Re: Event ID 7062 in DNS logs

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



In news:1136221528.378903.246780@xxxxxxxxxxxxxxxxxxxxxxxxxxxx,
ovidiu_m_gheorghita@xxxxxxxxx <ovidiu_m_gheorghita@xxxxxxxxx> stated, which
I commented on below:
> Hi,
>
> I installed a Windows 2003 forest containing one root domain and few
> child domains. The forest has Windows 2003 internal DNS servers which
> means that has no internet communication.
> All domain controllers on the root and child domains are also DNS
> servers with AD-integrated DNS zones.
>
> On all DNS servers I deleted the default root internet root hints, I
> let the Root Hints tab empty for the root servers and I populated it
> with the root servers addresses on all the child domain DNS servers.
> For all child domains, requested delegations were made into the root
> DNS zone.

<snip>
As Kevin mentioned, there is no need to delete the Root hints. If you create
the Root zone (the dot), you can keep away from internet resolution if
desired and would assume that you have ISA or some sort of proxy server
allowing controlled internet access or none at all.

But there is no need to populate the child domain DNS servers into the Root
hints. That is totally unnecessary. I've configured multiple clients with a
parent (the forest root DNS) to child delegations with forwarding from the
child back to the parent (forest root) DNS and it works like a charm. Of
course they wanted internet resolution, so I would forward from the parent
to the ISP. What you're doing is totally overhead and unnecessary. The
delegation method is the recommended best practice and pretty much the
industry standard (from opinions here in the newsgroups over the past 5
years).

I believe you are getting those errors, and as Kevin mentioned, from
improperly configuring forwarding to each other in essence creating a
possilbe forwarding loop?

For more information on delegations, this should explain a little for you:
255248 - HOW TO Create a Child Domain in Active Directory and Delegate the
DNS Namespace to the Child Domain:
http://support.microsoft.com/?id=255248

Also that article Kevin mentioned about delegating the TLDs to your "root"
server is a nice one, if you want to go that route.

--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

If you are having difficulty in reading or finding responses to your post,
instead of the website you are using, if I may suggest to use OEx (Outlook
Express or any other newsreader of your choosing), and configure a newsgroup
account, pointing to news.microsoft.com. This is a direct link into the
Microsoft Public Newsgroups, and it is FREE and DOES NOT require a Usenet
account with your ISP. With OEx, you can easily find your post, track
threads, cross-post, and sort by date, poster's name, watched threads or
subject.

Not sure how? It's easy:
How to Configure OEx for Internet News
http://support.microsoft.com/?id=171164

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft MVP - Windows Server Directory Services
Microsoft Certified Trainer
Assimilation Imminent. Resistance is Futile.
Infinite Diversities in Infinite Combinations.
=================================


.



Relevant Pages

  • Re: Forest to Child -- Permissions
    ... first DC in the root. ... the member servers only ... DCDiag pretty much confirms authentication AND that DNS is right. ... never happen unless some admin has been mucking about. ...
    (microsoft.public.windows.server.dns)
  • Re: urgent-DNS forwarder problem
    ... There is a firewall between my DCs and the root domain which I'm a little ... Using nslookup I've tried connecting to DNS servers in domains on the other ... >> I've recently inherited a child domain containing 4 DCs that is part ... > forwarder to go to the parent DNS. ...
    (microsoft.public.windows.server.dns)
  • Re: MS Update Breaks External DNS again
    ... name checking: Multibyte Load zone data on startup: From Active ... Yes I have to force root hint updates on both servers manuall (i use ... This is what is in both of my DNS servers cache.dns files. ...
    (microsoft.public.windows.server.dns)
  • =?UTF-8?B?UmU6IFByb2dyYW1taWNhbGx5IHF1ZXJ5aW5nIHRoZSBnbG9iYWwgY2E=?= =?UTF-8?B?dGFsb2cg4oCTI
    ... The one exception would be if you had a root, child1, child2 and you wanted to connect to child2 from child1 then kerberos in the backend would route up through root and back down to child2 for auth. ... I will forget about WinNT as should everyone else who is dealing with AD. LDAP simply tells you to use the LDAP protocol, GC, tells you to use the LDAP protocol over port 3268. ... I believe that becomes "connect to LDAP port 3268 on any machine returned by the dns query domainname.com" but I would have to do a network trace to be positive. ... Binding to a GC in a child domain from a child domain does not rely on the presence of a DC in the root domain. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Problems with named default configuration in 6-STABLE
    ... transfer the zone, the hints mechanism is still in the comments. ... with overall root traffic for the root zone, ... slaving the root zone will make you still being able to resolve DNS ... servers worldwide being unreachable. ...
    (freebsd-stable)