Re: DNS Restructure



Hi, thanks for the post. What I mean by child root is we have a regional
office in each domain and that regional office as a DNS server that all
branch offices point to. Then, all regional office point back to our
corporate office.

We're running a mix of 2000/2003, but we hope to have all 2003 by the end of
the year. It's my understanding that if each internal DNS server is using
the default root hints, that it's not very efficient because each server can
query Internet DNS servers and this causes more traffic and doesn't make
efficient use of caching. Right now, the parent DNS server is located by
using forwarders.

Our subnet scope is 10.x.x.x. Each location is assigned a 10.x.x.x subnet.

Thanks for the comments!

"Kevin D. Goodknecht Sr. [MVP]" wrote:

> Tynman <Tynman@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
> > I've just inherited a rather large DNS environment and would like some
> > comments/suggestions on how to make it better. Our internal and
> > external DNS servers are separate and we host both. Currently, we
> > have a root domain with 8 child domains. Each child domain has a
> > "child root" DNS server(s) are setup with forwarders to a DNS server
> > in the root domain. All other child DNS servers point to the "child
> > root" server.
>
> You want to clarify your term "Child root"?
>
> >
> > All child DNS servers have the default Cache.dns root hints. I'm
> > thinking I should point the root hints of the child servers to the
> > root; however, I'm not 100% sure how to set that up. Should I just
> > point them all to the root DNS server and then the root server use
> > it's root hints to resolve external requests?
>
> Is this Win2k or Win2k3?
>
> I'd leave the Root hints alone, if the parent DNS cannot be located by using
> root hints, turn off recursion on the Forwarders tab by checking "Do not use
> recursion"
>
> >
> > All child domain DNS servers also point to themselves for DNS. Each
> > child domain hosts its own Forward lookup zone and on the root server
> > there's a stub zone pointing to the child zone. As far as reverse
> > DNS goes, it's kind of a mess... For the most part, each child domain
> > hosts its own reverse zone; however, there is no delegation/stub at
> > the root server pointing back. Any recommendations on how and if I
> > should use stub zones for the child reverse zones?
>
> What subnet ranges are you using?
>
>
>
>
> --
> Best regards,
> Kevin D. Goodknecht Sr. [MVP]
> Hope This Helps
> ===================================
> When responding to posts, please "Reply to Group"
> via your newsreader so that others may learn and
> benefit from your issue, to respond directly to
> me remove the nospam. from my email address.
> ===================================
> http://www.lonestaramerica.com/
> ===================================
> Use Outlook Express?... Get OE_Quotefix:
> It will strip signature out and more
> http://home.in.tum.de/~jain/software/oe-quotefix/
> ===================================
> Keep a back up of your OE settings and folders
> with OEBackup:
> http://www.oehelp.com/OEBackup/Default.aspx
> ===================================
>
>
>
.



Relevant Pages

  • Re: Trust between child and domain broken
    ... Does the root DNS delegate to the child or in some other ... > And, when I tried to demote the child domain, it prompted: ...
    (microsoft.public.windows.server.dns)
  • Re: Question re: DNS forwarding best practices
    ... change rate of the root DNS zone's content. ... to a primary of the zone, so hopefully you have at least one ... as the case might allow) to the DNS servers of the root. ...
    (microsoft.public.windows.server.dns)
  • Re: AD Login
    ... phyically in the root domain), logon to with their own AD credentials. ... DNS issues OR to firewall/routing issues. ... or perhaps the DNS servers for one domain cannot find the "other" ...
    (microsoft.public.windows.server.active_directory)
  • Re: DNS setup for a child domain in Windows 2003
    ... > The thing is though if you are setting up a child domain you need to be ... > to resolve to the dc in the root domain so you dont get the option there ... So you need to have DNS setup before ... You can leave the server pointed at the root zone ...
    (microsoft.public.windows.server.dns)
  • Re: AD SRV records not shown in delegated child domain
    ... > Root hints work is totally incorrect. ... > unless the parent DNS has a root zone. ... > so on for each child domain pointing to the child DNS for each child ...
    (microsoft.public.win2000.dns)

Loading