Rogue DNS Settings appearing after initial DHCP lease

I am having issues with DNS settings changing on clients soon after allocation via DHCP. This is a workgroup only, no windows domain. DHCP is running from a Fortigate 60b which acts as the primary DNS server and Google DNS configured as secondary. The DHCP lease time is 8 days, these DNS changes can happen 3 times or more in a working day. The network consists of a single subnet, there is also an internal wireless network using Ubiquiti AP's.
1. Malware has been ruled out, having scanned machines with AV and Malware detection finding nothing.2. Have setup port mirroring on switch ports and scanned traffic for other sources of DHCP offer packets.. none found.3. When the DNS settings change they are different on each machine, but each time it is a valid IP for the network that can be found in the DHCP leases on the 60b.I was expecting to...
This topic first appeared in the Spiceworks Community

I am having issues with DNS settings changing on clients soon after allocation via DHCP. This is a workgroup only, no windows domain. DHCP is running from a Fortigate 60b which acts as the primary DNS server and Google DNS configured as secondary. The DHCP lease time is 8 days, these DNS changes can happen 3 times or more in a working day. The network consists of a single subnet, there is also an internal wireless network using Ubiquiti AP's.
1. Malware has been ruled out, having scanned machines with AV and Malware detection finding nothing.2. Have setup port mirroring on switch ports and scanned traffic for other sources of DHCP offer packets.. none found.3. When the DNS settings change they are different on each machine, but each time it is a valid IP for the network that can be found in the DHCP leases on the 60b.I was expecting to...
This topic first appeared in the Spiceworks Community

Similar Messages

  • Plugin login appears after initial weblogic everytime applet makes http request

    When I visit a page I get the initial login to the page via the realm followed
    by a java plugin loging (shown in attached pictures) every time the applet makes
    an http request. This stops the applet working, any idea how I can solve this?
    [pictures.doc]

    Any idea how to do thisn not really sure what you mean. I already inclued the session
    Id in the URL. Code we use to open connection is
    URL url = new URL(serverProtocol + "://" + serverName + ":" + serverPort + "/"
    + servlet + ((sessionId==null)?"":"?sessionid=" + sessionId));
    URLConnection uc = url.openConnection();
    uc.setDoOutput(true);
    uc.setDoInput(true);
    uc.setUseCaches(false);
    uc.setRequestProperty("Content-type", "java-internal/" + object.getClass().getName());
    Robert Patrick <[email protected]> wrote:
    If you are making HTTP requests from within an applet, you will need
    to provide the
    right HTTP headers to correctly identify that each subsequent request
    is from the
    previously logged-in user (e.g., the cookie that contains the WLS session
    ID
    attached to the response from logging in).
    andrea bates wrote:
    When I visit a page I get the initial login to the page via the realmfollowed
    by a java plugin loging (shown in attached pictures) every time theapplet makes
    an http request. This stops the applet working, any idea how I cansolve this?
    Name: pictures.doc
    pictures.doc Type: WINWORD File (application/msword)
    Encoding: base64

  • DNS aging and DHCP lease

    Hi all,
    I have AD integrated DNS server. Need advise how to set DNS aging\scavenging based on DHCP lease time. I know how the process works. Found couple of articles where is written "DHCP
    lease duration should match the “no-refresh + refresh” interval."
    Why should DHCP lease be equal to the sum of non-refresh and refresh interval? From my point of view DHCP lease time should be more than DNS non-refresh interval (and less then non-refresh + refresh interval) so DNS clients are able to register new DHCP
    assigned IP address to DNS within refresh period, right?
    Are there any "rules" which tells me what's the best set up of all this timers?
    Tomas

    Hi all,
    Why should DHCP lease be equal to the sum of non-refresh and refresh interval? 
    Because when Non-refresh and Refresh interval expires and the record is not updated it is considered as inactive as Ahmed said. My environment is based on
    (NonRef+Ref) = Lease and works correctly. Just do not try to scavenge records on AD Integrated zones if DHCP lease is something like 2-3 days. Yo will end up in a confusion state with a lot of false
    positives which are considered as inactive but actually they are not inactives!
    Mahdi Tehrani   |  
      |  
    www.mahditehrani.ir
    Please click on Propose As Answer or to mark this post as
    and helpful for other people.
    This posting is provided AS-IS with no warranties, and confers no rights.
    How to query members of 'Local Administrators' group in all computers?

