<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dns check produces 2 different experiences, but same DNS servers in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/dns-check-produces-2-different-experiences-but-same-DNS-servers/m-p/168378#M38596</link>
    <description>&lt;P&gt;How does the Serviceprinciplenames of the SVMs look like ? It is hard to understand if these are just dns zones and where the SVM belongs too - what is the Kerberos Realm etc.&amp;nbsp;You could define 2 Broadcast domains with their domain name - so the lif there would only "handle" one domain if there are 2 KRB Realms too.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jul 2021 04:49:48 GMT</pubDate>
    <dc:creator>mario_grunert</dc:creator>
    <dc:date>2021-07-13T04:49:48Z</dc:date>
    <item>
      <title>dns check produces 2 different experiences, but same DNS servers</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/dns-check-produces-2-different-experiences-but-same-DNS-servers/m-p/168374#M38593</link>
      <description>&lt;P&gt;IHAC running ONTAP 9.6p3.&amp;nbsp; They're complaining of CIFS performance, and managing the SVM (adding domain users into local groups, etc) timeout, and users have problems accessing shares.&amp;nbsp; I verified that the time is in sync with the DCs, and the SVM can ping the domain name.&lt;BR /&gt;&lt;BR /&gt;When I performed a dns check, I have 2 different experiences.&amp;nbsp; The DNS server is also a domain controller -&amp;nbsp;192.168.1x.xx5&lt;BR /&gt;That DC hosts 2 different domains:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;bad.domain.com&lt;/STRONG&gt; (this is the customer's AD domain)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;good.domain.com&lt;/STRONG&gt; (this looks like an administrative domain that was created in AD)&lt;BR /&gt;&lt;BR /&gt;On the prod SVM (as well as a test SVM), I configured DNS:&lt;BR /&gt;&lt;EM&gt;::&amp;gt; vserver services dns create -vserver svm1 -domains &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;bad.domain.com&lt;/FONT&gt;&lt;/STRONG&gt; -name-servers 192.168.1x.xx5, 100.100.x.xx1&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;When I check the domain, the test sometimes times out, or responds VERY slowly:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ntap01::*&amp;gt; vserver services dns check -vserver svm1 -instance&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Vserver: svm1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Name Server: 192.168.1x.xx5&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Name Server Status: up&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Status Details: &lt;FONT color="#FF0000"&gt;Response time (msec): &lt;STRONG&gt;3623&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Vserver: svm1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Name Server: 100.100.x.xx1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Name Server Status: up&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Status Details: &lt;FONT color="#FF0000"&gt;Response time (msec): &lt;STRONG&gt;2743&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;2 entries were displayed.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when I change the domain (not the CIFS domain, but the domain that the SVM has configured for DNS settings), the response adequate:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;::&amp;gt; vserver services dns modify -vserver svm1 -domains&lt;STRONG&gt; &lt;FONT color="#339966"&gt;good.domain.com&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ntap01::*&amp;gt; vserver services dns check -vserver svm1 -instance&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Vserver: svm1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Name Server: 192.168.1x.xx5&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Name Server Status: up&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Status Details:&lt;STRONG&gt; &lt;FONT color="#339966"&gt;Response time (msec): 15&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Vserver: svm1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Name Server: 100.100.x.xx1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Name Server Status: up&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Status Details: &lt;STRONG&gt;&lt;FONT color="#339966"&gt;Response time (msec): 13&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;2 entries were displayed.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both domains (&lt;FONT color="#339966"&gt;&lt;STRONG&gt;good.domain.com&lt;/STRONG&gt;&lt;/FONT&gt; and&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt; bad.domain.com&lt;/STRONG&gt;&lt;/FONT&gt;) are zones on the same DNS server.&amp;nbsp; I can reproduce this problem with the prod SVM that is having CIFS problems.&amp;nbsp; If I create a new nfs-only SVM, I get the same issues even though the test SVM is not part of an AD domin.