• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 204
  • Last Modified:

understanding DNS

1-What's the benefits of using stub zone over secondary zone?
-What the difference between creating a stub zone and making it AD integrated or just primary?
-If I created a stub zone, can I right-click and created host records in it just like any other zone?

2-what protocol or machanism that DNS uses to transfer primary to secondary zone, or AD Integrated to secondary zone, Does it use RPC, KCC,etc..?
3-Which scavenging setting will override, the one set up at the DNS server level or at the zone level?
4-what 's the difference between the DNS zone of the child domain created through the DC promo wizard and the DNS zone of the child domain created at the DNS server in the parent domain by right-clicking and selecting New Domain?
  • 2
  • 2
1 Solution
Chris DentPowerShell DeveloperCommented:

1. Stub is much lighter than a Secondary and is much more like a Conditional Forwarder than a Secondary Zone.

Advantages of a Stub Zone are:

 - Does not require permission to Transfer a zone
 - Is able to adapt if the Name Server records for a zone change

Disadvantages of a Stub Zone are:

 - Requires the servers listed in the NS records for the zone to answer the request

When comparing that to a Secondary zone, the server hosting the Secondary zone answers the request for the client directly. Secondary Zones allow for a much greater degree of fault tolerance.

2. It uses a Zone Transfer request on TCP Port 53. The operation is entirely within DNS, it doesn't touch on any external protocols or applications (such as RPC, or the KCC, etc).

The actual operation of Zone Transfers is discussed in RFC 1034, then again in  RFC 1995 which discusses Incremental Zone Transfers (changes only rather than entire zones):


3. You can set the Aging Defaults at the server level, however those are the defaults only. The Aging properties set on the zone itself take precedence over the server defaults.

4. There shouldn't be any difference at all. Both just create containers for the child domain to store data in DNS.

jskfanAuthor Commented:
1- so resolving request through stub zone is much more slower, because it needs to connect the servers in the NS tab.
can you right-click and created host records in it just like any other zone?
Does not require permission to Transfer a zone, what does that mean?

Chris DentPowerShell DeveloperCommented:

It can be, it depends how quickly the authoritative servers respond. Do bear in mind that responses from that system will be cached for the duration of the record TTL, so it may not be much of a reduction in speed.

> can you right-click and created host records in it just like any other zone?

No... Stub Zones only contain NS records. They should be read-only.

> Does not require permission to Transfer a zone, what does that mean?

To Transfer a Zone you must have explicit permission to perform the action on the Primary server. By default that isn't permitted.

Stub Zones only take the NS Records rather than the full zone so don't require that right (because we can easily query the NS records for a zone) making them a useful alternative to Conditional Forwarders.

jskfanAuthor Commented:
Thanks Chris for the clarification!
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Upgrade your Question Security!

Your question, your audience. Choose who sees your identity—and your question—with question security.

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now