  • DNS settings

    I don't understand why DNS settings appear in the setup both on the LAN side and the WAN side.
    What does this mean?
    Which should be set if  I want all clients to use a specified DNS list?

    seryanhoj wrote:
    EA6350. I am presently using static on the wan side (so I can elect a dns list) and leaving the lan side alone.
    Client devices report the dns as 192.168.1.1. 
    I don't aappear to have a way to determine which dns is actually used externally when a connection is made.
    This mabye by design of Linksys routers:
    https://community.linksys.com/t5/Wireless-Routers/WRT1900AC-s-DHCP-does-not-hand-out-the-specified-s...
    You an still use custom DNS, however the client HW will only get 192.168.1.1...

  • Windows 7 does not wake from sleep to renew DHCP Lease

    I am having trouble with DHCP and sleeping Windows 7 systems.  My Windows 7 systems go to sleep after an hour or so.  The Intel and Broadcom NICs we have use ARP offloading so they continue to respond to ARP while the machine is sleeping. 
    The problem is that after the DHCP lease expires, the NIC continues to respond to the ARP requests and that causes IP conflicts on the network because the computer is responding to ARP requests for an IP address the computer has lost its lease on.  Any
    time a computer is asleep for longer than the DHCP lease time then when a new computer gets the IP from the lost lease, an IP conflict is reported because the new leasee does an ARP to see if the IP is in use and the sleeping computers NIC responds to the
    ARP and this results in an IP conflict for the new leasee.
    I opened a ticket with the Hardware Vendor, which is Dell in this case, and they opened an engineering case with Intel - the NIC OEM.  The outcome of this case what that this is Windows fault.  Windows is supposed to wake up from sleep and renew
    its DHCP lease at the lease half life and then go back to sleep.  My computers are not doing this.  They let the lease expire while they are sleeping.
    Is there a problem with Windows 7 that prevents it from waking up and renewing its lease periodically?  It is supposed to maintain the lease according to Dell and Intel, but in my case it it not. 

    Extending the lease time is a bandage on the problem, and it is what we have done while I attempt to resolve the issue.
    The network group would like the lease time set to 4 hours.
    Extending the lease time doesn't resolve the issue because it only makes the problem occur less freqently.  With a 2 week lease, a machine needs to be asleep for 2 weeks before it causes a problem.  Machines are not likely to be asleep for 2 weeks
    very often.
    The resolution would be to figure out why a sleeping Windows OS is not maintaining its IP address.  If it is not going to renew the DHCP lease while it is asleep, it is still responsible for updating the TCP stack (and the NIC) to let it know that it
    no longer has a lease to that IP address.  The OS has offloaded ARP to the NIC, which continues to respond to ARP while the computer is asleep.  If the OS lets the lease expire, then it needs to notify the NIC to stop responding to ARP requests for
    that address.

