Solved

Move the primary DNS server

Posted on 2006-11-21
13
179 Views
Last Modified: 2010-04-13
I have windows 2000 DC which is also the DNS server. I have another domain controller.But the problem is that if the 1st DC is shutdown then users can't logon to the 2nd dc because the users can access the DNS servers.Any suggestions what I can do to resolve this issue.
0
Comment
Question by:life_j
13 Comments
 
LVL 48

Expert Comment

by:Jay_Jay70
Comment Utility
have you got the second DNS server specified in the TCPIP settings?
0
 
LVL 7

Author Comment

by:life_j
Comment Utility
one our network their no 2nd DNS server.
On our Main DC with DNS we have the 2nd dns server in the tcp/ip settings but the 2nd dns server is the public dns server
0
 
LVL 28

Assisted Solution

by:Michael Pfister
Michael Pfister earned 150 total points
Comment Utility
Install the DNS server service on your 2nd DC. Make sure your DNS is Active Directory integrated. The second DNS should replicate with your primary DNS.
Configure your provider's DNS server under "Forwarders" in DNS, this makes sure requests for any internet domain get resoved by your providers public DNS server. Configure your clients and servers to use both local DNS servers.

Hope it helps,

Michael
0
 
LVL 48

Expert Comment

by:Jay_Jay70
Comment Utility
agreed, you should never have an ISP dns server in those settings...ever! :-)    You want forwarders and a second DNS server, just make your zones AD integrated, install DNS on second DC and watch it replicate, use that as a secondary
0
 
LVL 7

Author Comment

by:life_j
Comment Utility
Thanks, say if the first dc failed.Then the 2nd dns wouldn't be working because it won't be getting any updates from the primary.Can I convert the 2nd DNS server to the primary one.
0
 
LVL 48

Expert Comment

by:Jay_Jay70
Comment Utility
if you make the zones integrated then you wont have that issue....they are both primary in a manner of speaking
0
6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

 
LVL 95

Assisted Solution

by:Lee W, MVP
Lee W, MVP earned 150 total points
Comment Utility
Ideally, you'll use an Active Directory integrated DNS setting which means there is no "primary" DNS server as far as the records are concerned.  With an AD integrated DNS, the DNS records are stored in AD and replicated through that.  An update on one is automatic to the other.

In addition, something you said concerns me....
>On our Main DC with DNS we have the 2nd dns server in the tcp/ip
>settings but the 2nd dns server is the public dns server

This is wrong.  mpfister alluded to it but (just my opinion) was emphatic enough about it...

Active Directory uses DNS to resolve network requests, as you've seen.  If you have your servers or your clients misconfigured, then you could easily have logon issues and issues with other network services.  Make sure all your clients ONLY use the Windows DNS Server(s) and make sure your servers point to whichever server you want to "declare" is your primary... But no where, on your servers or your clients, should any system's network settings point to a DNS server outside your network.  

Note - your DNS Server Configuration, where it asks for DNS forwarders, can point to public DNS servers, but NOT the network settings.

Incidentally, using a "primary" private and a secondary public  DNS server can result in intermittent problems that you may otherwise have difficulty explaining/resolving.
0
 
LVL 7

Author Comment

by:life_j
Comment Utility


Just want confirm the below

Active Drirectory intergrated DNS does that mean that when I do  DC promo on the 2 server. I just choose to install a new DNS server with the same IP as the 2 DC. How does the replication happen.
Also you want me to remove the public DNS in the tcp/ip settings of our 1st DNS+DC server.
0
 
LVL 48

Accepted Solution

by:
Jay_Jay70 earned 200 total points
Comment Utility
Correct, when you run DCPROMO select the DNS option, that will replicate a DNS zone IF you have made the current one AD integrated, the replication occurs the same as AD replication occcurs..funny enough AD and DNS go hand in hand    **grin**

deffinitely remove that public DNS setting and add it as a forwarder.....give it around 20 mintues to kick in as it can take a while.....dont panic if you cannot resolve external sites straight off.....
0
 
LVL 7

Author Comment

by:life_j
Comment Utility
Thanks James

So this would make the 2 DNS servers work as independantly with up to date  information about the AD.Is that right
0
 
LVL 48

Expert Comment

by:Jay_Jay70
Comment Utility
Thats correct mate 2 DNS servers makes life much nicer
0
 
LVL 7

Author Comment

by:life_j
Comment Utility
Cheers Mate

I will split the points.
0
 
LVL 48

Expert Comment

by:Jay_Jay70
Comment Utility
No worries, have fun :)
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
In this step by step tutorial with screenshots, we will show you HOW TO: Enable SSH Remote Access on a VMware vSphere Hypervisor 6.5 (ESXi 6.5). This is important if you need to enable SSH remote access for additional troubleshooting of the ESXi hos…
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now