Sites and Services



We just recently upgraded our NT domain to 2K3 AD. We have one corp site with
around 40 branches. The in place upgrade went great, however when deploying
DC's to other sites I am having an issue with Headquarters clients
authentication to a Branch.
We are using a mixed Bind windows DNS environment where our AD name is the
same as our existing Bind DNS name. The appropriate zones are handed off to
our windows DNS server. Our Windows DNS servers then transfer the zones to
the BIND dns servers. All clients/server use our BIND servers located at
headquartes for DNS.

Each DC is a GC and I have configured sites and services with the
appropriate server for each subnet.
Example Branch subnet 135.74.65.0/24 assigned to Branch site Houston which
includes the Houston DC.
Branch subnet 135.74.41.0/24 assigned to Branch site Tulsa which includes
Tulsa DC.
I have not defined any subnets for the Headquarters yet. (135.74.48.0 - 55.0)

I would like to keep Headquarters pc's from authenticating at branches...and
vice versa. That is the whole reason to have GC's at each site.

My thoughts are...It might have something to do with DNS. Setup each DC at
each branch as a DNS server and point all client at each branch to them for
resolution. Setup forwaders to the BIND servers.

Any thoughts?


.



Relevant Pages

  • [UNIX] Hardening the BIND DNS Server
    ... Hardening the BIND DNS Server ... Your Domain Name Service is the road sign to your systems on the Internet. ...
    (Securiteam)
  • Re: Local DNS Caching not caching on external interface
    ... I have just configured a Local DNS server using the built-in ... Bind 9.3.1 on a FreeBSD 5.4 machine. ... seem to query the caching name server from my local network. ...
    (freebsd-questions)
  • Re: Chroot Debian
    ... Why is a DNS server such a security risk that it should be run ... There's a long history of bugs and security compromises with BIND. ... The reason for the chroot configuration, though, is a ... As for what 'sploits there are, Googling "bind vulnerability OR ...
    (Debian-User)
  • Re: Observation on FC2/Help on FC1
    ... patience now to wrap all lines so that a proper quoting is possible] ... If you only run a bind DNS server on the suspicious FC1 host, ... You should that see from the logs. ...
    (Fedora)
  • Re: TCPIP Services on VMS (and Tru64)
    ... If the alpha is currently running the main DNS server, ... They are in standard BIND format. ... I think the same applies to DHCP. ... Once you've loaded the microsoft virus incubator with the BIND database, ...
    (comp.os.vms)