Re: Zone Transfer and Trust

Tech-Archive recommends: Speed Up your PC by fixing your registry

From: Herb Martin (news_at_LearnQuick.com)
Date: 02/17/05


Date: Thu, 17 Feb 2005 13:48:03 -0600


"Neil" <Neil@discussions.microsoft.com> wrote in message
news:C898FB58-DBC2-452E-8225-FDB5B265792B@microsoft.com...
> Hi,
>
> Do we need to do Zone transfers from one DNS to another DNS to establish a
> trust between two domains.

No. External trusts (outside the forest - you must be doing
this since trusts inside the forest are automatic) require NetBIOS
resolution.

This (pratically) means WINS Server if you have more than
one subnet.

ALL machines must be WINS servers clients, especially DCs.

> Scenario
>
> Remote Customer Location has
>
> Win2000 ADS
> IntegratedDNS
> Has Internal IP Address and is Natted to outside world through Firewall
>
> Our Location
>
> Windows 2003 ADS
> Integrated DNS
> Has Internal IP Address and is Natted to outside world through Firewall
>
> Why do we need Zone transfer to take place? Also, can't a one way trust be
> established?

Zone transfers need to take place to all DNS secondary
servers for THAT same zone. (That is what it means to
BE a secondary.)

-- 
Herb Martin


Relevant Pages

  • Re: Active Directory Restructure Question
    ... If you are building a new forest you can use the Active Directory ... To start would have to establish dns connectivity both ways, ... Once established you can then go and create your external trust, ... domains for your UNIX/LINUX servers, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Active Directory Restructure Question
    ... If you are building a new forest you can use the Active Directory Migration ... To start would have to establish dns connectivity both ways, ... Once established you can then go and create your external trust, ... domains for your UNIX/LINUX servers, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Setting up AD trust Across NAT
    ... >> I am trying to set up a Windows AD 2003 trust with a domain that is ... >> sitting on the other side of a router that is doing NAT. ... >> conditional forward to their DNS then when I ask DNS what is the IP ... >> things like name servers, LDAP servers and all the other AD related ...
    (microsoft.public.win2000.active_directory)
  • RE: DNS ACL ?
    ... and there should be no zone transfers coming in ... from the internet to these servers. ... Subject: DNS ACL? ... > Not all DNS clients automatically try to negotiate bigger UDP ...
    (Pen-Test)
  • Re: transferring secondary DNS zone problem
    ... All the servers involved are W2K3. ... IPs in as DNS forwarders and allowed zone transfers. ...
    (microsoft.public.windows.server.dns)