Solved

Microsoft DNS Delegation Zone

Posted on 2009-05-13
8
695 Views
Last Modified: 2012-05-06
Hi,
I have to Active Directory domains which are called:
domain1.local with 2 DNS servers dns11.domain1.local and dns12.domain1.local
and
domain2.local with 2 DNS servers dns21.domain2.local and dns22.domain2.local
I create in dns11.domain1.local a zone called domain2.local. On this new zone I create a new delegation which is pointing to dns21.domain2.local and dns22.domain2.local.
When I am using my client computer to ping machines from domain2.local those are not answering.
Mu delegation is not working, can you please help me with this.
Thank you.
0
Comment
Question by:BetfairRomania
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
8 Comments
 
LVL 71

Expert Comment

by:Chris Dent
ID: 24375239

> On this new zone I create a new delegation

Do you created something like sub.domain2.local in there?

From the sound of it you don't want to be using a Delegation here. You want to resolve names in domain2.local? Instead you want to use any of...

1. Conditional Forwarder
2. Stub Zone
3. Secondary Zone

Which is most appropriate depends a bit on the DNS server. Most are capable of 1, but Windows 2000 isn't.

Chris
0
 

Author Comment

by:BetfairRomania
ID: 24375311
Hi,
thank you for your answer.
What I really need is from my client computer when I run this commands ping -a 192.168.180.23 and this ping server1.domain2.local I need this machine called server1.domain2.local to respond.
I create in dns11.domain1.local a reverse lookup zone for 180.168.192 and also in this DNS server I create a forward lookup zone called domain2.local which i delegated to dns21.domain2.local.
Thank you.
0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 24375386

> ping -a 192.168.180.23

This is an entirely different matter. Ping -a attempts to resolve a name from the given IP address. That requires Reverse Lookup not Forward. Where is the Reverse Lookup Zone?

When you run "ping server1.domain2.local" the DNS server your client uses will need a way to find the records in domain2.local. This one comes to the next bit.

> delegated to dns21.domain2.local

Zones can only be delegated from a parent zone. To delegate domain2.local you would have to have a zone called "local.".

You cannot Delegate this and expect to be able to resolve names. You must use one of the three options I quoted above.

Chris
0
How Do You Stack Up Against Your Peers?

With today’s modern enterprise so dependent on digital infrastructures, the impact of major incidents has increased dramatically. Grab the report now to gain insight into how your organization ranks against your peers and learn best-in-class strategies to resolve incidents.

 

Author Comment

by:BetfairRomania
ID: 24375622
Hi,

> domain1.local
dns11.domain1.local and dns12.domain1.local

>domain2.local
dns21.domain1.local and dns22.domain2.local

What I need is:
> when you ping server1.domain2.local = 192.186.180.23
> when you ping -a 192.168.180.23 = server1.domain2.local

What I have done:
>in dns11.domain1.local and dns12.domain1.local I create a reverse lookup zone called 180.168.192
>in dns11.domain1.local and dns12.domain1.local I create a forward lookup zone colled domain2.local and from new delegation wizard I select dns21.domain2.local and dns22.domain2.local
>I create a new PTR record entry as 23  in reverse lookup zone called 180.168.192

Thank you.
0
 
LVL 71

Accepted Solution

by:
Chris Dent earned 125 total points
ID: 24375777

> in dns11.domain1.local and dns12.domain1.local I create a forward lookup
> zone colled domain2.local and from new delegation wizard I select
> dns21.domain2.local and dns22.domain2.local

So you have New Delegation. You clicked Next, then put what in the box that needs a value before you can continue?

You can only delegate responsibility for a zone from the Parent Zone. You cannot delegate on the same level.

Delete the "domain2.local" zone from the two servers on domain1.local then create a new Stub Zone as follows.

1. Right click and select New Zone click Next on the first page
2. Select Stub Zone and click Next
3. Enter the name domain2.local then click Next
4. Allow it to create a file with the default name then click Next
5. Enter the IP Addresses for dns21 and dns22. Click Next then Finish

No problems with the Reverse Lookup Zone.

Chris
0
 

Author Comment

by:BetfairRomania
ID: 24376672
HI,
in this way reverse is working only for DNS machine domain2.local (dns21 and dns22).
How can I make it  work  for all machine from domain2.local domain
Thank you.
0
 
LVL 71

Expert Comment

by:Chris Dent
ID: 24376711

Do both domains share the same IP range?

Are you wanting them to use Dynamic Updates to add themselves to the zone?

You might create a Secondary zone for the Reverse Lookup on the DNS servers in domain2.local.

Chris
0
 

Author Comment

by:BetfairRomania
ID: 24376881
Hi,
on both DNS servers from domain2.local I have a reverse lookup zone for all machines served by those DNS servers.
No this domains are using diffren IP range.
Thank you.
0

Featured Post

Resolve Critical IT Incidents Fast

If your data, services or processes become compromised, your organization can suffer damage in just minutes and how fast you communicate during a major IT incident is everything. Learn how to immediately identify incidents & best practices to resolve them quickly and effectively.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you have a multi-homed DNS setup in windows, you can have issues with connectivity to the server that hosts the DNS services (or even member servers of your domain if this same DNS server is a DC). This is because windows registers all of its IPs…
BIND is the most widely used Name Server. A Name Server is the one that translates a site name to it's IP address. There is a new bug in BIND (https://kb.isc.org/article/AA-01272), affecting all versions of BIND 9 from BIND 9.1.0 (inclusive) thro…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question