Laptops changing their location to often, DNS manager cannot keep up?

Tonito Dux 976 Reputation points
2021-12-03T11:36:09.76+00:00

Hi,

wanted to ask your experiences as admins and this situation with homeoffice. So we have users working in homeoffce with their laptops, and I regularly see that the same IP address is given to two machines. This happens only in the VPN scope. We are now working on a solution with an external company, but so far not luck.
I personally tried the following:

  1. Shorten the aging for forward lookup zone to 1 day, both in no-referesh and refresh interval.
  2. In VPN reverse lookup zone we have shorten the scavange interval to 4/4.
  3. On the new VPN DHCP scope, lease duration is set to 4 hours, DHCP name protection was activated but only 1 day in effect so it could be that it needs time?
  4. DNS dynamic updates are set to "Dynamically update DNS recoreds only if requested by the DHCP clients
  5. DNY dynamic update registration credentials were all over the place, from our 4 DCs some had the credential some did not - i managed to correct this.

Dynamic updates are set to secure only. We use Cisco Firewall, and we did not have, until yesterday this VPN scope in Windows DHCP Server, don't ask me why. Now we do have it in our DHCP. Cisco AnyConnect is being used as a VPN client.

Is there anything from the DHCP or I am leaning towards DNS setting that can be improved so we don't have this double entries. They are not for all currently connected clients, just some.

Cheers

Windows for business | Windows Client for IT Pros | Networking | Network connectivity and file sharing
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 39,931 Reputation points
    2022-01-05T09:47:32.47+00:00

    Hi there,

    This might be due to the VPN settings that you have configured.

    There are two options for VPN’s:
    -Bridged
    -Routed
    If you have bridged the two networks you will get an IP conflict and poor communication between the sites if two computers have the same IP address.

    If you have set up a routed VPN you will have to set up some kind of NAT/PAT to be able to communicate between the sites. It will be better to renumber your network.


    --If the reply is helpful, please Upvote and Accept it as an answer--

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.