Re: Overlapping Reverse Zone Files
- From: "Will" <westes-usc@xxxxxxxxxxxxxx>
- Date: Sun, 11 Feb 2007 14:46:56 -0800
"Kevin D. Goodknecht Sr. [MVP]" <admin@xxxxxxxxxxxxxx> wrote in message
news:uKQvq4gTHHA.4844@xxxxxxxxxxxxxxxxxxxxxxx
But it still leaves big questions, having a zone named168.192.in-addr.arpa.
is easier to overcome than having an actual 192.168/16 Network, the bigger
question is the Network a /16 network or a 192.168.0/24 network with a
192.168.x zone?
The forest I am calling F1 is compromised of many non-overlapping
192.168.x.0 / 24 subnets. The reverse zone file for F1 is AD integrated
and is a 192.168.x.zone. I realize that is a hack, but it is a really
convenient thing as opposed to having to create many separate reverse zone
files that are at the proper size for the subnets they map.
It is simple to add delegations to the 192.168.x zone for the192.168.11.x,
192.168.15.x and 192.168.16.x zones. But you would have to create amake
secondary of the 192.168.x zone on all DNS servers in the enterprize to
it seamless.
Not sure what you mean by adding delegations. So far I have just created
the large /16 zone file and AD is automatically placing into it any matching
IP on its own. I never configured it for specific subnets. Should I?
Don't worry about secondaries for now. I'm trying focus in and understand
the situation on the AD integrated DNS servers for the F1 forest. And the
thing that is causing some discomfort is that the Forest 2 contains this
subnet 192.168.21.0 / 24 which is implemented as a secondary reverse zone in
F1 forest. So in theory some machine in F1 could accidentally be given a
192.168.21.x address and then you would have a weird situation where two
reverse zone files might contain the same /24 subnet. How does AD resolve
that conflict? Will it raise an error, or will one of the zones silently
"win"?
In fact to make reverse lookups seamless across the enterprize ths wouldbe
the way to go with one exception, even on the DNS where the Primaryservers
192.168.x zone is, if it is a /24 network, you should add zone for the
192.168.0.x network, and a delegation for that zone.
So in clarification, all DNS servers should have:
192.168.x with delegations named 0, 11, 15 and 16 to the respective
with these zones:have
192.168.0.x
192.168.11.x
192.168.15.x
192.168.16.x
The reasoning is that if each subnet is properly delegated, any one DNS
server can find any other reverse lookup, and allows each DNS server to
proper authority over the zones they are responsible for the security of.
Oh, and Dynamic updates should be disallowed in the 192.168.x zone.
Also, reverse lookups are mostly irrelevent in Active Directory, but if
you're going to have them, make them seamless.
I think you are describing a huge environment, one where each subnet might
be in a different building or a different city, each of which might have
their own domain or domain controller. That's not our case at all. We
are small and I simply like to use lots of subnets off a firewall as a way
to isolate traffic flows and allow tighter control of security. So in many
ways our environment is highly trivial, and I'm simply trying to understand
how to deal with the overlap of a single /24 subnet that is not owned by the
F1 forest.
Are you suggesting to have the F2 /24 subnet exist within the F1 forest
reverse zone, and use delegation as a way to pull it as a secondary from the
F2 forest? If yes, how do I actually do that? I have no experience with
delegation of that sort.
--
Will
.
- Follow-Ups:
- Re: Overlapping Reverse Zone Files
- From: Herb Martin
- Re: Overlapping Reverse Zone Files
- References:
- Overlapping Reverse Zone Files
- From: Will
- Re: Overlapping Reverse Zone Files
- From: Kevin D. Goodknecht Sr. [MVP]
- Re: Overlapping Reverse Zone Files
- From: Will
- Re: Overlapping Reverse Zone Files
- From: Kevin D. Goodknecht Sr. [MVP]
- Overlapping Reverse Zone Files
- Prev by Date: Re: Unable to connect to a share
- Next by Date: Re: Overlapping Reverse Zone Files
- Previous by thread: Re: Overlapping Reverse Zone Files
- Next by thread: Re: Overlapping Reverse Zone Files
- Index(es):
Relevant Pages
|