LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 06-02-2014, 12:52 PM   #1
MarcLaf
LQ Newbie
 
Registered: Oct 2013
Posts: 10

Rep: Reputation: Disabled
Question Box keeps talking to old DNS but config has changed


I'm in the process of removing an old DNS server from our network and have been logging queries in order to update machines to point to our current DNS servers however I'm having the hardest time with two boxes. One is running Redhat and the other HP-Unix and both are doing the same thing.

After resolv.conf has been updated with new DNS settings (and no references to DNS in ifcfg file), these two boxes still query the old DNS server from time to time and I can't figure out what's causing this. Is there another place I could look for DNS configurations? I've restarted the network service on the Redhat box but that didn't correct the problem.

Where could I look next?
 
Old 06-02-2014, 02:40 PM   #2
nini09
Senior Member
 
Registered: Apr 2009
Posts: 1,880

Rep: Reputation: 162Reputation: 162
Each interface can have their own DNS configuration.
 
Old 06-02-2014, 02:44 PM   #3
MarcLaf
LQ Newbie
 
Registered: Oct 2013
Posts: 10

Original Poster
Rep: Reputation: Disabled
Oh I understand however these only have 1 interface each.
 
Old 06-03-2014, 02:12 PM   #4
nini09
Senior Member
 
Registered: Apr 2009
Posts: 1,880

Rep: Reputation: 162Reputation: 162
The existing connection could still use old DNS configuration. If TCP connection, tcpkill can clean up these connection.
 
Old 06-03-2014, 02:14 PM   #5
MarcLaf
LQ Newbie
 
Registered: Oct 2013
Posts: 10

Original Poster
Rep: Reputation: Disabled
Would these persist even if I've run service network restart?
 
Old 06-03-2014, 03:11 PM   #6
MikeDeltaBrown
Member
 
Registered: Apr 2013
Location: Arlington, WA
Distribution: Slackware
Posts: 96

Rep: Reputation: 10
Are you running nscd on those 2 boxes?
 
Old 06-03-2014, 03:16 PM   #7
MarcLaf
LQ Newbie
 
Registered: Oct 2013
Posts: 10

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by MikeDeltaBrown View Post
Are you running nscd on those 2 boxes?
Had to search what that was and it appears that it is running on at least one of the boxes.
 
Old 06-03-2014, 03:41 PM   #8
MikeDeltaBrown
Member
 
Registered: Apr 2013
Location: Arlington, WA
Distribution: Slackware
Posts: 96

Rep: Reputation: 10
Check /etc/nscd.conf for anything relevant and then do a `service ncsd restart`. Personally, I'd turn that service off completely (all run levels) and permanently.
 
Old 06-04-2014, 07:47 AM   #9
MarcLaf
LQ Newbie
 
Registered: Oct 2013
Posts: 10

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by MikeDeltaBrown View Post
Check /etc/nscd.conf for anything relevant and then do a `service ncsd restart`. Personally, I'd turn that service off completely (all run levels) and permanently.
Ran the command but it still talked to the old DC last night. Same time every night! I don't want to disable it because I'm not sure if the service is needed by the processes on the box (this is a very old box that's been passed down through generations of IT...) and I don't know enough about Linux to figure it out (hence me being here!)

Would restarting the service accomplish the same as 'nscd -i hosts' ? I found that command to clear the caches but haven't run it yet.
 
Old 06-04-2014, 10:21 AM   #10
MikeDeltaBrown
Member
 
Registered: Apr 2013
Location: Arlington, WA
Distribution: Slackware
Posts: 96

Rep: Reputation: 10
You can run that command without worry. Also, nscd provides no critical service of it's own. It is safe to turn it off, if you choose.

Another possibility is that you have a nameserver running and it is using the old DNS server as a forwarder. Try `netstat -lnvp` and see if anything is listening on port 53. bind (named) is common. If so, it's config file is usually found at /etc/named.conf. Look for a
Code:
forwarders { 10.2.3.4; };
line.
 
Old 06-04-2014, 11:01 AM   #11
MarcLaf
LQ Newbie
 
Registered: Oct 2013
Posts: 10

Original Poster
Rep: Reputation: Disabled
Thanks MikeDeltaBrown. I ran the command and will wait for tonight to see if it happens again.

Also, no nameserver running so I'm hoping it was just the cache.
 
Old 06-04-2014, 02:30 PM   #12
nini09
Senior Member
 
Registered: Apr 2009
Posts: 1,880

Rep: Reputation: 162Reputation: 162
Unless you have set a nonstandard "time to live" on your old DNS server, you must wait a considerable amount of time (typically 1-7 days) for remote users' cached DNS records to expire.
 
Old 06-06-2014, 07:50 AM   #13
MarcLaf
LQ Newbie
 
Registered: Oct 2013
Posts: 10

Original Poster
Rep: Reputation: Disabled
Ehh it's still talking to the box at the same time every day... I think I need to talk to the one guy who runs stuff on it to see what's going on at that time and maybe trace back from there.

Unless anyone else has any more ideas?
 
Old 06-06-2014, 11:20 AM   #14
MikeDeltaBrown
Member
 
Registered: Apr 2013
Location: Arlington, WA
Distribution: Slackware
Posts: 96

Rep: Reputation: 10
Since it happens at the same time you might want to check cron jobs: `crontab -l`
 
Old 06-06-2014, 11:30 AM   #15
GaWdLy
Member
 
Registered: Feb 2013
Location: San Jose, CA
Distribution: RHEL/CentOS/Fedora
Posts: 457

Rep: Reputation: Disabled
Quote:
Originally Posted by MarcLaf View Post
Ehh it's still talking to the box at the same time every day... I think I need to talk to the one guy who runs stuff on it to see what's going on at that time and maybe trace back from there.

Unless anyone else has any more ideas?
What version of Red Hat?
What is in /etc/resolv.conf (IOW, are the contents changing, or static?)?
Also, are you performing a 'service network restart' or using stop/start? Has this persisted after a reboot?

You may need to add 'PEERDNS=no' to your ifcfg files for it to stop picking up on random DNS servers-depending on your version of RH.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
grub config changed ubuntu abhijitbanke Linux - Desktop 8 03-07-2011 12:45 AM
Changed IP on Red Hat box and can't reconnect birkelbk Linux - Networking 20 08-04-2007 10:01 PM
changed ip for DNS server uji_amira Linux - Networking 3 06-08-2006 05:14 AM
I changed the config. of my mouse and now it won't work slimfadey Linux - Newbie 2 05-31-2005 03:55 PM
sendmail problems after i changed the name of my linux box motyl Linux - Networking 4 05-25-2003 01:31 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 02:48 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration