Re: Split DNS

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Andrew Hodgson (me3_at_privacy.net)
Date: 09/01/04


Date: Wed, 01 Sep 2004 19:59:14 +0100

On Mon, 30 Aug 2004 05:31:03 -0700, "draco55"
<anonymous@discussions.microsoft.com> wrote:

>How would I set a "split DNS" scenario using Win2K3? From
>what I read so far I would have to create two zones for
>the same domain. The zone on the external DMZ network
>will only have entries with public addresses for only
>those machines that need to be accessible from the
>internet. The other zone will be in the internal network

Yes, probably best to do this either using different DNS software
(i.e, MS DNS for AD/private DNS and something like Simple DNS Plus for
public resolution <http://www.jhsoft.com>), or use two different
machines.

>with entries for all the "inside" machines plus entries
>with private addresses for those machines located on the
>DMZ. My other questions are can the internal zone be AD
>integrated? And can I add the external zone on the DMZ as
>a forwarder for the internal zone?

Forwarders are a different issue - your internal DNS server doesn't
need to talk to your external server.

Andrew.

-- 
 Andrew Hodgson in Bromyard, Herefordshire, UK.
My Email: use <andrew at hodgsonfamily dot org>.


Relevant Pages

  • Re: DNS domain name same as AD domain
    ... Or should I change the DNS domain first to something else? ... For any host name that you wish to have access from both your internal network and from the external Internet you need scenario 1, although it is the most DNS-intensive over time. ... Each DNS zone is authoritative for the zone of that name so therefore the external DNS zone and internal AD/DNS zone will NOT replicate with each other thereby prevent internal company records to be visible to the outside Internet. ...
    (microsoft.public.windows.server.dns)
  • Re: .com versus.local
    ... DNS and public names on the internet etc but I have never had someone ... All DNS entries are help at the ISP. ... external Internet you need scenario 1, although it is the most DNS-intensive ... Each DNS zone is authoritative for the zone of that name so ...
    (microsoft.public.windows.server.dns)
  • Re: AD DNS naming
    ... my e-mail and Site Internet." ... infrastructure (mostly with respect to DNS and VPN). ... If you do not select this option and go with scenario 2 ... Each DNS zone is authoritative for the zone of that ...
    (microsoft.public.windows.server.dns)
  • Re: How many Global Catalog Servers are needed?
    ... make for an AD DNS FQDN domain name, ... external Internet you need scenario 1, although it is the most DNS-intensive ... Each DNS zone is authoritative for the zone of that name so ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain naming strategies
    ... a delegation to an unreachable internal dns server. ... my e-mail and Site Internet." ... network and from the external Internet you need scenario 1, ... Each DNS zone is authoritative for the zone of that name so ...
    (microsoft.public.windows.server.active_directory)