Solved

W2K AD DNS

Posted on 2004-04-22
10
238 Views
Last Modified: 2010-03-18
I need some help on DNS resolution in an AD Domain.  The scenario is I have a root domain and two second level domains i.e. root.local, us.root.local and eu.root.local.  I have been advised to install DNS only in the two child domains and have them be secondaries of each other.  With this setup I am unable to query host.us.root.local from a client in eu.root.local (and vice-versa) I believe due to the fact that the client resolver is set to only query using the primary and parent suffixes, meaning the suffix us.root.local would never be tried leading to no resolution.  I know I can add a list of domain suffixes, but it seem in Y2K this can only be done manually and we have too many machines.

To complicate things the DNS server in the child domain also need to be forwarders for external resolution.

I also know that the MS solution would be to have DNS installed in the root domain and delegate the child domains.  However I will come across the same problem described above.

Can someone advise what is the correct/best way to setup DNS in this scenario without relying on WINs please?

Thanksin advance
Richard
0
Comment
Question by:eggwhisk
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
10 Comments
 
LVL 9

Expert Comment

by:jamesreddy
ID: 10887855
Use Active Directory Integrated DNS.  Skip the primary and secondary stuff.  It's counter productive in a Win2K environment.  

Do you have DHCP enabled on the network?  If so you can set scope options to include the DNS addresses and suffixes for the additional DNS servers.  If everything is statically assigned, then I'm afraid you have no choice and you will have to change everything manually.

James
0
 

Author Comment

by:eggwhisk
ID: 10888042
Hi James,

I do not understand why AD integrated DNS would help this situation, can you expand please?

Yes, we do have DHCP, but under W2K there are not option for specifying more than one suffix to search.  This option is only available under W2003 GPO.

What do you think?

Thanks
Richard
0
 
LVL 9

Expert Comment

by:jamesreddy
ID: 10888135
Oh...you're right.  I've been on Win2K3 for a bit, and forgot about that.

In any event, AD DNS wouldn't neccessarily help in this situation...it helps all situations.  Just having a uniformed AD structure throughout the entire network has been beneficial in my experience.

OK.  DNS Suffix.  Perhaps you could create a script to specify them  Below is an example of a script that you could employ as a logon script that could set the DNS suffix of the remote machines.

http://www.noplan.com/Scriptings/dnssuffix.asp

And then the following link has some ways you can tweak the registry.  You can create a registry key then import it at the users' workstations, again, by running a logon script if you prefer.

http://support.microsoft.com/default.aspx?scid=kb;EN-US;178277

Maybe those will help you.

James
0
Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

 

Author Comment

by:eggwhisk
ID: 10888403
I really need the answer to my original question.  
0
 
LVL 31

Accepted Solution

by:
Gareth Gudger earned 250 total points
ID: 10890821
The only way I can see that would resolve your problem eggwhisk would be to make the Secondary DNS servers set to forward to the primary root DNS zone servers and have the root DNS servers forward to external DNS/ISP servers for outside name resolution.

Alternatively, you could also try adding your root DNS servers as the first forwarders in the list and your extenral ISPs DNS server (for external name resolution) as the secondary forwarders. Just make sure you internal root DNS server are the first servers to query.
0
 
LVL 9

Expert Comment

by:jamesreddy
ID: 10890915
I did answer the original question.  Those scripts can be used to add the DNS suffixes to your client machines.
0
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 10890987
I guess he really doesn't want to do it that way.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Greetings, Experts! First let me state that this website is top notch. I thoroughly enjoy the community that is shared here; those seeking help and those willing to sacrifice their time to help. It is fantastic. I am writing this article at th…
A common practice in small networks is making file sharing easy which works extremely well when intra-network security is not an issue. In essence, everyone, that is "Everyone", is given access to all of the shared files - often the entire C: drive …
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Suggested Courses
Course of the Month5 days, 16 hours left to enroll

626 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question