Re: Forwarders



"jremmc" <jremmc@xxxxxxxxxxxxxx> wrote in message
news:u1dxxo9gFHA.3912@xxxxxxxxxxxxxxxxxxxxxxx
> Setting up AD-Integrated DNS on branch child DC. Branch is connected via
> Frame-Relay WAN to HQ (which contains our Root DCs and two other child
DCs),
> but also has second, direct T1 to Internet for Internet traffic.
>
> What is best practice -- Should Branch DNS Forwarders point to Root DCs
like
> HQ Child DCs do (and Root DCs point ot our ISP for public resolution), or
> can they point directly to our ISP to avoid the added Frame-Relay traffic.

There is no "best practice" here, except that every DNS server much
be able to resolve ALL of the names needed by it's clients; resolve
them either directly (from zone files) or through forwarding and/or
actual recursion.

> Root DNS replicates to all DCs in Forest, so child DC would have copy of
> Root Domain zone.

Then there is little necessity for the child DNS server to forward
to the root explicitly so more likely they should foward to your
"Firewall-DMZ" DNS" unless you feel that you can obtain some
more economies of scale and cache by using an itermediate forwarder
(e.g., the root DNS) and then test that expectation successfully.

Most of us do NOT want you to have DCs forwarding directly to
the outside, EVEN to the ISP. DCs should be kept ISOLATED on
your internal network.

Thus the DNS server(s) -- probably caching only -- in the DMZ
or on your firewall SHOULD deal with Internet names for ALL
internal DNS servers and clients.

--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]


.



Relevant Pages

  • Re: Trust between child and domain broken
    ... Does the root DNS delegate to the child or in some other ... > And, when I tried to demote the child domain, it prompted: ...
    (microsoft.public.windows.server.dns)
  • Re: Child DNS replication scope error - "Name limit for the local.
    ... Anyway, based on the Event Logs, it seemed that a zone was being ... Restarted both the child DCs. ... replication scope in EITHER of those to "All DNS servers in AD domain ...
    (microsoft.public.windows.server.active_directory)
  • Re: DNS Restructure
    ... What I mean by child root is we have a regional ... It's my understanding that if each internal DNS server is using ... >> external DNS servers are separate and we host both. ...
    (microsoft.public.windows.server.dns)
  • Re: DNS setup for a child domain in Windows 2003
    ... > The thing is though if you are setting up a child domain you need to be ... > to resolve to the dc in the root domain so you dont get the option there ... So you need to have DNS setup before ... You can leave the server pointed at the root zone ...
    (microsoft.public.windows.server.dns)
  • Re: AD SRV records not shown in delegated child domain
    ... > Root hints work is totally incorrect. ... > unless the parent DNS has a root zone. ... > so on for each child domain pointing to the child DNS for each child ...
    (microsoft.public.win2000.dns)