DNS design questions



Good Morning,

We're currently at the beginning of an eDir to AD migration. We currently run DNS on linux. We've created our AD structure and enabled a DNS zone for our AD domain. Now we'd like to move our public DNS server to Windows. I'm debating whether or not to integrate our public DNS records with AD. I very much like the benefits of having DNS stored and replicated in AD however I'm concerned about exposing one of our DCs to the general public (this is a medium size college campus). I was thinking about integrating DNS on our two Domain controllers then having one member server, totally dedicated to DNS, run a secondary copy of the zone and having it exposed to the internet. As far as the "world" is concerned, this would be our primary DNS server. Would this work? Is it overkill? Is there an issue with exposing one of our DCs to the internet for DNS services? If so, what is the best way to mitigate those risks?

Thanks,

Travis
.



Relevant Pages

  • Re: Replication issues
    ... I wanted to say Zone Transfers not Zone Forwarding. ... AD-Integrated DNS does not do zone transfers between the ... your DNS server will bypass ...
    (microsoft.public.windows.server.active_directory)
  • Re: Servers hang on boot
    ... The last DC at that site (not a DNS server). ... EventID: 0x00000457 ... (Event String could not be retrieved) ...
    (microsoft.public.windows.server.networking)
  • Re: DNS Redesign Issue
    ... set the new child domain DNS server as primary for the domain controllers? ... -If you are going to create a new AD Integrated Zone in each child domain, ...
    (microsoft.public.windows.server.dns)
  • Re: Internet connection wizard
    ... turn on DHCP on the workstation. ... Connection-specific DNS Suffix. ... calling CNetCommit::ValidateRouterConnectionProperties. ... Call to Reading preferred DNS server IP returned ok. ...
    (microsoft.public.windows.server.sbs)
  • Re: RPC Endpoint Mapper Error
    ... Event Type: Warning ... I checked DNS entries with articles from Microsoft on ... PASS - All the DNS entries for DC are registered on DNS server ... List of NetBt transports currently bound to the Redir ...
    (microsoft.public.win2000.active_directory)

Loading