Re: Active Directory Naming Convention

Tech-Archive recommends: Speed Up your PC by fixing your registry

From: Ryan Hanisco (rhanisco_at_flagshipis.com)
Date: 03/15/05


Date: Mon, 14 Mar 2005 19:50:44 -0600

In a case with internal and external access, you usually have either two DNS
servers or one server with two domains. One would be for external
resolution and one for internal. This also helps you avoid hairpin routing
issues into your DMZ by internal customers.

I would caution you though, it is usually a bad idea to have a DC in an DMZ.
I would suggest using IAS (RADIUS) or LDAP pass-through to your DC
internally. If you need a DC in your DMZ, be EXTREMELY careful and lock the
ports down on there server and on your firewall/ DMZ router.

-- 
Ryan Hanisco
MCSE, MCDBA
FlagShip Integration Services
"rrwall" <rrwall@discussions.microsoft.com> wrote in message 
news:A4ADBC0E-DC8F-49D1-9F1B-289A9127C765@microsoft.com...
>I am in the process of upgrading my network from NT4 to win2k3 AD.  I have 
>a
> server that is responsible for DNS\authoritative in my DMZ.  I have approx 
> 10
> records for access to web sites that I am hosting as well.
>
> The DNS server is running winnt4.
>
> I would like to use mydomain.loc rather than mydomain.net for simplicity 
> and
> I understand that resolving DNS issues is easier, as well.
>
> My question is, can I do this and set my forwarders up to point to this 
> name
> server and not have to worry about touching the existing DNS server in my 
> DMZ?
>
> 


Relevant Pages

  • Issues migrating SBS 2003 domain to Server 2008 Standard
    ... We are stuck migrating our SBS 2003 domain to Server 2008. ... Fatal Error:DsGetDcName (SRV-EXCH) call failed, ... Verify your Domain Name Sysytem (DNS) is ... network connectivity to a domain controller. ...
    (microsoft.public.windows.server.sbs)
  • Re: AD management snap in cannot find DC (netdiag /v workstation)
    ... The name.local entries are used by my apache server to implement ... change button, more button, the "Primary DNS suffix of this ... Attr: subschemaSubentry ... Owner of the binding path: ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD management snap in cannot find DC (netdiag /v workstation)
    ... button, more button, the "Primary DNS suffix of this computer", it should ... The Security System could not establish a secured connection with the server ... Attr: subschemaSubentry ... Owner of the binding path: ...
    (microsoft.public.windows.server.active_directory)
  • RE: [fw-wiz] Backup exec agent in dmz
    ... named.conf file and the zonefiles off the the NT box in the DMZ. ... on the Apache server, ... backup tape library in this DMZ and backup all your servers to the new DMZ. ... what do you really need to back up on the DNS and web servers? ...
    (Firewall-Wizards)
  • Re: AD management snap in cannot find DC (netdiag /v workstation)
    ... DNS Host Name: tonyb-pc.imageproc.imageproc.com ... Testing IpConfig - pinging the DHCP Server... ... Attr: subschemaSubentry ... Owner of the binding path: ...
    (microsoft.public.windows.server.active_directory)