Re: Any reason for this DNS setup?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



In news:FDBD92FF-050D-4464-AAC6-4DBA33D1BB33@xxxxxxxxxxxxx,
Peter <Peter@xxxxxxxxxxxxxxxxxxxxxxxxx> stated, which I commented on below:
> Kevin, thank you so much for your help and quick responses. Your
> help is much appreciated.
>
> BTW, we are going to retire all DCs. We are going to use new
> hardwares. I plan to intall Windows 2003 on one new server and
> promote and transfer FSMO roles on root and child domain; then
> introduce more DCs for load balance and fault tolence for root domain
> and child domain for some time. That means that Windows 2000 DCs
> will co-exist with Windows 2003 DCs.
>
>> After you upgrade the parent domain and before you upgrade the Win2k
>> child DCs, you should delete the secondary _msdcs.us.local zone
>
> In my situation above, should I delete the secondary first?
>
> BTW, what are right steps or suggestions for moving to windows 2003
> envir. if we are going to use different new servers?
>
> Thank you!
>
> Peter

If a delegation was in place, the secondary wouldn't have been needed. In a
delegation, a delegation is made under the parent zone for the child zone to
go to the child DC/DNS servers that are hosting the zone. From the child
DC/DNS servers configure a forwarder back to the parent. From the parent,
configure a forwarder to the ISP. This is a general config that works fine
for the _msdcs zone to be available forest wide, as Kevin mentioned.

255248 - HOW TO Create a Child Domain in Active Directory and Delegate the
DNS Namespace to the Child Domain:
http://support.microsoft.com/?id=255248

In your scenario, I would do this to make it a little easier and reduce the
complexities going forth to 2003. I would also suggest if in a mixed
2000/2003 scenario where both types of DCs are hosting DNS, be careful on
the replication scope settings on the 2003 DNS server with the AD Integrated
zones to keep them compatible with 2000 otherwise it may make a bit of a
mess with duplicate zones in AD if you mix replication scope types (where
the zone is being stored in AD). If you ask me, install your 2003 DCs, and
move all DNS services over to them as a priority in your upgrade project
management tasks list.

Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

If you are having difficulty in reading or finding responses to your post,
instead of the website you are using, if I may suggest to use OEx (Outlook
Express or any other newsreader of your choosing), and configure a newsgroup
account, pointing to news.microsoft.com. This is a direct link into the
Microsoft Public Newsgroups, and it is FREE and DOES NOT require a Usenet
account with your ISP. With OEx, you can easily find your post, track
threads, cross-post, and sort by date, poster's name, watched threads or
subject.

Not sure how? It's easy:
How to Configure OEx for Internet News
http://support.microsoft.com/?id=171164

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft MVP - Windows Server Directory Services
Microsoft Certified Trainer
Assimilation Imminent. Resistance is Futile.
Infinite Diversities in Infinite Combinations.
=================================


.



Relevant Pages

  • Re: DNS Redesign Issue
    ... -Using DNS console you can right-click the zone and export to a File, ... -To export a Zone and import that Zone in another DNS Server you need to use ... Create a child zone dallas on the DNS server in the child domain ...
    (microsoft.public.windows.server.dns)
  • Re: Unable to Raise Domain Functional Level
    ... Check if this server is deleted, and if so clean up this DCs ... The same error always appears regardless of which DC in the child domain I ... The Root domain is an AD integrated DNS zone. ...
    (microsoft.public.windows.server.migration)
  • Re: Active Directory Admin privileges
    ... The solution therefore as to come from MS and the best attempt at it is coming out of Redmond in Longhorn and is called Read Only DCs with delegated administrator. ... Forests, regardless of the number of domains, should have one small set of domain admins who are also enterprise admins who do management of all DCs. ... No one else should have any builtin rights such as account operator or server operator or even local logon onto Domain Controllers. ... Any time an admin in a child domain wanted access to sensitive material back at corp hq they could have gotten that access unless you were using some form of third party encryption that has no dependence on Windows security. ...
    (microsoft.public.security)
  • Re: gc doesnt show via nslookup
    ... results but when I do _msdcs.pri.ad.domain.com on the child domain, ... as a separate zone that replicates Forest Wide so it is ... available in all Domains and so all DCs can make their Netlogon ... registrations in the zone. ...
    (microsoft.public.windows.server.dns)
  • Re: ADI Zone on child and parent domains?
    ... delgation to only the child domain. ... Server 2003, there is the option of replicating DNS zones to all DCs in the ... the forest DC with an ADI zone for child.domain.com. ... My goal is to have a writable DNS zone for the child domain at both ...
    (microsoft.public.windows.server.dns)