but how are they grabbing these users IP addresses?

I'm pretty sure this is a DNS problem, yet can't quite put my finger on how
these old machine names are getting propagated back into the picture.

I'm seeing other oddities in DNS like multiple machines with the same IP
address too. I have flushed the DNS, but this didn't seem to help.

In DNS there's an option to "Reload". Is this the same thing as doing
ipconfig /flushdns at the command prompt, or does it do something else?
 
A

Ace Fekay [MVP]

In
Penny said:
I've been working on this problem for many hours at a time for over a
week now, and I'm stumped, and am hoping that someone might be able
to give me some assistance.

I have 2 users (that I know of) that have persistent connection
drops. I can see the problem as odd as it would seem, yet I don't
know where it's coming from. I have been monitoring these users
connections and running Ethereal scans on their machines and I can
see when they get dropped. When I ping -a on their IP addresses they
no longer show up as their regular machine ID's.

The machine ID's that are showing up as these people's IP address are
machines that no longer exist!!! These machines aren't listed in the
Active Directory as computers and one of them is showing up in WINS
with a "tombstoned" state, but how are they grabbing these users IP
addresses?

I'm pretty sure this is a DNS problem, yet can't quite put my finger
on how these old machine names are getting propagated back into the
picture.

I'm seeing other oddities in DNS like multiple machines with the same
IP address too. I have flushed the DNS, but this didn't seem to help.

In DNS there's an option to "Reload". Is this the same thing as doing
ipconfig /flushdns at the command prompt, or does it do something
else?

Delete the addresses in DNS that no longer exist. Check WINS again for any
other old machines that may have been overlooked.

--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

If this post is viewed at a non-Microsoft community website, and you were to
respond to it through that community's website, I may not see your reply
unless that website posts replies back to the original Microsoft forum.
Therefore, please direct all replies ONLY to the Microsoft public newsgroup
this thread originated in so all can benefit or ensure the web community
posts it back to the original forum.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft Windows MVP - Windows Server - Directory Services
Microsot Certified Trainer
Infinite Diversities in Infinite Combinations.
=================================
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top