NSLookup still showing IP of demoted Domain Controller
So had an interesting issue today where a Domain Controller (DC) was demoted yet the IP of the demoted DC was still showing up when running nslookup internaldomain.local
Demoted DC:Â MWDC04 / IP: 10.14.111.111
I had done the metadata cleanup and tried many suggestions when googling the subject. To my surprise none of the solutions I found worked.
I had removed the IP address from the Primary DNS Server and saw entries for:
(same as parent folder) Host(A)Â 10.14.111.111
(same as parent folder) NameServer (NS)Â 10.14.111.111
I also looked under internaldomain.local > _msdcs and deleted entries from there.
After clearing the cache and waiting for replication, did a nslookup again and the IP was still there.
Well, there are some good and bad things about Microsoft DNS.
The BAD:
You cannot search DNS values in DNS Management. You are limited to searching just the names.
THE GOOD:
All DNS entries are stored in a flat file on the DNS Server “C:\WINDOWS\system32\dns\internaldomain.local.dns” (The default location). JACKPOT!
I opened it up in Notepad++, did a search for IP and DNS name of the demoted server(MWDC04-10.14.111.111) and started deleting matched entries. I was so surprised to find entries that were deeply buried under “domaindnszones” & “forestdnszones” and a few other subzones.
Cleared the cache again and waited for replication. Once replication completed I tried nslookup internaldomain.local and this time it didn’t list the demoted DC anymore.
I hope this saves others time, because finding a record in DNS might be like searching for a needle in a haystack!
Author
Related Posts
Get all the domains controllers in the AD forest along with their current FSMO roles
In a large enterprise an admin would need to keep track of all the domains in a AD forest, the domain names,...
Read out all
Force synchronization for DFSR-replicated SYSVOL
One of my clients had a problem with processing GPO on client computers. Different computers applied different settings from the same GPO...
Get Inactive Users Report for the past 60 days in a multi domain environment
I had a request recently to provide an inactive user report for the past 60 days. Basically, find out which accounts have...
Get Primary, Secondary, Tertiary DNS values and more from Multiple Servers
Came across a unique request to get primary, secondary, and tertiary DNS values for multiple computers/servers across the domain. I started writing...
Fix Active Directory broken security inheritance problem
Ran into a situation at a client location where in Active Directory, the security permissions applied to an OU were not getting...
How to Fix: Attribute userAccountControl of DC is: 0x82020
When running a DCDiag at a customer site today I had the following error occur: [su_box title=”” box_color=”#f3f1cb” title_color=”#000000″ radius=”6″]Warning: Attribute userAccountControl...