Re: Overlapping Reverse Zone Files



Will wrote:
"Kevin D. Goodknecht Sr. [MVP]" <admin@xxxxxxxxxxxxxx> wrote in
message news:u50N45aTHHA.5016@xxxxxxxxxxxxxxxxxxxxxxx
When you say you have multiple subnets using 192.168.0.0, does that
mean these are on two separate networks?
If this is the case, it really makes no difference because you won't
be able to route between the two networks anyway.

Forest 1 contains these subnets:

192.168.11.0 / 24
192.168.15.0 / 24
192.168.16.0 / 24

Forest 2 contains this subnet:

192.168.21.0 / 24

All of these subnets are connected together by a firewall. They do
route between each other.


Or is it two forests sharing the same network?

No

So the proposal was the Forest 1 would have a reverse primary zone
that is AD integrated defined to be:

192.168.0.0 / 16

Forest 2 would have a reverse primary zone that is AD integrated
defined to be:

192.168.21.0 / 24

Forest 1 would have a secondary on the 192.168.21.0 that pulls from
Forest 2's DNS.

The above appears to work but leaves me a little uncomfortable only
because the two reverse zones have overlapping addresses in theory
(not in practice).

This post is a lot more clear about your actual network than your original
post.
But it still leaves big questions, having a zone named 168.192.in-addr.arpa.
is easier to overcome than having an actual 192.168/16 Network, the bigger
question is the Network a /16 network or a 192.168.0/24 network with a
192.168.x zone?
It is simple to add delegations to the 192.168.x zone for the 192.168.11.x,
192.168.15.x and 192.168.16.x zones. But you would have to create a
secondary of the 192.168.x zone on all DNS servers in the enterprize to make
it seamless.
In fact to make reverse lookups seamless across the enterprize ths would be
the way to go with one exception, even on the DNS where the Primary
192.168.x zone is, if it is a /24 network, you should add zone for the
192.168.0.x network, and a delegation for that zone.

So in clarification, all DNS servers should have:
192.168.x with delegations named 0, 11, 15 and 16 to the respective servers
with these zones:
192.168.0.x
192.168.11.x
192.168.15.x
192.168.16.x
The reasoning is that if each subnet is properly delegated, any one DNS
server can find any other reverse lookup, and allows each DNS server to have
proper authority over the zones they are responsible for the security of.
Oh, and Dynamic updates should be disallowed in the 192.168.x zone.
Also, reverse lookups are mostly irrelevent in Active Directory, but if
you're going to have them, make them seamless.

--
Best regards,
Kevin D. Goodknecht Sr. [MVP]
Hope This Helps
Send IM: http://www.icq.com/people/webmsg.php?to=296095728
===================================
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
===================================
http://www.lonestaramerica.com/
http://support.wftx.us/
http://message.wftx.us/
===================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
===================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
===================================


.



Relevant Pages

  • Re: Is this possable with exchange and no ISP
    ... What I would do is just setup email for the AD domain. ... follow the directions below and instead setup DNS in a new primary zone (and ... Create an MX record for the domain pointing to your Exchange server. ... > dc i create pointers and mx records for the 2 computers on their network. ...
    (microsoft.public.exchange.setup)
  • creating subzones with dnscmd
    ... I am trying to create a script to populate our new MS DNS servers, ... when you create a reverse zone, you only need to state the network part ... service will create the relevent subzones as needed. ...
    (microsoft.public.windows.server.dns)
  • Re: recursive DNS servers DDoS as a growing DDoS problem
    ... (list of trusted peers who can request your zone files) ... allow-query {locals;}; ... This lets anyone on your network, and others you might trust, full ... Copy the bind config fully so you have two copies. ...
    (Bugtraq)
  • Re: a records and pointers
    ... can you create and zone for a different domain on a different network ... server for private use so long as it never gets accessed publicly. ... >for the other email server that is on the other network. ... real domains or just test domains - even if test domains do they still ...
    (microsoft.public.windows.server.dns)
  • Re: .Net security for shared network driver
    ... > network driver, we also installed a security package on each desktop to ... > choose the Zone code group; within in the Zone we made Local Intranet ... If it has any dots, it is assumed to fall in the internet zone. ...
    (microsoft.public.dotnet.languages.csharp)