Re: Split Brain DNS Configuration

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Al Mulnick (amulnick_No_SPAM_at_ncDOTrr.com)
Date: 12/03/04


Date: Thu, 2 Dec 2004 20:44:23 -0500

Nothing out of the ordinary comes to mind. Split-brain (or, where I am,
multiple-personality DNS) is essentially two different domains as far as the
users think. As long as you manage them that way, then it's just ordinary
DNS and any best practices that go with that.

Al

"JMolay" <JMolay@discussions.microsoft.com> wrote in message
news:73CED9CE-89F3-4FAD-9E4E-F9581FBD0CE9@microsoft.com...
>I have been investigating the possibility of using a split brain DNS
> structure so that the routable domain name I have can be used both on the
> internal lan and the internet as well. As to the question of the DNS
> configuration it looks like I should set up two internal DNS servers that
> are
> integrated into active directory and then make them forwarders to the
> external DNS servers hosted by our ISP. In some of the literature it
> states
> that recursion should also be turned off on the internal DNS servers. Is
> this
> true? Are there any best practices that should also be incorporated into
> this
> design?



Relevant Pages

  • Re: Help - External DNS & SMTP relay
    ... Do you mean you want to host your domains' public DNS in-house? ... Only the external DNS server is configured with Internet root ... All internal DNS servers are configured only with the root ...
    (microsoft.public.security)
  • Re: DNS Forwarders to ISP Is it necessary?
    ... In light of the recent developments around cache poisoning and the roles ... forwarding played in their spread, I remain convinced that forwarding is a ... If you trust yourself enough to run a DNS server, ... > 2) Internal DNS servers do not need ...
    (microsoft.public.windows.server.dns)
  • Re: 2 Nics And DNS COnfig
    ... >> The second server is our proxy server.. ... >> Its messing up with My DNS Config. ... > forwarder for the other internal DNS servers ...
    (microsoft.public.win2000.dns)
  • Re: slow logon on windows 2000 domain
    ... the most secure and least trouble with the firewall ... is to have the internal DNS servers forward strictly ...
    (microsoft.public.win2000.group_policy)
  • Re: slow logon on windows 2000 domain
    ... the most secure and least trouble with the firewall ... is to have the internal DNS servers forward strictly ...
    (microsoft.public.win2000.dns)