  • Self-assigned IP after trying to renew DHCP lease for former network

    Hi all,
    MacBook Pro 15" purchased in Februrary 2008, currently running 10.5.5, up-to-date with patches as of yesterday, 10/20/2008.
    For a few weeks now, I've been consistently unable to connect to wireless networks (secured or unsecured, public or private) after changing networks (i.e. going from home to a coffee shop).
    I have control over my home network router, and its logs show that upon connecting to the network, OS X tries to renew a DHCP lease for the previous network it was on. Upon receiving the "bad network" DHCP reply, instead of releasing the lease and obtaining a new one, the AirPort interface is immediately assigned an IPV4LL address (from 169.254.0.0/16) and no combination of changing network settings, changing AirPort settings, or rebooting will eliminate the old DHCP lease.
    The end result is that my MBP is entirely nonfunctional on some wireless networks that other clients (both Windows and Mac) seem to have no trouble accessing. The problem is quite annoying because I can't connect to access points that (previously) worked fine and whose configurations haven't changed.
    In any case where this problem occurs, an old DHCP lease for a different network (10.0.0.0/8 when trying to get on 192.168.0.0/24 or vice versa) is present, so I strongly suspect a DHCP problem. In all cases, I have perfect connectivity to the access point itself, so problems with the wireless connection parameters (including encryption), or those troublesome problems with 802.11b/g/n interoperation seem highly unlikely.
    One of two things would help me:
    1) Please tell me how to clear the DHCP lease cache. Deleting files from /var/db/dhcpclient/leases does nothing (they appear again upon reboot, identical save for timestamps even after changing network environments, so the cache must be read at boot time and written at shutdown). Selecting "Renew DHCP lease" from the "TCP/IP" tab in the advanced network settings merely attempts to renew the existing lease (for an invalid IP address); it does not appear to release invalid leases.
    2) If this is really how the DHCP client is behaving, change the DHCP client so that upon receiving the "Bad network" response, it releases (or simply abandons) the lease and obtains a new one, rather than immediately assigning an IPV4LL address to the AirPort interface.
    Additionally, is there any documentation on the Apple DHCP client? Under Linux, I could alter dhcpcd parameters to diagnose things like this. I could find no documentation about the Apple DHCP client outside of Mac Help, which wasn't really any help in this case.
    Finally, I do not suspect that this is an instance of the problem discussed in http://discussions.apple.com/thread.jspa?threadID=1352518&tstart=0 as my connection is rock-solid if it can get an IP address when it connects. I've never even seen it hiccup.
    Thanks,
    Matt Z.

    I have had wireless problems intermittently for a year, and seriously for 6 weeks. Apple denied the issue and was no help in spite of many tens of thousands of people on their own discussions complaining. I found a post suggesting a couple of things which fixed the problem. I don't know if both are necessary, but the first by itself does not solve the problem.
    Lock the channel of your router to channel 1, apparently Apple and 802.11n don't play well together on higher channels. When this becomes a standard this will be resolved I hope.
    Open your network preferences, select 'airport' and advanced. Delete unused networks. Select your network.
    Open TCP/IP and write down all the settings, configure iPv4 manually. Enter the settings manually. Turn off IpV6.
    Open DNS and write down your DNS server. Delete it and re-enter it manually.
    This has worked on 2 macbooks and an iMac for the last 3 weeks with no network drops.
    Joe Shea
    Philadelphia

  • TS1388 After one or two websites the search "freezes". To rectify this I need to go into "Network" and press "Renew DHCP Lease" on my imac 10.6.8

    After one or two websites the search "freezes". To rectify this I need to go into "Network" and press "Renew DHCP Lease" on my imac 10.6.8TS1317 - Mac OS X: Troubleshooting a cable modem, DSL, or LAN Internet connectionAny help?

    Check your computers time and date are correct, and updating to your location via Apple's servers.
    WiFi, Internet problems, possible solutions

  • What are DHCP settings and what is a DHCP lease

    My macbook has decided to stop logging on to my wifi router automatically.
    Seems the DHCP settings are wrong with an inappropriate IP address and Submask coded applied.
    When I change them back manually to what they were the computer says it is logged on to internet but refuses to open any internet application?
    I have tried the DHCP lease renewal prompt but still will not award appropriate IP or Submask code

    Hi RobertaMcC,
    Are you having trouble with a Wi-Fi connection or a wired (Ethernet) connection to the internet?  DHCP is a communications protocol that assigns each computer a unique IP address on the internet.    I'll include the information you specifically requested first, and general troubleshooting steps as well.
    OS X Yosemite: Renew an IP address from the DHCP server
    https://support.apple.com/kb/PH18513?locale=en_US
    Here is an overview of the troubleshooting steps for a Wi-Fi connection:
    Wi-Fi: How to troubleshoot Wi-Fi connectivity - Apple Support
    https://support.apple.com/en-ca/HT202222
    Hope that helps ...
    - Judy

  • Brand new computer - Windows 7 - Browser Mozilla Firefox - Trying to install Adobe Flashplayer - after initial box appears, I click 'save' and nothing happens - McAffee Anti virus already installed

    Brand new computer - Windows 7 - Browser Mozilla Firefox - Trying to install Adobe Flashplayer - after initial box appears, I click 'save' and nothing happens - McAffee Anti virus already installed - how do  proceed?

