Re: One AD zone poses problem for regional adminstrator

From: Mark Renoden [MSFT] (markreno_at_online.microsoft.com)
Date: 06/10/04


Date: Fri, 11 Jun 2004 09:35:01 +1000

Hi DJ

I don't know how you're going to achieve this if all of the machines are in
the same domain/name space. An example of what can go wrong:

++++++
Let's assume the domain is called "mydomain.local".

All sites except this "special site" use DNS servers that have a copy of the
"mydomain.local" zone and this zone covers all computers in all sites except
the "special site".

The "special site" has it's own zone called "mydomain.local" that only
contains machines that are in the "special site".

How does a machine in the "special site" ever find a machine in any other
site?
++++++

If you're using a single domain, you need one consistent zone across all DNS
servers. If you use child domains with delegation and forwarders, you can
more easily meet the goals that your administrator has.

Kind regards

-- 
Mark Renoden [MSFT]
Windows Platform Support Team
Email: markreno@online.microsoft.com
Please note you'll need to strip ".online" from my email address to email 
me; I'll post a response back to the group.
This posting is provided "AS IS" with no warranties, and confers no rights.
<anonymous@discussions.microsoft.com> wrote in message 
news:1af9501c44f3f$79eaee30$a101280a@phx.gbl...
> Thanks Mark,
>
> Essentially the admin does not want to have to browse
> through several hundred computers when administering DNS.
> He wants to view the DNS information for his region only.
>
> I did not know if we could install a child domain as all
> of the sites are included in one domain.
>
>
>
>>-----Original Message-----
>>Hi DJ
>>
>>You might need to explain "segregate the his computner
> from the zone for
>>administrative purposes".
>>
>>Here's a how to on zone delegation for child domains:
>>
>>255248 HOW TO: Create a Child Domain in Active Directory
> and Delegate the
>>DNS
>>http://support.microsoft.com/?id=255248
>>
>>Kind regards
>>-- 
>>Mark Renoden [MSFT]
>>Windows Platform Support Team
>>Email: markreno@online.microsoft.com
>>
>>Please note you'll need to strip ".online" from my email
> address to email
>>me; I'll post a response back to the group.
>>
>>This posting is provided "AS IS" with no warranties, and
> confers no rights.
>>
>>"DJ" <anonymous@discussions.microsoft.com> wrote in
> message
>>news:1af6801c44f3a$b8671f80$a101280a@phx.gbl...
>>>I will soon be deploying Windows 2003/AD for our network
>>> which consists of several offices around N. America.  My
>>> plan calls for a single forest/single tree with one DNS
>>> zone however one of the administrators in a regional
>>> office wants to segregate the his computers from the
> zone
>>> for administrative purposes.  Does anyone know of a way
> to
>>> do this?  I have looked at and tested Delegated zones
> but
>>> I cannot get it to work.
>>>
>>> Any help would be appreciated!!!
>>
>>
>>.
>> 


Relevant Pages

  • Re: One AD zone poses problem for regional adminstrator
    ... you need to make this distinction, create a child domain called ... > wanted to seperate his regions DNS information i.e. ... >>"mydomain.local" zone and this zone covers all computers ... >>the "special site". ...
    (microsoft.public.windows.server.dns)
  • Re: Problem with AD and AD Integrated DNS
    ... All 200 machines were affected all except the servers.. ... With that said I had to re-image the machines to fix this issue. ... What I was told before working at this place was that each DNS server ... If all DCs are in the same domain, if a zone is AD integrated on one DC, the ...
    (microsoft.public.windows.server.dns)
  • Re: private and public version of same zone on a single server?
    ... > serves the same zone to the private network directly. ... > private version of the zone and public machines the ... This is not possible with MS DNS, ...
    (microsoft.public.windows.server.dns)
  • Re: Dynamic Forward Lookup Zone
    ... I guess what I had envisioned is that I could have the bulk of my machines ... using DHCP and getting automatically registered with DNS with whatever value ... zone, I would configure those to use the conneciton specific zone for ...
    (microsoft.public.windows.server.dns)
  • Re: Thoughts on a large-scale DNS server...
    ... > (One ISP is taking over another ISP) and would greatly appreciate any ... > In the end we will probably be doing authoritative DNS for 11,000 domains, ... > The plan is to have 3 core machines. ... One is the master, and gets its zone ...
    (freebsd-isp)