&lt;BR /&gt;&lt;BR /&gt;The reason I'm putting stock into this test is because&lt;STRONG&gt;&lt;EM&gt; vserver cifs check&lt;/EM&gt;&lt;/STRONG&gt; doesn't bode well (&lt;EM&gt;the below output is a re-enactment, so some of the responses have been manually modified to simulate the actual response&lt;/EM&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;::&amp;gt; vserver cifs check -vserver svm1 -instance&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Vserver: svm1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Node: ntap01-01&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;CIFS NetBIOS Name: SVM1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;CIFS Server Status: Running&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;CIFS Server Site:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Domain Controller Name: &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;bad.domain.com&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Domain Controller IP Addr: &lt;FONT color="#FF0000"&gt;192.168.1x.xx5&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Connectivity Status: &lt;STRONG&gt;down&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&amp;nbsp; My initial thought was bad SRV records or something, but the rest of the computer accounts are OK.&amp;nbsp; There are no other NetApp instances on their AD domain.&lt;BR /&gt;&lt;BR /&gt;Thanks for the help&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:19:27 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/dns-check-produces-2-different-experiences-but-same-DNS-servers/m-p/168374#M38593</guid>
      <dc:creator>borkp</dc:creator>
      <dc:date>2025-06-04T10:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: dns check produces 2 different experiences, but same DNS servers</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/dns-check-produces-2-different-experiences-but-same-DNS-servers/m-p/168378#M38596</link>
      <description>&lt;P&gt;How does the Serviceprinciplenames of the SVMs look like ? It is hard to understand if these are just dns zones and where the SVM belongs too - what is the Kerberos Realm etc.&amp;nbsp;You could define 2 Broadcast domains with their domain name - so the lif there would only "handle" one domain if there are 2 KRB Realms too.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 04:49:48 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/dns-check-produces-2-different-experiences-but-same-DNS-servers/m-p/168378#M38596</guid>
      <dc:creator>mario_grunert</dc:creator>
      <dc:date>2021-07-13T04:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: dns check produces 2 different experiences, but same DNS servers</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/dns-check-produces-2-different-experiences-but-same-DNS-servers/m-p/168383#M38601</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/8214"&gt;@mario_grunert&lt;/a&gt;&amp;nbsp;Thanks for the reply. &amp;nbsp;Kerberos is not configured. &amp;nbsp;The SPN of the CIFS SVM account should be default, but the nfs-only SVM wouldn’t have one as it is not configured for Kerberos or AD.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;thr only difference is the DNS domain configured via vserver services dns create/modify.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;It’s so odd as both zones are hosted on the same DNS/AD server, and that server is on the same subnet as the SVM’s LIF.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;To rule out the actual DNS server being a problem, I modified the list of configured DNS servers on the SVM to just one, and reproduced the results. I did this with 3 different DNS servers.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 09:53:54 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/dns-check-produces-2-different-experiences-but-same-DNS-servers/m-p/168383#M38601</guid>
      <dc:creator>borkp</dc:creator>
      <dc:date>2021-07-13T09:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: dns check produces 2 different experiences, but same DNS servers</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/dns-check-produces-2-different-experiences-but-same-DNS-servers/m-p/168392#M38605</link>
      <description>&lt;P&gt;Probably worth getting a packet trace during each ping to see what is going on behind the scenes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DNS check is a very basic command that just does standard A/AAAA queries, so this is likely either a network issue or you have duplicate records out there. A trace will tell you more.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 14:07:42 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/dns-check-produces-2-different-experiences-but-same-DNS-servers/m-p/168392#M38605</guid>
      <dc:creator>parisi</dc:creator>
      <dc:date>2021-07-13T14:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: dns check produces 2 different experiences, but same DNS servers</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/dns-check-produces-2-different-experiences-but-same-DNS-servers/m-p/168617#M38670</link>
      <description>&lt;P&gt;The SVM will need to DNS to connect to the dc. After establishing the connection, it stays open for a long time.&lt;/P&gt;
&lt;P&gt;You can even try to add a preferred dc to the SVM to minimize DNS interactions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will recommend checking the network or the DC connections.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_can_I_check_in_ONTAP_if_an_external_service_such_as_netlogon%2C_ldap-ad%2C_lsa%2C_ldap-nis-namemap%2C_or_nis_is_responding_slowly" target="_self"&gt;&lt;SPAN&gt;How can I check in ONTAP if an external service such as netlogon, ldap-ad, lsa, ldap-nis-namemap, or nis is responding slowly?&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jul 2021 06:28:57 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/dns-check-produces-2-different-experiences-but-same-DNS-servers/m-p/168617#M38670</guid>
      <dc:creator>Mjizzini</dc:creator>
      <dc:date>2021-07-21T06:28:57Z</dc:date>
    </item>
  </channel>
</rss>