    Try using these installers:
    Flash Player for ActiveX (Internet Explorer)
    Flash Player Plug-in (All other browsers)

  • I bought iphone on donedeal.ie it had no icloud account on it. i erased content and settings as previous owner had photos on it.icloud appearing after erased content. Stuck on activation screen now

    i bought iphone on donedeal.ie it had no icloud account on it. i erased content and settings as previous owner had photos on it.icloud appearing after erased content. Stuck on activation screen now
    what can be done?

    http://support.apple.com/kb/PH13695
    Theres no issue with the mother board.  It's the activation lock look at the link I provided.
    There is nothing you or Apple can do without the previous owners icloud information.
    Like I already stated you have a paperweight.

  • How do I revoke a DHCP lease in the 10.8.4 server app?

    Hello Everyone,
    I have some devices (security cameras) that have successfully requested a DHCP lease.  Since then I went ahead and manually created a static reservation for them with a MAC hardware address in the DHCP.  For whatever reason they are not switching over to the reserved address.  The leases were originally for 1 day.  It has been 5 days now.  After the first day I switched my lease time to 1 hour.  I have done everything short of leaving the devices off for 24 hours.
    In Lion server, I could revoke the lease via the gui.  No such luck now.  My call to Applecare resulted in a "there is no way in 10.8.4 to do this".  They said it would switch to the new reserved address after the initial lease period timed out, so I'm hoping the representative was wrong twice.  They mentioned a complete lease wipe, but couldn't say if this would cause me to lose my list of reserved static addresses, which isn't an option.
    It seems crazy that such a basic feature wouldn't make it into this release of the DHCP service.  Any help would be greatly appreciated!

    Are there any DHCP queries from the cameras?  Check the DHCP server log via Console.app or Server.app (or Terminal.app) for details.  (I don't know the 10.8 path to the DHCP logs offhand.)
    According to a FAQ over at the Vivotek site, the following is the setup sequence for various recent cameras; the boxes start up in the "I don't have an IP address" self-allocated address block oddly enough, and apparently don't ask for a DHCP address?  (You may well be aware of all of this, but this is the block that DHCP clients use when they first communicate with DHCP servers.)
    If you are using our new product such as IP7138 / IP7139 / FD7131 / VS7100… etc, no matter your network environment is what, you can always find the camera by Installation Wizard II with the IP address 169.254.x.y.
    And then, please double click the camera found by Installation Wizard II or directly type the IP address to your Internet Explorer URL box to access your camera (you do not need to change your PC's IP address). After access your camera, please go to "Network" page to configure proper network settings.
    See if the devices are available via mDNS, as well; download the Bonjour Browser and have a look around your LAN.  (If you're very lucky, the cameras might be visible and chatting on mDNS.)
    Might also try resetting one of the cameras back to factory defaults, and seeing if you can get them to re-ask the DHCP server.
    (I've had issues with some HP printers and DHCP clients and IP address assignment, but that's fodder for another discussion.  And I also wouldn't rule out a rogue DHCP server, either.  I've seen all sorts of unexpected stuff connected to networks over the years...)

  • MDT 2013 - A Connection to the deployment share could not be made - DHCP Lease was not obtained

