Re: Migrating to new ISP




"Herb Martin" <news@xxxxxxxxxxxxxx> wrote in message news:OhB0mKmmIHA.5024@xxxxxxxxxxxxxxxxxxxxxxx

"Paulo Faustino" <paulofaustino@xxxxxxx> wrote in message news:AE2B307E-15C4-4E68-BDC2-3057A868313E@xxxxxxxxxxxxxxxx

"Herb Martin" <news@xxxxxxxxxxxxxx> wrote in message news:%23fSfRkgmIHA.5260@xxxxxxxxxxxxxxxxxxxxxxx

"Barry" <bazagee@xxxxxxxxxxx> wrote in message news:OTK9$1bmIHA.6064@xxxxxxxxxxxxxxxxxxxxxxx
Hi all,

I'm looking for advice on moving to a new ISP in a smooth manner with little or no down time to our public websites, MX etc.

Change the TTL to something small at LEAST one full TTL period ahead of the
change.

E.g., if you TTL is 1 day, then at least a day ahead, change it to 5 minutes or
some such.

My concern is how to do this with Win2k DNS services. I will have new IP's mapped to the Nics of our servers in advance and have contacted our Domain registrant to see if we can add multiple ip's to our nameserver records. I was hoping to be able to propagate downstream routers before the phyisical changeover. We have two public facing DNS server, Primary and Secondary zones.

Can this be done or what is the better way of approaching this?
TIA

TTL settings are the key and it doesn't matter if it is Windows DNS or some
(unknown) ISP/Registrar DNS server (e.g., BIND).

BTW, most companies should NOT be running their own public DNS but
should be using the REGSTRAR provided DNS Servers so you might wish
to consider this before performing this move and just use that instead.


Why you advice so strongly for most of the companies to do not run their own dns services?

Because the DNS for the PUBLIC resolution should be completely separate from
the private, their is a business rule (not really enforced) that public DNS must be
at least two machines (and a lot of these people don't even have one that is
separate), and because it is just something else that might be compromised or
use up cycles on a web server etc.

The Registrars already provide a fault tolerant, battery backed up, 24/7 supported
DNS service in almost all cases (for free), and a nice GUI-Web interface for you
to manage it yourself.

The exceptions are (possibly) those companies who have a large Internet presense,
with many Internet facing records and/or frequent changes, plus their own dedicated
staff who manage little or nothing else.

Also, the issue that many ISP will DISALLOW your public DNS server(s) from
doing recursion which effectively enforces the strong suggestion that the internal
and external DNS servers should be separate machines.

It is really a no brainer. Let the registrar do it (not the ISP either in almost all
cases.)



Good point, although i guess alot prefer to run the domains on their servers for speed and utmost control. And in some cases GUI-Web interface that is made available do not cover all your needs.

.



Relevant Pages

  • Re: Some DNS server names will not resolve using internal servers
    ... I have done all the nslookup commands. ... All of our external ISP DNS ... Is there a trace i could do on the DNS server to tell me what is happening? ...
    (microsoft.public.windows.server.dns)
  • Re: Thoughts on a large-scale DNS server...
    ... basically explaining our similar setup. ... > (One ISP is taking over another ISP) and would greatly appreciate any ... sounds like a very conservative setup, and for DNS that's good. ... We currently use a TTL of 12 hours. ...
    (freebsd-isp)
  • Re: Replication issues
    ... I wanted to say Zone Transfers not Zone Forwarding. ... AD-Integrated DNS does not do zone transfers between the ... your DNS server will bypass ...
    (microsoft.public.windows.server.active_directory)
  • Re: DNS NOTIMP response
    ... The following a good example of a "bad guy" attempting to UPDATE/NOTIFY a sub-domain into our domain and the MS DNS server rejected this attempt with a NOTIMP response. ... TTL 0 ...
    (microsoft.public.windows.server.dns)
  • Re: Servers hang on boot
    ... The last DC at that site (not a DNS server). ... EventID: 0x00000457 ... (Event String could not be retrieved) ...
    (microsoft.public.windows.server.networking)