Re: Nt 4.0 and Integrated Dns in AD

From: Kevin D. Goodknecht Sr. [MVP] (admin_at_nospam.WFTX.US)
Date: 08/25/04


Date: Wed, 25 Aug 2004 08:10:20 -0500

In news:d16101c48a9e$c57c4ca0$a601280a@phx.gbl,
Steve <anonymous@discussions.microsoft.com> wrote their comments
Then Kevin replied below:
> Hello,
>
> I have 2 domains. An NT 4.0 domain and a Windows 2000
> domain. The trust between these 2 domains do not exist
> for security reasons. All my current machines both in the
> NT domain and 2000 domain recieve dns resolution via a
> primary dns box located in the 2000 domain. Will
> upgrading this dns to "active directory integrated" have
> any effect on the NT 4.0 machines that are in the old NT
> domain? What would be my best option?

Do you only have one DC in the Win2k domain?
If so you should probably stick with a standard primary zone for the AD
domain. AD integrated _is_ more secure but if you only have one DC in the
Win2k domain you'll probably see errors at start up because AD can't start
without DNS and DNS can't load ADI zones until AD is started. It is a catch
22 situation, but you really should have two DCs with DNS, even if the
replica DC is not on the greatest box.

-- 
Best regards,
Kevin D4 Dad Goodknecht Sr. [MVP]
Hope This Helps
================================================
-- 
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
================================================
http://www.lonestaramerica.com/
================================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
================================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
================================================


Relevant Pages

  • Re: How to enable communication between Two different lans (subnets)/ domains 2003 server based? Ass
    ... You will also almost certainly have DNS problems running a domain behind ... server domain, with a DHCP server running on one of the 2003 boxes. ... the "inner" subnet can see the original subnet and the Internet, ... The .227 machines can see the machines on the 192.168.1.0 subnet and the ...
    (microsoft.public.windows.server.networking)
  • RE: suspicious firewall rules in WinXP firewall
    ... When that site got taken down, DNS ... suspicious firewall rules in WinXP firewall ... I can ping out of these two machines, ... World renowned security experts reveal tomorrow's threats today. ...
    (Incidents)
  • Re: Removing "permanently offline" DC...
    ... Make sure that at least one of these machines is a Global Catalog ... In the DNS console, use the DNS MMC to delete the cname ... If this was a DNS server before you brought it down, ... Event 13516 OR 13509 which indicate successful replication. ...
    (microsoft.public.windows.server.active_directory)
  • Re: ISA 2006 and Listeners Part 2!
    ... All machines use only the internal AD/DNS ... No machine should ever use any other DNS ... The AD/DNS machine will use the ISP's DNS in the ... Microsoft Internet Security & Acceleration Server: ...
    (microsoft.public.isa.configuration)
  • Re: 2 PCs not visible in net view or network browsing - Why?
    ... > it is the SAME as the Primary DNS suffix -- but this is NOT ... :yes some are public but behind firewall, so only visible to local domain.. ... Between the working machines ... > Are you using a DC for a router (multiple NICs)? ...
    (microsoft.public.win2000.networking)

Loading