Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 323
  • Last Modified:

Domain Controller DNS Problem

I've just promoted a W2K Adv. Server that is a router between a DMZ and a private zone (DMZ is internet routable, private is 192.168.X.X) to a Domain Controller without installing a DNS Service on that server since I have one in the DMZ. The domain controller now claims that there is no DNS available for the domain which results in Netlogon problems and DHCP - dynamic DNS update problems. This despite the fact that the newly created DC has DNS records on the DMZ interface and the DHCP server also publishes these NS records to the DHCP Clients.

Do I have to install a DNS on the Domain Controller and delegate a zone for this so that the DC is happy?

1 Solution
There are lots of issues that result from Domain Controllers that are multi-homed.  This can cause all kinds of name resolution issues.

I would start by using a different machine from your router as your DC..

WolfgangBaeckAuthor Commented:
Thanks, I know the warning but I'm at the end of my hardware.
Obviously - make sure your DNS zone is allowing dynamic updates...

Is this the only DC?

If not - you MAY be able to get away with making your existing zone AD integrated, and installing DNS on the DC in question..  You would then point the DNS resolver (of this DC) to the internal IP of the DC.

If it is - Check that the DNS resolves (TCP/IP settings) are pointing to the internal IP address of the host, and reboot...

Do you see the _tcp, _gc etc entries in your DNS zone?  They should have been automatically created when you promoted (after a reboot) if your DNS is setup correctly..

I tend to make it standard practice to have the DNS zone that is used for the AD 'AD Integrated' - and install the DNS service on all DC's.. (unless you have a unix-based DNS in the mix...) - but then I've never used a multi-homed box for a DC..
Evaluating UTMs? Here's what you need to know!

Evaluating a UTM appliance and vendor can prove to be an overwhelming exercise.  How can you make sure that you're getting the security that your organization needs without breaking the bank? Check out our UTM Buyer's Guide for more information on what you should be looking for!

WolfgangBaeckAuthor Commented:

The issue was that I didn't have the dynamic update of the DNS enabled when the DC was created. From there on, nothing helped. I needed to demote and promote again. It works. No problem with being a router at the same time as of now.
The nice part of being a router to the DMZ is that I can use Terminal Client to administer not only the DC but all computers in the domain as well.

This old question needs to be finalized -- accept an answer, split points, or get a refund.  For information on your options, please click here-> http:/help/closing.jsp#1 
Post your closing recommendations!  No comment means you don't care.
No comment has been added lately, so it's time to clean up this TA.
I will leave the following recommendation for this question in the Cleanup topic area:

Accept: mwareman {http:#8233011}

Please leave any comments here within the next seven days.

Julian Crawford
EE Cleanup Volunteer

Featured Post

Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now