Posted: 6/18/2025 1:02:59 PM EDT
|
I'm not talking regular users but actual tech people. Been in the industry for over 20 years and can count on one hand the people I've worked with who actually understand DNS, how it works, and how to effectively configure and manage it. Don't get me started on the complete lack of understanding for how DNS misconfiguration can affect network performance and reliability. No point in even mentioning troubleshooting DNS records via nslookup, dig, powershell, etc. because these folks certainly have no idea how to do that either - e.g. "what is an MX record" or a complete lack of awareness that anything beyond "host=IP" exists within the DNS hierarchy. Once sent a raw zone file to another sysadmin I was working with and he had zero idea what it was. I'm currently working with a large company that has many distinct Active Directory sites. Every single site that I've gone through has had fucked up AD and DNS issues galore. Stuff like orphaned DCs still being referenced by clients, long gone DCs still present in the AD DNS records, clients configured to call external DNS servers before AD DCs, lack of any kind of defined forwarder hierarchy, etc. If it wasn't affecting user logins it was definitely affecting network performance, with accesses to Windows SMB servers often being painfully slow just because of misconfigured DNS causing all sorts of timeouts and resolution failures. The sites that I've gone through and cleaned up all magically began running like butter. The guys previously responsible for managing these sites didn't know any more than "if ping google.com works than DNS is working" and just accept things like client PCs being unable to talk to the AD domain as normal (because they decided to try talking to an orphaned DC), telling employees to "just reboot" until it works has been accepted for years. Just stopped in the middle of writing up a suggested AD DNS configuration standardization document to bitch about this because I'm 99% sure nobody will read the document or understand it because none of them understand DNS. This is why "it's always DNS" is a thing - seems like most people I've worked with genuinely don't. It's not a god damn mystery, it's actually really simple, but seems like nobody wants to take the time to actually learn it. |
Your rant doesn't even touch on TCP over DNS. ![]() I've used iodine to tunnel TCP packets over DNS to get internet service on airplanes and whatnot. |
|
Originally Posted By giantpune: Your rant doesn't even touch on TCP over DNS. ![]() I've used iodine to tunnel TCP packets over DNS to get internet service on airplanes and whatnot. itsbeautiful.jpg |
|
People not understanding DNS has been one of the banes of my existence (professionally) for as long as I can remember, and I've been in IT since the 90's. If you want insanity-levels of spite, let's talk BGP *and those who say they know it*. |
|
Originally Posted By giantpune: Your rant doesn't even touch on TCP over DNS. ![]() I've used iodine to tunnel TCP packets over DNS to get internet service on airplanes and whatnot. Oooh, that could be a fun toy to play with
|
Abolish the FBI, ATF, and the NSA.
Any citizen accused of a crime is presumed innocent until bankrupted beyond all reasonable doubt.
Boycott Colorado - don't reward communists in Denver with your business.
Any citizen accused of a crime is presumed innocent until bankrupted beyond all reasonable doubt.
Boycott Colorado - don't reward communists in Denver with your business.
|
I think a good part of it is that AD, as you know, is utterly reliant on DNS.. and the MS DNS and DHCP servers are trash. Replacing them with other solutions help tremendously. I once had an hour-long conversation with another 'admin' about why aging/scavenging mattered when users traversed the wired and wireless VLANs. It was like trying to teach a dog to square dance. |
God's children are not for sale.
| Worked with an “admin” once who went to delete a host record and mistakenly deleted the entire zone. |
"The trouble with our liberal friends is not that they're ignorant: It's just that they know so much that isn't so." - Ronald Reagan
NRA Life Member
Second Amendment Foundation member
NRA Life Member
Second Amendment Foundation member
|
Originally Posted By MMcCall: I think a good part of it is that AD, as you know, is utterly reliant on DNS.. and the MS DNS and DHCP servers are trash. Replacing them with other solutions help tremendously. I once had an hour-long conversation with another 'admin' about why aging/scavenging mattered when users traversed the wired and wireless VLANs. It was like trying to teach a dog to square dance. This right here. MS DNS is such trash and having admins who have no other experience than with MS Server XXXX made my life miserable for over a year. After moving network infrastructure to Linux and BIND - "Wow! everything is so much faster! How did you do that? |
That's no way for guys like us to go out. We should go out in the midst of a desperate battle, doing great deeds. - COL Rick Rescorla
|
Originally Posted By 2ANut: Most IT guys, in my experience, don't really know much of anything about IT. But they paid a lot to pass exams for certifications that bamboozle clueless managers into hiring them. And so much this. |
That's no way for guys like us to go out. We should go out in the midst of a desperate battle, doing great deeds. - COL Rick Rescorla
|
Originally Posted By HenryKnoxFineBooks: This right here. MS DNS is such trash and having admins who have no other experience than with MS Server XXXX made my life miserable for over a year. After moving network infrastructure to Linux and BIND - "Wow! everything is so much faster! How did you do that? Moving DNS/DHCP and RADIUS auth to our core network infra was like a ray of light directly down from the heavens. |
God's children are not for sale.
|
Originally Posted By MMcCall: I think a good part of it is that AD, as you know, is utterly reliant on DNS.. and the MS DNS and DHCP servers are trash. Replacing them with other solutions help tremendously. I once had an hour-long conversation with another 'admin' about why aging/scavenging mattered when users traversed the wired and wireless VLANs. It was like trying to teach a dog to square dance. I proposed a whole list of DNS cleanup and optimization objectives in a meeting yesterday - we have a number of sites with fucked up DNS causing all kinds of network delays and performance issues, which I very clearly outlined in the proposal - and both the director and one of the seniors said "OK but what does this get us?" I had to explain what a DNS forwarder is and why it's different from root lookups.
|
|
Originally Posted By bowhuntr09: Worked with an “admin” once who went to delete a host record and mistakenly deleted the entire zone. UUNet had a Kerberized zone editing utility (did RCS stuff, would bump zone serial etc.) that used the EDITOR environment variable, defaulting to 'vi', with predictable results. I believe it eventually performed zone linting and made the human ACK the diff before allowing check in. |
|
Yeah so for maximum use of our AD DNS I store our break glass account credentials in Active Directory DNS as base64-encoded, GPG-encrypted TXT records split across `bgkey0.corp.local`, `bgkey1.corp.local`, etc., because nothing says resilient infrastructure like hiding your emergency root access behind a `dig` loop. So if we ever get locked out, the recovery procedure is literally "run dig and pray the domain controller isn't also on fire," which, let's be honest, is still more reliable and secure than our passwords.txt on ADFS. |
|
Originally Posted By bowhuntr09: Worked with an "admin" once who went to delete a host record and mistakenly deleted the entire zone. Oh, I had my share of "admins" who had clusterfuck the system. I'm known as IT Janitor cuz I always fix things back to action. |
What you do today will affect your outcomes tomorrow.
| I'll up you one: how many people in IT have absolutely no fucking clue how certificate services work. I've kept quiet at my current employer that I know anything about certs because I don't want to inherit another CA. |
F.D.N.Y. Box 55-8087
In Memory of Brothers in Battle
In Memory of Brothers in Battle

