Re: sub-childdomain windows2003 Ad forest

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Ace Fekay [MVP] (PleaseSubstituteMyActualFirstName&LastNameHere_at_hotmail.com)
Date: 09/03/04


Date: Fri, 3 Sep 2004 15:01:56 -0400

In news:%23dLUrDdkEHA.3896@TK2MSFTNGP15.phx.gbl,
eric romero <e.romero@cgnet.com> made a post then I commented below
> Hi All
>
> I have a Windows2003 AD several childomains one of the childomains
> (b.c.com)admins plans to add a subchildomain(a.b.c.com)
>
> My question does the DNS delegation, subnet, site-link must be done
> at the root or at the childomain (b.c.com) ? any documents describing
> this process?
>
> thx

Hi Eric,

You would want to delegate it from the child to the next child, since at the
child is where the full zone is. From the root, if you already have a
delegation, you can't delegate from a delegated child zone anyway. But don't
forget to configure a forwarder from child2 to child1, which should have a
forwarder to the root.

How to delegate a child zone (doesn't talk about sub child zones, however):
http://support.microsoft.com/default.aspx?scid=kb;en-us;255248

Since you have Windows 2003, you can also use stub zones (which is
recommended over delegation). Matter of fact, if you have a Win2k, and you
have a delegation to a child, during an upgrade it changes it to a stub
zone. The advantages is that if any of the nameservers change their IP or
names at the child zone, that change is transferred automatically to the
stub at the parent zone. You would still use a forwarder back to the
immediate parent. Keep in mind, you can use conditional forwarding as well
to go from child2 directly to the root domain DNS. I think it would be to
your advantage to use stubs in your scenario.

Understanding stub zones:
http://www.microsoft.com/resources/documentation/WindowsServ/2003/standard/proddocs/en-us/Default.asp?url=/resources/documentation/WindowsServ/2003/standard/proddocs/en-us/sag_DNS_und_StubZones.asp
or easier:
http://tinyurl.com/3bhfv

811118 - Support WebCast Microsoft Windows Server 2003 DNS Stub Zones and
Conditional Forwarding:
http://support.microsoft.com/default.aspx?scid=kb;en-us;811118

Keep in mind, there was a hotfix out that addresses an issue that came up
about stubs to childs of a child zone. Read this about that:
834378 - Windows Server 2003 DNS name resolution may fail when stub zones
are configured:
http://support.microsoft.com/default.aspx?scid=kb;en-us;834378

As for your previous thread about the missing ForestDnsZone and
DomainDnsZone, I had offered to take a look at it. Did you still want any
help with that?

-- 
Regards,
Ace
Please direct all replies ONLY to the Microsoft public newsgroups
so all can benefit.
This posting is provided "AS-IS" with no warranties or guarantees
and confers no rights.
Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft Windows MVP - Windows Server - Directory Services
Security Is Like An Onion, It Has Layers
HAM AND EGGS: A day's work for a chicken;
A lifetime commitment for a pig.
-- 
=================================


Relevant Pages

  • Re: sub-childdomain windows2003 Ad forest
    ... delegation, you can't delegate from a delegated child zone anyway. ... How to delegate a child zone ... you can also use stub zones (which is ...
    (microsoft.public.win2000.general)
  • Re: sub-childdomain windows2003 Ad forest
    ... delegation, you can't delegate from a delegated child zone anyway. ... How to delegate a child zone ... you can also use stub zones (which is ...
    (microsoft.public.windows.server.active_directory)
  • Re: sub-childdomain windows2003 Ad forest
    ... delegation, you can't delegate from a delegated child zone anyway. ... How to delegate a child zone ... you can also use stub zones (which is ...
    (microsoft.public.win2000.active_directory)
  • Re: Remove Delegation / Transfer Records
    ... NS record for the DNS you are removing the zone from. ... And wouldn't the delegation NS point to ... childdomain4 ...
    (microsoft.public.windows.server.dns)
  • Re: Child AD domain zone - delegate from root DC or not?
    ... You have no branch DNS servers? ... for that zone but it is usually hard to find a better place ... act of delegation where you are working on the parent ... GENERAL forwarding is ...
    (microsoft.public.windows.server.dns)