Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

2 dc's one resolves a domain trust the other will not resolve the trust but resolves the internal domain

Posted on 2010-08-16
12
Medium Priority
?
478 Views
Last Modified: 2012-05-10
I have inherited a network which has a domain, abc.local which has two dc's one on one subnet .60.1 and.62.1on another.  These two dc's reslove internally just fine.  DC 1 resolves a domain trust for can.com.  It resolves perfectly.  DC 2 cannot resolve or ping the domain trust.  How do I configure dns to resolve can.com on dc2?
0
Comment
Question by:Steely
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 5
12 Comments
 
LVL 6

Expert Comment

by:nettek0300
ID: 33451507
I would check the following:

1. Verify that the DNS IP address for can.corn is set in the IP settings of DC2.
2. Verify that the 62.X network has access to the can.corn domain and that it has a route set up in the router to get to that IP.

If I am reading the above correctly, DC1 houses the DNS for both domains.  If that is the case, is DC2 using DC1 as the DNS server, or is it using itself?  You should be able to make DC2 a secondary DNS server for the second domain.
0
 

Author Comment

by:Steely
ID: 33451597
DC1 houses the main domain.  DC2 is connected via point to point connection from another location.  I have DC1 and DC2 dns servers as name server authorities.  DC2 is using itself as DNS server.  It is also set to use DC1 as secondary dns.  I have a secondary server on DC1's subnet as well. Should the 62.x dc use the 61.x as the primary dns server?  
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 33452043
You should configure DNS conditional forwarding on your DNS servers. Do you know how to do that or need help?

NIC configuration queries first DNS entry. When it doesn't reply then it queries second entry. To be able fully query both domains, you need to configure conditional forwarding (2003) or forwarders (2008) to query proper DNS server.
0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 

Author Comment

by:Steely
ID: 33454905
Ok so I need to configure conditional forwarders from both subnets dns servers to the trusted domain and have the trusted domain set conditional forwarders for both subnets 61.x and 62.x?  Could you elaborate?
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 33455016
in one domain DNS server you have to set forwarder to other domain's DNS and reverse. So let's say you have 2 domains

testenv.local 192.168.1.1 DNS
mynet.org 172.16.5.5 DNS

on testenv you have to set in forwarders mynet.org with 172.16.5.5 IP
on mynet.org you have to set in forwarders testenv.local wit 192.168.1. IP

now each query will be redirected to proper DNS sever
0
 

Author Comment

by:Steely
ID: 33455177
Are conditional forwarders different from creating a forward lookup zones?  I am using windows server 2003 dns servers.  
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 33455255
yes, forward lookup one is a zone which contains all host records for particular zone. It is authoritative zone. Forwarder is only info about DNS IP address where you can find info about forward lookup zone. it doesn't have records. it is non-authoritative query.

Please readthis article
http://www.windowsnetworking.com/articles_tutorials/DNS_Conditional_Forwarding_in_Windows_Server_2003.html

and this one

http://www.blurtit.com/q968828.html
0
 

Author Comment

by:Steely
ID: 33455443
Great.  I setup the conditional forwarders from DNS server 62.x and also 610.x for abc.com with abc.com IP address.  One more question is the name servers tab.  names servers are authoratative servers correct.  Should both of my can.local dns servers be in the names servers tab even though they are at two different locations under two seperate subnets?
0
 

Author Comment

by:Steely
ID: 33455469
 Do I also need to have forwarders set on the trusted domain to both subnets in my local domain?  Also, how long does the conditional forwarders take to take effect
0
 
LVL 39

Accepted Solution

by:
Krzysztof Pytko earned 2000 total points
ID: 33461840
Conditional forwarders work after you click "Apply" button. Name servers is a list of DNS server hosting your DNS zone (it is also used in zone transfer process for secondary and stub zones). So the answer for your question "hould both of my can.local dns servers be in the names servers tab.." is no. The don't need to be added there. You use conditional forwarding for DNS insted of secondary zone transfer to different domain. They shouldn't be there for security reasons.
0
 

Author Closing Comment

by:Steely
ID: 33484832
Thnaks for your expertise.
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 33492335
You're welcome
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
How to deal with a specific error when using the Enable-RemoteMailbox cmdlet to create a mailbox in the cloud-based service, for an existing user in an on-premises Active Directory.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question