Re: dns over subnets

From: Roger Abell [MVP] (mvpNoSpam_at_asu.edu)
Date: 12/07/04


Date: Mon, 6 Dec 2004 21:10:02 -0700

You should not be in position of needing to create DNS A records in one
subnet as compared to another in this scenario. If a machine is to be
a member of a domain it needs access to all SRV and related A and CName
records of the zone supporting the domain it has joined and of the root
domain
of that forest if this is different from its domain of membership.

Usually this is done by allowing access to a DNS server that can resolve
those.
Most commonly this means allowing the queries through the firewall or by
having
the zone(s) hosted by a local DNS server by use of a zone transfer.

It is possible that issue you see are because of the FW. I know you said
that
it is dropping nothing. Does that mean if you shut it off, I mean, bypassed
it,
then the issues remain?

-- 
Roger Abell
Microsoft MVP (Windows Server System: Security)
MCDBA,  MCSE W2k3+W2k+Nt4
"sktech" <sktech@discussions.microsoft.com> wrote in message 
news:4105C3AB-0CD2-47AC-B820-3AB064FC257A@microsoft.com...
>I have two subnets connected through a firewall and have managed to get 
>most
> of windows to network through. Although I have joined one server on subnet 
> B
> to the domain on subnet A, it seems to be sluggish in resolving. The FW is
> not dropping anything. I created a HOST A record for the server in subnet 
> A
> DNS and a record in subnet B dns. Both DNS are hosted on subnet A. Should 
> I
> create a DNS server for subnet B to improve performance. Windows services
> seem to run fine but pervasive db 8.5 keeps losing its connection and I am
> wondering if it is because of name resolution....
>
> Thanks 


Relevant Pages

  • Re: Cannot find a primary authoritative DNS server
    ... then if there are other suffixes, ... DNS server and looking at the subnet mask, ... Microsoft Windows MVP - Windows Server - Directory Services Security Is Like An Onion, ...
    (microsoft.public.win2000.dns)
  • Re: dns over subnets
    ... Why must a domain member "see" the _msdcs zone of the root domain, ... > subnet as compared to another in this scenario. ... > Usually this is done by allowing access to a DNS server that can resolve ... > the zonehosted by a local DNS server by use of a zone transfer. ...
    (microsoft.public.windows.server.dns)
  • Re: applying computer settings takes a lot of time
    ... So in the moments the computer connected to another subnet to reach a DC/DNS server to authenticate and apply configuration settings, ... So is there a DNS server in there subnet available? ... Connection-specific DNS Suffix. ...
    (microsoft.public.windows.group_policy)
  • Subnet prioritization
    ... I got Windows 2003 and Windows 2000 dns running in our ... test subnet prioriitization against W2K DNS and W2003 ... other resource in other subnet. ...
    (microsoft.public.windows.server.dns)
  • Re: applying computer settings takes a lot of time
    ... PC and DNS/DC are in the 192.168.10.x subnet ... Add a DNS/DC to the site where the computers are located and let the clients use that machine as preferred DNS on the NIC and another site DNS as secondary for redundancy. ... So is there a DNS server in there subnet available? ... Connection-specific DNS Suffix. ...
    (microsoft.public.windows.group_policy)