Re: AD DNS naming



In news:eBdIZZsTGHA.2276@xxxxxxxxxxxxxxxxxxxx,
SuperGumby [SBS MVP] <not@xxxxxxxxxxx> stated, which I commented on below:
G'day Ace,

Nice breakdown.

I suppose my main concerns stem from questions raised where the DNS
naming has been assumed ('it's asking for a DNS name, better give it
this one') rather than planned.

It probably means the person setting it up rather didn't really get into
researching it extensively or didn't attend classes on AD
design/immplementation. Common problem. As a trainer, I always recommend
such training, and I say this for their benefit, and not as a salesman,
because I'm not a salesman. There is much info to be learned and the
Microsoft MOC# 2279 (Implement and Troubleshoot) and # 2282 (Design) AD
courses are well worth attending.


If I juggle the info around somewhat I get 'considerations that
should influence your AD DNS name choice':
(in no particular order)
Security.
Considerations about what info from the DNS is exposed by the
different choices when implemented properly or improperly.
Name complexity.
we.dont.wanna.have.to.remember.something.like.this to access a
record. User considerations, the 'people' aspect. Some consideration
here for the 'machine' context.

Use WINS and/or make sure the name suffixes are set in teh search suffix, of
ensure proper delegation/forwarding in a design with a parent/child
relationship in a forest.

Name visibility.
How does resource availability differ inside vs outside the AD?

That will depend on your VPN software, as mentioned in my post. Cisco,
Netscreen, etc, VPN software is better suited. If using default Microsoft
software, may have some issues with name resolution, but not saying you
will.

Also, from other post, what differing visibility do I wish to
provide and is this dependent on the choice.

That depends on what visibility YOU want or are required to allow your
outside users in order to do their jobs with regards to access to the
internal resources.


Managability.
Does the choice influence the amount of work necessary to maintain
the system?

Once implemented, there shouldn't be any additional work, unless the
split-zone was chosen, then if you are using the IIS redirection as I
mentioned, it would need to implemented on any new DCs. Otherwise, I really
don't see any additional tasks, unless you change something.


I have to go play golf in a few minutes. It will give me time to
think about what other aspects I want to consider in the process of
choosing the name. I'll pop back in to see what else comes in.

Don't look at this as an elephant under a microscope. Look at the broad
ramifications and results that your users require to remain productive, and
what is easier to implement and maintain. Myself? I would either choose
..local (and make the appropriate changes for the Macs, if any), or a
delegated subdomain.


Cheers!

Ace


.



Relevant Pages

  • Re: Same internal and external domain name - safe?
    ... But there are a lot of considerations, ... Windows 2000 DNS Center: ... "Mark N." ... > I seem to remember that having your NT4 internal domain name the same as ...
    (microsoft.public.win2000.active_directory)
  • RE: exchange server cannot mount mailbox store
    ... What's the exact detailed DNS Events ... Type desired internal IP address of your SBS server. ... it will delete the reverse lookup zone if the zone no longer ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • RE: OWA fails to Authenticate with AD in SBS 2003 - Failure with O
    ... SInce altering the Server's DNS to reflect this - DHCP DNS - Server, Router, ... > be able to access the companyweb, please check the every domain user have ... > Microsoft CSS Online Newsgroup Support ... > This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: For Microsoft Partners and Customers Who Cant Download or Access
    ... Microsoft for msdn2.microsoft.com. ... "I use a NetGear firewall which gets the DNS ... use a static IP and set the DNS server addresses to the DNS ... access MSDN and MSDN downloads on at least 6 different PCs, ...
    (microsoft.public.dotnet.general)
  • RE: Remote Access Issue
    ... the DHCP server do not update the A record for the ... Click DNS ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)

Loading