?
Solved

Source of AD Integrated zone.

Posted on 2009-04-06
5
Medium Priority
?
315 Views
Last Modified: 2012-05-06
In DNS server console which is also a Domain controller of ABC.com domain.
I see multiple zones with different names XYZ.com,TOT.com,etc.. and they are AD Integrated zones.
If I understand if there is XYZ.com AD integrated zone, that means there is a domain controller somewhere in the network that belongs to XYZ.com to which clients register the host A record.
My point is any AD integrated zone that show up in DNS console means that it's part of the forest or the domain, or it can be a different forest with a trust?

thanks

In DNS server console which is also a Domain controller of ABC.com domain.
I see multiple zones with different names XYZ.com,TOT.com,etc.. and they are AD Integrated zones.
If I understand if there is XYZ.com AD integrated zone, that means there is a domain controller somewhere in the network that belongs to XYZ.com to which clients register the host A record.
My point is any AD integrated zone that show up in DNS console means that it's part of the forest or the domain, or it can be a different forest with a trust?
 
thanks

Open in new window

0
Comment
Question by:jskfan
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 71

Expert Comment

by:Chris Dent
ID: 24078135

Your DCs will only be able to load AD Integrated Zones stored in the current domain.

There are three possible locations by default:

CN=MicrosoftDNS,CN=System,DC=yourdomain,DC=com
DC=DomainDNSZones,DC=yourdomain,DC=com
DC=ForestDNSZones,DC=yourdomain,DC=com

The first you can see in AD Users and Computers if you select View / Advanced Features then expand System and MicrosoftDNS.

DomainDNSZones exists for each domain in a forest. So a forest of domain.com, uk.domain.com and us.domain.com would have three versions of DomainDNSZones. They would be:

DC=DomainDNSZones,DC=domain,DC=com
DC=DomainDNSZones,DC=uk,DC=domain,DC=com
DC=DomainDNSZones,DC=us,DC=domain,DC=com

ForestDNSZones, as the name suggests, replicates to every DNS server in the forest and there's only one copy of it.

Both DomainDNSZones and ForestDNSZones can be accessed using ADSIEdit, but you have to create a manual connection (they won't show up anywhere by default).

In addition to those it is possible to configure additional partitions for DNS. However, they are also restricted to replication within the current forest (although you can choose where by only enlisting certain DCs).

Chris
0
 

Author Comment

by:jskfan
ID: 24085239
so the main condition to have many AD integrated zone in DNS(Active Directory), is either the domains belong to one forest, or as I think at least there should be a trust between 2 forest?
0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 24085288

I'm not quite with you there I'm afraid. The trust is not relevant to the DNS service, or at least not in the bounds of this discussion, because DNS cannot load data from a trusted directory; only files or a local directory.

Making a zone AD Integrated is simply a way of storing the zone data, the zone stored there doesn't necessarily have to have anything at all to do with Active Directory.

Chris
0
 

Author Comment

by:jskfan
ID: 24087001
<<<Making a zone AD Integrated is simply a way of storing the zone data, the zone stored there doesn't necessarily have to have anything at all to do with Active Directory.>>>>
I agree if it's a primary or secondary zone it has nothing all to do with Active Directory.

If I understand what you are saying, for instance our AD domain is ABC.com that's all we have; one domain
you can create AD Integrated zones for domains that don't have any relation with ABC.com, and those zones will be stored in AD database. I agree with you here.
But those AD integrated zones(not the ABC.com) can't have their new records created if we don't create them manually.

On your example above, the domains yourdomain.com,uk.yourdomain.com,etc... you mentioned are contiguous, in that case AD integrated zones get updated with whatever computers are on that domain.


0
 
LVL 71

Accepted Solution

by:
Chris Dent earned 2000 total points
ID: 24087230

> But those AD integrated zones(not the ABC.com) can't have their new records created if
> we don't create them manually.

"Can't" is not true. That they won't is, but only because that's what the configuration says for them to do.

If you were to use those zones for AD (despite the name not matching) then you're looking at a concept called Disjointed Namespaces. The steps for it are discussed here:

http://technet.microsoft.com/ja-jp/library/cc731929.aspx

That would allow an client machine to update a DNS namespace that doesn't match it's domain membership.

Of course, dynamic DNS is not specific to MS, although the version of Secure updates is. Any MS client can dynamically register records, as can many / most other operating systems if given appropriate configuration when using Non-Secure Updates. The client doesn't have to be a member of the domain for that, but they do have to send an appropriate update request or it will be ignored / rejected.

Chris
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

One of the most often confused topics in the area DNS is the idea of GLUE records. Specifically, what they are, when they are needed, when they are provided, and how they are created. First, WHAT IS GLUE? To understand GLUE, you must first under…
I wrote this article to explain some important DNS concepts that should be known to avoid some typical configuration errors I often see in forums. I assume that what is described here is the typical behavior of Microsoft DNS client. I don't know …
This tutorial will teach you the special effect of super speed similar to the fictional character Wally West aka "The Flash" After Shake : http://www.videocopilot.net/presets/after_shake/ All lightning effects with instructions : http://www.mediaf…
In this video, Percona Solution Engineer Dimitri Vanoverbeke discusses why you want to use at least three nodes in a database cluster. To discuss how Percona Consulting can help with your design and architecture needs for your database and infras…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question