I assume we're missing a bit of info here, particularly the root paths set for each zone. Do all the DNS IP addresses correspond to AD? Are all customers/zones using the same AD?
This sounds very much like a problem with AD, actually, where one or more DCs are not responding or cannot be reached via certain IP addresses.
How many network pools does your Isilon cluster have?
Peter's hit the nail on the head, but since you already use Access Zones, have a chat with your account team about DNS features that may be coming in OneFS.Next in the very near future that may directly alleviate your issues. Of course anything concerning future product launches is under NDA so it cannot be discussed in this open community forum.
Peter_Sero
4 Operator
•
1.2K Posts
0
December 11th, 2015 22:00
The important point carlilek has implied is that
it can only work if *any* DNS server can resolve *any* AD!
This is because OneFS (and most UNIX-like OSes)
takes the configured list of DNS servers as a redundant set
rather than partitioned services which complement each other.
All these queries should succeed with correct results:
$ host AD1 dns1
$ host AD2 dns1
$ host AD1 dns2
$ host AD2 dns2
[etc. for all combinations also including AD3 or dns3]
Cheers
-- Peter
Peter_Sero
4 Operator
•
1.2K Posts
0
December 8th, 2015 22:00
Does KB194525 apply? It deals with DNS caching in OneFS which can be turned off or restarted to help with certain problems.
-- Peter
carlilek
2 Intern
•
205 Posts
0
December 9th, 2015 03:00
I assume we're missing a bit of info here, particularly the root paths set for each zone. Do all the DNS IP addresses correspond to AD? Are all customers/zones using the same AD?
This sounds very much like a problem with AD, actually, where one or more DCs are not responding or cannot be reached via certain IP addresses.
How many network pools does your Isilon cluster have?
chughh27
39 Posts
0
December 10th, 2015 01:00
Hello,
root path for all zone is /ifs.
we have 9 pools
3 group using 3 different AD and 3 different zones
Strange behaviour when AD 2 is offline and i do
d-g -x for dns1 & dns 2 i get response from AD 1 which is online.
AD is coming online after shuffling ip address of AD 2 to be first and then isi auth refresh
chughh27
39 Posts
0
December 10th, 2015 01:00
Hello Peter,
I have disabled dns cache but still issue persist.
crklosterman
450 Posts
0
December 14th, 2015 07:00
Peter's hit the nail on the head, but since you already use Access Zones, have a chat with your account team about DNS features that may be coming in OneFS.Next in the very near future that may directly alleviate your issues. Of course anything concerning future product launches is under NDA so it cannot be discussed in this open community forum.
Have a good day,
~Chris Klosterman
Advisory Solution Architect
EMC Emerging Technologies Enablement Team
chris.klosterman@emc.com
twitter: @croaking