Re: Primary vs. Secondary

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Kevin D. Goodknecht Sr. [MVP] (admin_at_nospam.WFTX.US)
Date: 10/01/04


Date: Fri, 1 Oct 2004 17:04:07 -0500

In news:e$L4Ez$pEHA.556@tk2msftngp13.phx.gbl,
Fenton <fenton@no-email.com> commented
Then Kevin replied below:
> Thanks kevin,
>
> Just wondering since the DNS will randomly select the all
> Nameservers for query, (including the primary and all the
> secondarys), so, is putting an EXTRA "not-as-reliable"
> secondary nameserver a good idea? On one hand, it
> creates some extra redundancy. However, on the other
> hand, there are chances for it to be picked randomly
> while it is offline and hence delay the query.

Do not confuse what I said, when you put a DNS on your public record as
authoritative then it should answer with authority. In other words it needs
a zone and an NS record for its name and IP.
You could list as many DNS servers you want, up to the maximum you can list
with your registrar, if they don't have a zone and an NS record they have no
authority. If they are capable of doing recursive lookups they will still
answer without a zone for your domain, but not with authority.
Whether it is a primary or a secondary zone makes no difference to the DNS
server asking for the records, as long as it has authority. The difference
between a primary and a secondary is the secondary will have a read only
zone, but still have authority. The only DNS servers it actually makes a
difference to is the ones holding the zones, the DNS server shown as the
master is the one the secondary servers sync up to. Even that doesn't mean
that it is the one with a Primary zone. In fact, you could make all of the
DNS servers on the public record have secondary zones and the one with the
Primary zone may not even be publicly accessible. It would be a hidden
master and could be configured so that only the secondary servers could
access it to update their zones.

-- 
Best regards,
Kevin D4 Dad Goodknecht Sr. [MVP]
Hope This Helps
===================================
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
===================================
http://www.lonestaramerica.com/
===================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
===================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
===================================


Relevant Pages

  • Re: DNS signature failed to verify error
    ... In our last we discussed the need for there to be a NS record for each DNS ... Under the zone domain.local there is a delegation _msdcs which only has one ... _msdcs.domain.local is configured the "Replicate to all DNS servers in the AD ... Thanks for the DCDiag syntax suggestion. ...
    (microsoft.public.windows.server.dns)
  • Re: DNS Cache Corrupt for individual zone
    ... for authoritative DNS of external hosts). ... We have a frustrating issue where the zone for one particular zone ... when the cache is in this state. ... DNS servers are only accessible in our internal DNS network. ...
    (microsoft.public.windows.server.dns)
  • Re: Windows 2008 DNS Secondary 2003 primary DNS zone
    ... I have a primary DNS zone "mydomain.com" running on a 2003 DC, ... we register our domain names with) All the DNS servers are AD domain ... When you have an AD integrated zone, the DNS data is stored in the actual AD database and is replicated to all DCs and will be available to any DC that has DNS installed, depending on the zone replication scope setting. ...
    (microsoft.public.windows.server.dns)
  • Re: Question re: DNS forwarding best practices
    ... change rate of the root DNS zone's content. ... to a primary of the zone, so hopefully you have at least one ... as the case might allow) to the DNS servers of the root. ...
    (microsoft.public.windows.server.dns)
  • Re: 2 Questions...
    ... In one post you asked about the value of the empty root. ... With a multi-domain forest one has a few choices for DNS ... One could use standard zone transfer to these, ... as already stated or by having the DNS servers of corp forward to ...
    (microsoft.public.windows.server.dns)