Skip to main content
The Windows DNS scan module captures Windows DNS servers with their zones and records. It requires a connected gateway.

Captured data

Each DNS server becomes an asset of the type DNS with three groups: How the detail page of the type is structured is described in Directory and Network Services.

Setting up the job

The wizard follows the standard path Basics › Targets › Schedule › Summary—see Creating a Scan Job. The Targets step is what sets this module apart. Each row carries the columns Server Name and Credentials. Server Name takes one DNS server per row, as an address or hostname; the column does not accept an address range. Search DNS Servers fills in the servers from Active Directory instead: the dialog asks for the Domain and credentials and adds the DNS servers it finds as rows, including the servers in child domains. The Credentials column may stay empty. The scan then runs under the gateway’s service account, and that account needs the rights listed under Permissions. An entry in Credentials for all targets applies to every row without an assignment of its own.

Prerequisites

The scan connects to the DNS servers over WMI and queries the DNS data through PowerShell.

Ports and protocols

Permissions

  • On the DNS servers the account needs domain administrator rights.
  • Enter the account with the domain: DOMAIN\user or user@domain.local.

Network requirements

  • The firewall allows the ports above.
  • The DNS servers have:
    • .NET Framework 4.6.1 or later,
    • PowerShell 3 or later, allowed to run,
    • the PowerShell module for DNS,
    • access to C:\Windows\Temp and to the IPC$ share.
Scan DNS servers the gateway cannot reach directly on the server with the Discovery-DNS.exe scan script—see Scanning by Script. After it is created, the job appears among the jobs; how you watch and adjust it is in Managing Jobs. You capture the DHCP servers of the same domain with Windows DHCP.