DNS Search Suffix When DHCP Option 015 and GPO is used

asked 2020-08-25T18:49:14.607+00:00
RJames2010 11 Reputation points

We have an issue where the DNS Search Suffix seems to stop working. The machine is in Domain A which is trying to contact a resource in Domain B. Both domains are in different forests and connected via a two way trust.

This is a very intermittent problem but one thing I noticed is that in addition to setting the DNS Search Suffix List via GPO, option 015 with our primary domain (Domain A) is set as well. I'm wondering if this would cause any potential conflicts. You can only assign one DNS suffix via option 015 whereas we have 4 set via GPO.

If I check HKLM:\SOFTWARE\Policies\Microsoft\Windows NY\DNSClient\SearchList - the data in there matches the GPO.

If I check HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\SearchList - the data contains two comma-separated entries for Domain A.

I'm hoping someone can help as we've been struggling with this intermittent issue for some time.

Thanks in advance!

WB

Windows DHCP
Windows DHCP
Windows: A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.DHCP: Dynamic Host Configuration Protocol (DHCP). A communications protocol that lets network administrators manage centrally and automate the assignment of Internet Protocol (IP) addresses in an organization's network.
925 questions
{count} votes

1 answer

Sort by: Most helpful
  1. answered 2020-08-26T03:17:32.603+00:00
    Candy Luo 12,441 Reputation points

    Hi ,

    If you are trying to simply add one additional suffix, DHCP Option 015 will work for your DHCP clients. If you’re trying to add more than one additional suffix, GPO should be the better alternative. Generally, we don't enable them at the same time.

    Based on your situation, we recommend you only use GPO and remove the DNS Search Suffix in DHCP option 15. Then see if the issue is gone.

    ---Please Accept as answer if the reply is helpful---

    Best Regards,

    Candy

    No comments