Solved

Source of AD Integrated zone.

Posted on 2009-04-06
5
306 Views
Last Modified: 2012-05-06
In DNS server console which is also a Domain controller of ABC.com domain.
I see multiple zones with different names XYZ.com,TOT.com,etc.. and they are AD Integrated zones.
If I understand if there is XYZ.com AD integrated zone, that means there is a domain controller somewhere in the network that belongs to XYZ.com to which clients register the host A record.
My point is any AD integrated zone that show up in DNS console means that it's part of the forest or the domain, or it can be a different forest with a trust?

thanks

In DNS server console which is also a Domain controller of ABC.com domain.

I see multiple zones with different names XYZ.com,TOT.com,etc.. and they are AD Integrated zones.

If I understand if there is XYZ.com AD integrated zone, that means there is a domain controller somewhere in the network that belongs to XYZ.com to which clients register the host A record.

My point is any AD integrated zone that show up in DNS console means that it's part of the forest or the domain, or it can be a different forest with a trust?
 

thanks

Open in new window

0
Comment
Question by:jskfan
  • 3
  • 2
5 Comments
 
LVL 70

Expert Comment

by:Chris Dent
ID: 24078135

Your DCs will only be able to load AD Integrated Zones stored in the current domain.

There are three possible locations by default:

CN=MicrosoftDNS,CN=System,DC=yourdomain,DC=com
DC=DomainDNSZones,DC=yourdomain,DC=com
DC=ForestDNSZones,DC=yourdomain,DC=com

The first you can see in AD Users and Computers if you select View / Advanced Features then expand System and MicrosoftDNS.

DomainDNSZones exists for each domain in a forest. So a forest of domain.com, uk.domain.com and us.domain.com would have three versions of DomainDNSZones. They would be:

DC=DomainDNSZones,DC=domain,DC=com
DC=DomainDNSZones,DC=uk,DC=domain,DC=com
DC=DomainDNSZones,DC=us,DC=domain,DC=com

ForestDNSZones, as the name suggests, replicates to every DNS server in the forest and there's only one copy of it.

Both DomainDNSZones and ForestDNSZones can be accessed using ADSIEdit, but you have to create a manual connection (they won't show up anywhere by default).

In addition to those it is possible to configure additional partitions for DNS. However, they are also restricted to replication within the current forest (although you can choose where by only enlisting certain DCs).

Chris
0
 

Author Comment

by:jskfan
ID: 24085239
so the main condition to have many AD integrated zone in DNS(Active Directory), is either the domains belong to one forest, or as I think at least there should be a trust between 2 forest?
0
 
LVL 70

Expert Comment

by:Chris Dent
ID: 24085288

I'm not quite with you there I'm afraid. The trust is not relevant to the DNS service, or at least not in the bounds of this discussion, because DNS cannot load data from a trusted directory; only files or a local directory.

Making a zone AD Integrated is simply a way of storing the zone data, the zone stored there doesn't necessarily have to have anything at all to do with Active Directory.

Chris
0
 

Author Comment

by:jskfan
ID: 24087001
<<<Making a zone AD Integrated is simply a way of storing the zone data, the zone stored there doesn't necessarily have to have anything at all to do with Active Directory.>>>>
I agree if it's a primary or secondary zone it has nothing all to do with Active Directory.

If I understand what you are saying, for instance our AD domain is ABC.com that's all we have; one domain
you can create AD Integrated zones for domains that don't have any relation with ABC.com, and those zones will be stored in AD database. I agree with you here.
But those AD integrated zones(not the ABC.com) can't have their new records created if we don't create them manually.

On your example above, the domains yourdomain.com,uk.yourdomain.com,etc... you mentioned are contiguous, in that case AD integrated zones get updated with whatever computers are on that domain.


0
 
LVL 70

Accepted Solution

by:
Chris Dent earned 500 total points
ID: 24087230

> But those AD integrated zones(not the ABC.com) can't have their new records created if
> we don't create them manually.

"Can't" is not true. That they won't is, but only because that's what the configuration says for them to do.

If you were to use those zones for AD (despite the name not matching) then you're looking at a concept called Disjointed Namespaces. The steps for it are discussed here:

http://technet.microsoft.com/ja-jp/library/cc731929.aspx

That would allow an client machine to update a DNS namespace that doesn't match it's domain membership.

Of course, dynamic DNS is not specific to MS, although the version of Secure updates is. Any MS client can dynamically register records, as can many / most other operating systems if given appropriate configuration when using Non-Secure Updates. The client doesn't have to be a member of the domain for that, but they do have to send an appropriate update request or it will be ignored / rejected.

Chris
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
DHCP via Two Domains -- one network ? 3 110
Active Directory Replication & DFS Not Working 10 63
Guest VLAN not syncing email 13 30
Office365 login in Page not accessible. 3 39
This article is intended as an extension of a blog on Aging and Scavenging by the MS Enterprise Networking Team. In brief, Scavenging is used as follows: Each record in a zone which has been dynamically registered with an MS DNS Server will have…
I will assume you are running a non-server version of some sort of Windows throughout this article. There are many flavors of Windows since Windows Server 2000 - 2008, XP Home & Pro, Vista Home & Pro, and Windows 7 Starter, Home, Pro, Ultimate, etc.…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This is a video that shows how the OnPage alerts system integrates into ConnectWise, how a trigger is set, how a page is sent via the trigger, and how the SENT, DELIVERED, READ & REPLIED receipts get entered into the internal tab of the ConnectWise …

948 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now