Question on AD-integrated DNS

should all of your DNS servers in AD be AD-integrated?

If i make them all AD integrated, I do not have to allow zone transfers because it happens
automatically right?


Also, what is the "typical" amount of Forward lookup zones a company has?  
thanks
dissolvedAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

cfairleyCommented:
Once you enable AD integration of DNS, the DNS records automatically get replicated to all other DCs.  That means that and DC can resolve queries, but does not mean that they can make updates.  The DNS service has to be installed on the DC for it to write DNS info.

Zone transfers will happen at normal replication times.

Usually you will have a forward lookup zone for each domain you have.  If you are going to host your root domain, then you will have one to two additional zones.  You will also want to have a reverse lookup zone to handle request for names based off of IP address.
0
dissolvedAuthor Commented:
"If you are going to host your root domain, then you will have one to two additional zones"

why is this?

Thanks! Great explanation by the way!
0
cfairleyCommented:
Thanks!

If the DNS name for your org will be microsoft.com, you will have a "." domain, "com", and "microsoft".  That's if you plan to host all of that yourself.  You will need forwarders to get requests from the outside world.  This is usually the setup for a private org.  A public org will just host the "microsoft" domain.
0
Cloud Class® Course: Microsoft Azure 2017

Azure has a changed a lot since it was originally introduce by adding new services and features. Do you know everything you need to about Azure? This course will teach you about the Azure App Service, monitoring and application insights, DevOps, and Team Services.

dissolvedAuthor Commented:
Wow, so microsoft.com requires 3 forward lookup zones??? (im confused)

  The "microsoft " one is the forward lookup zone for internal name resolution right? like
host a                  192.168.1.5

by the way, what do you mean by "host your own root domain?"

Thanks!
ps: new at this
0
cfairleyCommented:
If microsoft were a private org, they would have three zones.  The is explained in the link.

Yes.

I could explain further, but I'm sure I would make some mistakes along the way because it's pretty late and I'm actually removing a domain controller over VPN.  This DNS whitepaper is the best out there, I believe.  It will take a couple of days to digest.  Although, this is a must read for any IT professional.

http://www.microsoft.com/windows2000/techinfo/howitworks/communications/nameadrmgmt/w2kdns.asp
0
dissolvedAuthor Commented:
Hey cfairley, what is the purpose of adding DNS servers to the DNS tab. Here is a screen shot of some settings at work (had to blur it for confidentiality purposes, but it gets my point across)

Looks like severeal DNS severs are listed. Do they get listed automatically?

http://mvpbaseball.cc/dns-servers.jpg
0
dissolvedAuthor Commented:
0
cfairleyCommented:
The servers listed in the Name Servers tab are servers that are configured to be authoritative for the zone.  If you go to the Zone Transfers tab, you can choose to do zone transfers to only servers listed in the name servers tab.

Also, as a tech tip, you can click on the "?" near the "X".  Your mouse will turn into a "?" and click the box the servers are listed in or any other button or tab and it will tell you what it does.  When I first started using DNS, I used this feature on every option and basically learned DNS that way.
0
dissolvedAuthor Commented:
so all the servers listed are authorative for the forward lookup zone displayed? (we only have one forward lookup zone by the way). I'm guessing all DNS servers in AD are authorative if they all reside in the same domain?
Thanks!
0
dissolvedAuthor Commented:
by the way, whats the purpose of even listing your authorative DNS servers in the Name Servers tab if you arent going to be doing zone transfers anyway (all of our DNS servers are AD integrated)
0
cfairleyCommented:
If you were not able to list the autouratative DNS servers, you would not have the option to just transfer to them.  If you don't use the option to only transfer to DNS servers listed, you or someone could set up a DNS server as a secondary and pull records from the AD Integrated zone.  We use this to transfer to a secondary DNS in a NT4 domain.  If we turned on the option to only transfer to DNS servers listed, our scenario would not work.
0
dissolvedAuthor Commented:
So in a pure win2k environment (that uses AD-integrated DNS), you dont need to populate the NAME SERVER tab?
Looks like my place of employment is only

IF your DNS servers are all integrated, you do not need to transfer in between them right? AD replication does this? Am I correct?

thanks
0
cfairleyCommented:
Yes, you still need to populate the Name Server tab.  I think it does this automatically if it's AD integrated, I don't remember when I set it up.  I am looking for the exact answer of why it's needed.

You are right, you do not need to do a transfer, AD will take care of that.  It will not take care of any Primaries or Secondaries.
0
cfairleyCommented:
As of now, the only reason I am finding is that its need to restirct zone traffic to specific listed servers.  If I had my test lab running, I would take all the servers out of the list and see if they still update each other, which I'm sure they would.  Sorry I dont' have anything more concrete than that.  I'll send an update if I find something, even if it's after the question is closed.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
dissolvedAuthor Commented:
thanks!
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows 2000

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.