[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Refresh Interval of the DC Locator DNS Records

ID: oval:org.secpod.oval:def:19032Date: (C)2014-05-29   (M)2023-07-04
Class: COMPLIANCEFamily: windows




The Refresh Interval of the DC Locator DNS Records machine setting should be configured correctly. Specifies the Refresh Interval of the domain controller (DC) Locator DNS resource records for DCs to which this setting is applied. These DNS records are dynamically registered by the Net Logon service and are used by the Locator algorithm to locate the DC. This setting may be applied only to DCs using dynamic update. DCs configured to perform dynamic registration of the DC Locator DNS resource records periodically reregister their records with DNS servers, even if their records data has not changed. If authoritative DNS servers are configured to perform scavenging of the stale records, this reregistration is required to instruct the DNS servers configured to automatically remove (scavenge) stale records that these records are current and should be preserved in the database. Warning: If the DNS resource records are registered in zones with scavenging enabled, the value of this setting should never be longer than the Refresh Interval configured for these zones. Setting the Refresh Interval of the DC Locator DNS records to longer than the Refresh Interval of the DNS zones may result in the undesired deletion of DNS resource records. To specify the Refresh Interval of the DC records, click Enabled, and then enter a value larger than 1800. This value specifies the Refresh Interval of the DC records in seconds (for example, the value 3600 is 60 minutes). If this setting is not configured, it is not applied to any DCs, and DCs use their local configuration. Fix: (1) GPO: Computer Configuration\Administrative Templates\System\Net Logon\DC Locator DNS Records\Refresh Interval of the DC Locator DNS Records (2) KEY: HKLM\Software\Policies\Microsoft\Netlogon\Parameters\DnsRefreshInterval

Platform:
Microsoft Windows Server 2008 R2
Reference:
CCE-11053-6
CPE    1
cpe:/o:microsoft:windows_server_2008:r2
CCE    1
CCE-11053-6
XCCDF    1
xccdf_org.secpod_benchmark_general_Windows_Server_2008_R2

© SecPod Technologies