Re: DNS in 2003 Domain



In news:bassaddict.1ss1t3@xxxxxxxxxxxxxxxxxxxxxx,
bassaddict <bassaddict.1ss1t3@xxxxxxxxxxxxxxxxxxxxxx> stated, which I then
commented on below:
> Hey
>
> Thanks to both of you for your replies. Let me just clarify the
> existing set up. Our Forest Root is 2003, and we have a mixture of Win
> 2000 and Win 2003 DCs and DNS Servers. All of our 15 branch offices
> have 2 DNS servers / DC's, one being Win 2000 and one being Win 2003.
> Each server points to itself for lookups and then to the Forest Root
> which is located at head office. Is this good practice?
>
> On our 2003 DNS servers, the option to create a default application
> directory partition is available (but not on the 2000 DNS boxes). Am i
> correct in thinking to set this up though, all DNS servers should be
> running on 2003? In my proposal, I am recommending upgrading all 2000
> to 2003 DNS and using Application Directory Partition to improve
> replication, but does the Forest Functional level need to be raised to
> 2003?
>
> Underneath our ForwardLookupZone, we have our domain (lets call it
> domain.com) Underneath here, we have the default _msdcs, _sites, _tcp,
> _udp, DomainDnsZones and ForestDnsZones. The DNS is active directory
> integrated and uses forwarders to the forest root without recursion
> for the domain, and then the Forest Root forwards WITH recursion to
> the ISP DNS servers.

If you have a child domain, and are delegating the child namespace to the
child domain's DNS servers, then yes, you would forward from the child
domain's DNS to the parent domain's DNS.

OTHERWISE, if you only have ONE domain, DO NOT FORWARD TO EACH OTHER or to
any others in the same domain. This will cause a forwarding loop and you
will be bound with issues. Configuring as such is only for a delegation or
stub scenario with child domains. If you have only one domain, as indicated
in your more recent post, forward from each INDIVIDUAL DNS to the ISP. Allow
recursion.

>
> From one of our Win 2000 boxes, the same subdomains as above exist and
> all replicate to each other.

The folders underneath with the underscores in them (e.g. _msdcs, _tcp,
_upd, and _sites), as you call "subdomains" are actually the SRV records,
and not necessarily subdomains. These are the service location records that
a DC registers into DNS and is used to locate domain controller services.

So I'm not entirely sure what you mean by they "...all replicate with each
other". Zone data in any AD Integrated zone types, since they are stored in
the actual physical AD database, will replicate to other DC/DNS servers
along with the default AD replication cycle, since they are part of the AD
database. If the understanding is skewed meaning you thought they replicate
"with each other", then in a way, they do, but all the data is replicated
based on AD's replication process just because they are part of the
database.

>
> So are you saying the Application Directory replication is not
> available on 2000 DOMAINS or DCs/DNS servers? Because the option is
> there to create one from one of our 2003 DNS servers.

The Application Partitions are not available for use by a Windows 2000
DC/DNS, albeit the partitions exist on such a machine, but it;s just that
you can't take advantage of the feature. The ability to use that feature is
only available by using Windows 2003 DC/DNS servers.

>
> Sorry if I sound like a beginner with DNS.... its because I am ! But I
> appreciate how helpful you are.
>
> Cheers

No problem. The only way you'll find out is if you ask!

Ace



.



Relevant Pages

  • Re: Incremental DNS zone transfers
    ... see attached excerpt from Microsoft White Paper "Windows 2000 DNS" ... Active Directory Storage and Replication Integration ... no need to support a separate replication topology for DNS servers. ...
    (microsoft.public.win2000.general)
  • Re: Remove a non-existent DC
    ... dcdiag returned replication attempt errors. ... The DSA operation is unable to proceed because of a DNS ... The failure occurred at 2007-10-12 07:54.54. ... is not registered on one or more DNS servers. ...
    (microsoft.public.win2000.active_directory)
  • Re: Cannot change from Domain DNS replication to Forest DNS replic
    ... Have checked all other child domain DNS servers and there are no stub zones ... I have also removed the DNS role from the DC, ... forced replication, ... the zone to a new location in Active Diretory. ...
    (microsoft.public.windows.server.dns)
  • removing a dead DC
    ... dcdiag returned replication attempt errors. ... The DSA operation is unable to proceed because of a DNS ... The failure occurred at 2007-10-12 07:54.54. ... is not registered on one or more DNS servers. ...
    (microsoft.public.windows.server.dns)
  • Re: Active Directory Integrated
    ... >> A different DNS solution is used for the forest root domain in our forest. ... This can be designed to be equal (eg IPSec beteween DNS servers). ... Windows Server 2003 is my strong recommendation for DNS for the reason ...
    (microsoft.public.windows.server.dns)

Loading