Re: dns questions

Tech-Archive recommends: Speed Up your PC by fixing your registry

From: Andrew Hodgson (me3_at_privacy.net)
Date: 08/26/04

  • Next message: Andrew Hodgson: "Re: dns questions"
    Date: Thu, 26 Aug 2004 08:14:42 +0100
    
    

    On Wed, 25 Aug 2004 05:06:46 -0500, "Kevin D. Goodknecht Sr. [MVP]"
    <admin@nospam.WFTX.US> wrote:

    >Your issue with Exchange is a configuration issue, the message headers can
    >be configured to say anything you want.

    I would be grateful if you could let me know how to change the
    Message-ID then in the headers. Please reply off-group if you feel it
    would be more apropriate.

    >But I can think of several reasons
    >right off the bat why _not_ to use the same internal name as the public
    >name, or for that fact not even in the same DNS tree.
    >
    >Most importantly, some users either prefer or must access their external
    >website by only its domain name, without www. It is impossible to access the
    >public website from within the local domain by only its domain name, unless
    >that public website is hosted on the domain controller for that domain name.

    This is true, but as most people use WWW for websites throughout the
    Internet, I don't see this as an issue. For example, I give people an
    address, www.hodgsonfamily.org, which works both internally and
    externally. http://hodgsonfamily.org, although hosted on the same IIS
    server on the DC, points to a different website that only the LAN
    users have access to, plus it is used for OWA access (i.e,
    https://hodgsonfamily.org/exchange/). Again this works fine
    internally and externally.

    >The record for the domain name must point to the IP address(es) on the
    >domain controller that have file sharing enabled to allow access to the
    >SYSVOL DFS share at \\example.com\SYSVOL . If you modify the behavior of a
    >DC to _not_ create this record and then manually add a record that points to
    >the web server, domain members will look to the web server for the SYSVOL
    >DFS share. For that fact all DFS shares use the domain name and therefore
    >DFS shares will not work.

    I don't recomend doing this, however, so it is not an issue.
    >
    >Another problem caused by using the same public name as AD name is for VPN
    >clients which have the unique ability to see both the public and private
    >name spaces. Even if you make the internal domain a third level, such as
    >corp.example.com this is a problem unless the public DNS zone has the sub
    >domain corp delegated to the private IP of the internal DNS server. This is
    >why I recommend example.local, by using example.local it causes the public
    >DNS servers to delay long enough for the internal DNS to respond and keeps
    >any cached records from the public domain on the VPN client from conflicting
    >with AD domain records.

    While I can see caching may be an issue on the clients here, I have
    never experienced the problem - the private data is always returned
    when I am on the VPN.
    >
    >All in all, it saves time and money for the AD domain to not have a name
    >that might conflict in any way, with any name in the public name space.

    If you can show me how to change the Message-ID in Exchange, I would
    be happy to comply with this request.

    Andrew.

    -- 
     Andrew Hodgson in Bromyard, Herefordshire, UK.
    My Email: use <andrew at hodgsonfamily dot org>.
    

  • Next message: Andrew Hodgson: "Re: dns questions"

    Relevant Pages

    • Re: Urgent! New router and big disaster
      ... The SBS DNS server, running on ... its IP it means that your problem is now DNS. ... forward ports to it reliably in the router. ... I should have been more clear about internet connection.. ...
      (microsoft.public.windows.server.sbs)
    • Re: Cannot connect to RWW from home PC
      ... DNS stuff says your mail server is responding with reply that is not MS ... When we setup this new SBS2003 setup we installed without ISA as it does ... not seeing any problems anywhere regards internet or email - we also run ...
      (microsoft.public.windows.server.sbs)
    • Re: Non-domain connection problem
      ... For some reason the DNS is persistent. ... connect new PC to the internet from the non-domain network: ... In server 2000 gpoedit.msc showed them but in SBS it is different. ...
      (microsoft.public.windows.server.sbs)
    • Re: resolve incorrect IP from RRA server.
      ... dynamic address, 10.5.101.123 from DHCP server. ... This is because the addtional DNS records that get registered cause major problems with AD functionality, especially the additional IPs registered by RRAS. ... However, if you choose to keep RRAS on the DC, then you have to force DNS to only register the internal static interface, and no others. ... If it is the internet gateway, it is recommended to purchase an inexpensive, or cable/DLS router, or even better, a Cisco or similar firewall to perform the task, which if it is compromised by an internet attacker remotely, can further compromise the rest of the internal network. ...
      (microsoft.public.windows.server.dns)
    • Re: Urgent! New router and big disaster
      ... Even a single-NIC configuration should have ONLY the LAN IP of the server as ... Then you can run the CEICW or use the DNS console to enter ... forward ports to it reliably in the router. ... I should have been more clear about internet connection.. ...
      (microsoft.public.windows.server.sbs)