    First, let me give you some context:
    Framework: MDT 2013 with MS SDK 7.1
    Task Sequence: Standard Client TS with sysprep and capture.
    Target workstation (build workstation): VM Guest on ESX 5.5 host, 8 vCPU, 8GB RAM, LSI Logic SAS Controller, E1000 NIC, SSD DAS
    Behavior: The VM loads and installs the OS fine in PE, VM boots into OS successfully and resumes the TS, after the first system reboot, the error message occurs and it reads:
    A connection to the deployment share (\\*********\DeploymentShare$) could not be made. DHCP Lease was not obtained for any Networking device! Possible Cause: Check physical connection. Retry:...... Cancel:.....
    While observing this error, I didn't notice the NIC hadn't completely initialized and obtained an IP yet (network adapter icon in systray), additionally hitting retry after the NIC was initialized resumed the TS.
    This behavior reoccurs with several subsequent reboots until a few more applications (Citrix Receiver, VMware Tools) with services are installed which seem to then slow the system boot-up time and then allows the TS to start after the NIC has initialized.
    From several posts I've read on this forum, this particular behavior was alleviated by a "wait for IP lease" mechanism built into the TS engine which was introduced in MDT 2010 SP1, I wasn't able to find any other confirmation whether
    this mechanism is still in effect with MDT 2013. Another point worth mentioning from several other posts I was able to find is that this behavior appears to manifested itself on target workstations with SSDs, which would somewhat explain the faster
    TS load time vs waiting for an IP lease. I've also tried to replicate this behavior in a non-SSD and low-performance VM environment and I wasn't able to replicate it.
    My question: Does anyone else have experienced this behavior with MDT 2013 and if so, how did you resolve it? Or is this a bug?

    I have this issue intermittently as well.  For us, it coincided with the deployment of IP phones, which meant PoE switches all around.  However, the problem persisted even after we turned off PoE to the ethernet ports from which we normally PXE
    boot.
    As this issue has been intermittent, I've backburnered it.  When it does happen, I just wait for the lease to arrive then rerun the wizard.
    Thanks for the feedback, that's true the TS can be resumed manually once the lease has occured but it defeats the purpose of an automated TS if I have to keep an eye on it and intervene if I need to.
    The network guys here recommended putting wireshark or network monitor on it and figuring out just what the heck is going on.  Basically, what Keith Garner said.  They also disabled PortFast awhile back to see if that made any difference, and it did
    not.

  • DNS Settings have Changed with Snow Leopard Update

    Before I upgraded to SL, I was able to append a DNS server to the list of servers that my MacBook Pro acquired from the DHCP server. This way, I didn't have to manually edit my DNS settings all the time when I was in the office and wanted to access our lab network by name. Now after the upgrade, I have to remove all manually entered DNS servers before it will use the DNS servers given to it by the DHCP server. Is there a way that I can always append my lab DNS server to the list given to me by DHCP?
    Thanks,
    John

    I am on or office wireless network which handles the DHCP lease and DNS addressing, but I am an engineer in the office and access the lab often and we have another DNS server in the lab to handle all of the lab network. The Sales folk don't need access to the lab so the DHCP server doesn't give out the lab dns server... I would like to access the lab via name, not IP, so I need the lab DNS server on my list of servers. If I can't append this to the DHCP list, I have to manually add all three every time I am in the office. I am frequently out at customer/vendor sites and use thier wireless, so I get thier DNS list.
    Short answer is I need our lab DNS server on the list and frequently move from network to network... I want it to work the way it was before the "upgrade", which wasn't much of an "upgrade" if it breaks this. I want my Leopard back.
    John

  • VPN Client and DNS settings

    Hello,
    here are few posts (quite some time ago) telling the same trouble:
    The VPN Client does *NOT* restore the original DNS settings.
    Upon BM3.8.2 Massimo told, that this is a bug in that version of the VPN
    client. I face this issue with 3.8.16 and nwclient 4.91.4 with or without
    the three currently available hotfixes [1]
    Anybody else facing this trouble with the current VPN client release?
    May be an older one works better, any experiences?
    This trouble is fact even after clean disconnects. But it happens only now and then,
    I might need to try it 50 times to see it once.
    a followup in CMD boxes with ipconfig /all does show, that the times
    to restore the original DNS settings vary from 2 to 30 seconds. Mostly about 5 seconds.
    Massimo also told, that a "VPN-down" due to a Win-Shutdown can cause this: So is
    there a possibility to trigger a "clean-VPN down" in the Win-shutdown sequence?
    As a workaround I packed this line into all users "run" key:
    netsh int ip set dns name="LAN-Verbindung" source=dhcp
    so at least after a reboot it's corrected.
    Any suggestions appreciated,
    [1]
    Novell Client 4.91 Post-SP2/3/4 NWSPOOL.DLL
    Novell Client post-4.91 SP4 LGNCXW32.DLL
    Novell Client 4.91 Post-SP4 NWGINA.DLL 1
    IT-Beratung Rudolf Thilo
    Schweinfurter Str. 131
    97464 Niederwerrn
    t: +49 (0)9721/6464840
    f: +49 (0)9721/6464841
    m: +49(0)171/685 9 685

