DNS Child domain and AD configuration



I have a relatively Simple AD setup that we are in the process of setting up
and I would like some DNS related info please.

My company is expanding so we have to setup a new AD structure that will
allow for our once separate branches (about 200 people in 9
branches/different states/provinces) to probably connect into our Network.

Now Our current plan is as follows

Server 2003 Standard x64 as default dc's 2 GB memory hardware based onboard
HD MIRRORING.

Create Root Domain

Corp.company.local
=============


Setup two Child domains

HQ.corp.company.local and Branches.corp.company.local
============== ===================

This is being planed ahead so we can add the branches.company.local domain
at some later stage.

But we want to configure the setup as simple as possible so it does not need
allot of changing when/if our branches get joined and is easily maintainable
do to shortage of people that can administer this I.e 2 of us. (The reason we
are going the whole Root ;child is the info given in the branch setup
whitepaper/reference document Microsoft has made available i.e. keeping
replication traffic and dns requests down over very expensive slow wan links.)

Now in the process of setting up the new root and first child domains
everything has gone relatively smoothly so far with the rollout of a test
root forest.

All DNS updates reverse lookups etc work properly.

the snag that has now come up is the 1st child domain HQ.corp.company.local
(To test we want to make out 1st child as near as possible to the
configuration of how our branch sites will be setup. (I.e DNS requests will
be kept to the local child domain and only forwarded outside the child domain
for internet names or root Domain/forest server Name resolution. Meaning we
want to setup a DC1.hq.corp.company.local that will handle all the DNS and ad
requests inside the HQ child domain etc.)

Now I would like some in depth info as well as some recommendations please.

Recommendations: on how to keep the dns request in the child domain HQ; what
is better a stub record or delegate approach?

More in depth info on when the child domain dc is setup should a delegation
record be created in the root domain first and then DNS be setup first on the
child domain dc followed by AD.

Or should the delegate record be setup in the root domain followed by AD
creation on dc in the child domain DC then dns?

OR AD first in dc of child domain then dns then delegate.(If AD is setup
first everything seems to work fine but dns records are added as normal to
the ROOT dc's and dns requests are sent to root DC's.)

Thank you ahead of time and Please when replying as much info as possible
I'm new to this
.



Relevant Pages

  • Re: urgent-DNS forwarder problem
    ... There is a firewall between my DCs and the root domain which I'm a little ... Using nslookup I've tried connecting to DNS servers in domains on the other ... >> I've recently inherited a child domain containing 4 DCs that is part ... > forwarder to go to the parent DNS. ...
    (microsoft.public.windows.server.dns)
  • =?UTF-8?B?UmU6IFByb2dyYW1taWNhbGx5IHF1ZXJ5aW5nIHRoZSBnbG9iYWwgY2E=?= =?UTF-8?B?dGFsb2cg4oCTI
    ... The one exception would be if you had a root, child1, child2 and you wanted to connect to child2 from child1 then kerberos in the backend would route up through root and back down to child2 for auth. ... I will forget about WinNT as should everyone else who is dealing with AD. LDAP simply tells you to use the LDAP protocol, GC, tells you to use the LDAP protocol over port 3268. ... I believe that becomes "connect to LDAP port 3268 on any machine returned by the dns query domainname.com" but I would have to do a network trace to be positive. ... Binding to a GC in a child domain from a child domain does not rely on the presence of a DC in the root domain. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Trust between child and domain broken
    ... Does the root DNS delegate to the child or in some other ... > And, when I tried to demote the child domain, it prompted: ...
    (microsoft.public.windows.server.dns)
  • Re: Trust between child and domain broken
    ... The DNS both domain names of AD ... no forwarder configured for child and root DC ... And, when I tried to demote the child domain, it prompted: ... Install and configure DNS forward lookup zone and reverse lookup zone and ...
    (microsoft.public.windows.server.dns)
  • Re: basics: dns for a subdomain
    ... Tim Moor stated, ... the one and only dc hosts the dns for this domain. ... The in the child domain controller's DNS ... setup a forwarder to the parent. ...
    (microsoft.public.win2000.dns)

Loading