Re: Need feedback about DNS implementation



"Slimard" <Slimo@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:004B0ABA-5DB4-4243-B9D1-12C51860D175@xxxxxxxxxxxxxxxx
> Hello,
>
> Sorry if this question has been already raised on this forum.
> We are an holding group that holds 4 companies.
> We are in the process of implementing a new AD 2003. The design will be a
> single domain with placeholder domain on top (empty toot). The single
domain
> will be collapsed into 4 OUs (= 4 companies, each OU is a geographical
> location). Each comapany has its own ISP and has its own internet public
> domain (company1.com...company4.com). All the companies are interconnected
> through VPN.
>
> The holding group has an internet public domain: company.com. We decided
to
> go for ad.company.com for the DNS namespace. So we separate the internal
and
> external DNS. ad.company.com will be the root domain and the production
> domain will be a child domain, let say corp.ad.company.com.
>
> We would like to achieve the following goals:
> *** create 5 DNS subdomain (zone) and allow each company to manage their
> zone. For example we will have a zone like company1.corp.ad.comapny.com,
> company2.corp.ad.comapny.com...

That is fine technically -- those names are obnoxiously
complicated (for users and admins to type).

One obvious simplification would be to avoid using BOTH
"ad" and "corp" as qualifiers -- they don't seem to (both)
be making any real distinction.

> *** Queries to Internet should be resolved by the local ISP's and not
> traverse the WAN

Forwarding to the ISP does this.

> *** VPN users (travelling users) should be able to resolve internal names.
> By having the internal domain a subdomain of the external domain, it
should
> not be a problem.

You need to arrange for EVERY DNS server (they might
use) to be able to resolve ALL of your internal DNS names,
and to do that with a server that can also deal with the
Internet (forwarding above.)

> *** Is it possible to set the NETBIOS name to CORP, or do we need to use
AD
> as netbios name? So it is possible to a netbios name <> than the DNS name

No, you can technically use anything that isn't the same
on different AD domains -- i.e., one unique NetBIOS
name per AD domain.

BUT the usual convention is to use the LEFTMOST tag --
since this is usually the most distinctive or specific, and
in your case this would give: company1, company2, etc.

BUT having said that it reminds me that early on you said
you were collapsing this into ONE DOMAIN.

If that is case the internal DNS name will be the same for
ALL of the "companies".

And as to EXTERNAL DNS for public zones, those are
best left at the REGISTRAR (or retuned there.)

> Thanks in advance for your comments about this design



.



Relevant Pages

  • Re: What is FQDN ?
    ... Active Directory setup Wizard didn't add my computer name which is "DC1DNSAD". ... Connection-specific DNS Suffix. ... I think at one Point AD Setup Wizard ask you Question What should be NETBIOS ... How to Configure OEx for Internet News ...
    (microsoft.public.windows.server.dns)
  • Re: computer name length issue
    ... This length is reflective of the old NETBIOS computer name which was 8 characters, 15 on then newer Windows OSes. ... However, what Microsoft did a long time ago when they finally added Internet support over its NETBIOS based LAN support, was WINS which ties the IP address of the machine with the netbios computer name. ... That is only TRUE when the network administrator has made it that way via DNS and WINS. ...
    (microsoft.public.vc.language)
  • Re: Need feedback about DNS implementation
    ... > The holding group has an internet public domain: ... > decided to go for ad.company.com for the DNS namespace. ... So it is possible to a netbios name than ...
    (microsoft.public.windows.server.dns)
  • Re: Urgent! New router and big disaster
    ... Both NICs should point to his internal IP for DNS. ... forward ports to it reliably in the router. ... I should have been more clear about internet connection.. ...
    (microsoft.public.windows.server.sbs)
  • Re: Urgent! New router and big disaster
    ... Both NICs should point to his internal IP for DNS. ... You should give your SBS a fixed external address so you can forward ports to it reliably in the router. ... I should have been more clear about internet connection.. ...
    (microsoft.public.windows.server.sbs)