    Hello Craig,
    thanks for your answer.
    [VPN Client sometimes doesn't restore DNS settings after disconnecting]
    e.g. TID 10096552 is telling such a trouble, that should be fixed with
    BM VPN Client 3.8.10
    > > Any suggestions appreciated,
    > >
    > This one seems to be so related to the design of the VPN client that
    > you may need to open an incident to get it fixed, if that even would
    > help.
    >
    > There used to be a utility designed to clean up after the VPN client,
    > but I can't remember now what it was. I never tried it that I can
    > remember.
    Anybody else who knows about that tool?
    After doing some "teachment" to these VPN users the incidents of this
    trouble didn't show up as frequent as before. So I assume, that one
    reason might be this:
    Scenario
    VPN connect
    PCA connect to host in corporate LAN
    PCA full screen *SHOULD* be activated (ALT+ENTER)
    working, working, working
    shutdown PC in corporate LAN
    close VPN tunnel
    shutdown local home office PC.
    When it was missed to activate PCA fullscreen without noticing this,
    then the "remote" start button is not visible.
    So instead of shutting down the remote PC, the local PC is shut down.
    By that, the local shutdown is killing (not cleanly disconnecting)
    the VPN client. When this happened (and I 100% can reproduce this)
    after the next boot of the home office PC the VPN connect will *ALWAYS*
    fail. After another reboot the VPN connect will succeed again without
    any problems.
    Is this a known issue? (I cannot find that TID I found before telling
    missbehaviour when VPN connects are not disconnected clean. IIRC this
    was something fixed in a VPN client version /several/ subversions ago)
    Home Office PC = XPSP2+Hotfixes, VPN Client BM 3.8.16, nici from that
    one first, now taken from NWClient 4.91.4, no difference.
    Regards, Rudi.
    IT-Beratung Rudolf Thilo
    Schweinfurter Str. 131
    97464 Niederwerrn
    t: +49 (0)9721/6464840
    f: +49 (0)9721/6464841
    m: +49(0)171/685 9 685

  • Is it possible to restore from a backup after initial setup on my iPad air?

    is it possible to restore from a backup after initial setup on my iPad air?

    You don't even have to do to an erase all content and settings.
    Just connect the iPad to iTunes. Once it appears on the left, right click on it and select restore from backup. It's that easy.

Maybe you are looking for

  • TDS liability line items are not picking in u2013 J1INCHLN

    Hi Experts During depositing of TDS through J1INCHLN it is not picking all line items i.e. available in Ledger (FBL3N). We came to know after reconciliation even as all line items are available in table With_item as uncleared. We are facing this prob

  • Problem In Data Base Creation... Oracle 10g server in windows server 2008

    I have installed Oracle 10g server in windows server 2008 and the domain & active directory r created now i am trying to create the databse i am getting usual error (tns protocol adapter error ) in the 2% i have removed the domain and the active dire

  • Hi Res Pdf Problem

    I was trying to make a hi res pdf of a InDesign page to use as a piece of art in a Quark file. Every time I tried to make the pdf the way I usually do, which is thru our printers PPD and then distilling in Acrobt Distiller, the art would get res-ed d

  • How do I get Text Effects to Display Clearly In Illustrator?

    How do I get text effects to display clearly in Illustrator?

  • How to enable https or SSL for login page only?

    Hi, My application is runnnin in iPlanet web server 4.1 version. how to make my login page only secured (SSL)? previously we have done https enable for the whole application. but client specifically wants for login page only, not for the whole applic