Re: Creating a new Zone in DNS



What do I need to do then? I only have one zone in DNS which is a diffent Domain name to this external one we use. Do I need to create a new primary zone?



"Herb Martin" <news@xxxxxxxxxxxxxx> wrote in message news:OgN0RMGzIHA.4040@xxxxxxxxxxxxxxxxxxxxxxx

"Cyborg" <apollo13@xxxxxxxxxxxxxx> wrote in message news:234C796B-1CAD-47E7-ACBC-1087FB72742C@xxxxxxxxxxxxxxxx
Hi, we only have one forward lookup zone for our Active Directory domain, it's all Windows 2003 Native. Now we have many web servers on our DMZ (on our Cisco firewall) that external customers get to. They use addresses like ftp.domain.co.uk and webmail.domain.co.uk etc but my internal users can't get to these as the domain names resolve to external IP's on the firewall.

If you use the same Domain names (not addresses) internally and externally
for your zones then YOU must manually add the external record names
and address to your internal zone.

Such is termed "Shadow DNS".

My internal users however can get to these my using the private IP address of these server, so I thought is it possible to create a new zone called doamin.co.uk and then create ftp.domain.co.uk etc to point to the private IP address, so everyone is use the same FQDN?

Nice thing is when you do that extra manual work you can choose to give
internal users the internal or the external address for them, as appropriate.




.



Relevant Pages

  • Re: Resolving internal and external DNS records
    ... > Our firewall will not allow our internal computers to resolve our external ... > So if my internal users type in www.aaa.com, ... If you don't actually have a Shadow DNS setup then ... you need to add a NEW version of your zone externally. ...
    (microsoft.public.win2000.dns)
  • RE: AD Design
    ... I would like to clarify that external DNS is already hosted by ISP, ... Internal DNS which is used by only by internal users and has a forwarder ... Since there is already a zone for "mydomain.com". ... A delegation "corp" on the same server. ...
    (microsoft.public.windows.server.migration)
  • Re: Server Access
    ... internal users as server1.company.co.za. ... Local DNS, create a forward zone called company.co.za inside that zone create an A record for server1 that points to 172.16.1.33.2? ... Make sure that your users are using that internal DNS server. ...
    (comp.dcom.sys.cisco)
  • Re: Basic concept of AD and DNS
    ... have a different zone for internal users - the one that AD is using - you ... in which case you also need an external zone. ... Microsoft MVP - Windows Server - Directory Services ... Prev by Date: ...
    (microsoft.public.windows.server.active_directory)
  • RE: exchange server cannot mount mailbox store
    ... What's the exact detailed DNS Events ... Type desired internal IP address of your SBS server. ... it will delete the reverse lookup zone if the zone no longer ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)

Loading