Solved

Domain DNS and Firewall DNS

Posted on 2010-08-30
7
423 Views
Last Modified: 2012-05-10
I have a win2003svr domain controller. I also have a firewall (Kerio Control).  My question is regarding the configuration of the DNS from the AD controller and the Kerio Control.
0
Comment
Question by:benjalamelami
  • 3
  • 2
  • 2
7 Comments
 
LVL 8

Expert Comment

by:sstone55423
Comment Utility
Use AD, and do not use the Firewall DNS.  
Within Windows 2003 server, DNS can integrate with DHCP and work more effectively.  You should have the WIndwos DNS use root hints to look up secondary/recursive records, rather than specifying the firewall or ISP DNS for outside.  This offers better reliability.  Alyernatively, you could use the ISP DNS which might give you fatser lookup speed, but be less reliable.
0
 
LVL 4

Expert Comment

by:sire_harvey
Comment Utility
Check out this article about windows 2003 DNS

http://support.microsoft.com/kb/323380

cheers
0
 

Author Comment

by:benjalamelami
Comment Utility
Dear Sstone.

Thanks for your help.  I have my DHCP integrated with my DNS.  So, let me see if I get it right:

- Stablish the DHCP to give DHCP clients the DNS from the AD server itself (its small network: AD, DNS, DHCP are all in the same server)

- The DNS for the server will be" 127.0.0.1

What I dont understand very clear, is where or how do clients know where to look for the external name servers for solving the internet names.  

Thanks
0
Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

 
LVL 4

Expert Comment

by:sire_harvey
Comment Utility
The 2003 DNS server will service all your internal network.

In the DNS Console, there will be Root Hints which point to External IP addresses for external name resolution.

Also check your firewall, DNS uses UDP port 53 and TCP port 53.
0
 

Author Comment

by:benjalamelami
Comment Utility
Thank you very much for your help.  However DNS resolution for internet domains became really slow.  It does work, but takes 4 seconds or something per domain.  I was wondering, if it had to do on how the Kerio Control machine is configured.  Or if I should add some root hints to the ISP DNS.
0
 
LVL 8

Accepted Solution

by:
sstone55423 earned 125 total points
Comment Utility
Within the Windwos DNS you can specify secondary lookup.  (properties of the DNS server) If nothing is specified there, then it uses root hints, which can be slugglish sometimes.  You can also specify outside DNS servers explicitly for everything (instead of root hints) or on an on domain basis.  These look ups should be faster than root hints.  Some people specify their ISP's DNS servers.  Depending on the ISP, that can be slow or not.  You can also try pointing the Windows DNS to the Kerio as secondary -- just to see if performance is better.
 
The reason you need to use your internal WIndows erver for DNS (given out by Windows DHCP) is that to authenticate with Windows domain properely, (AD) you have to resolve SRV records that are unique to AD.
0
 

Author Closing Comment

by:benjalamelami
Comment Utility
Thanks for the tip.  
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

I've always wanted to allow a user to have a printer no matter where they login. The steps below will show you how to achieve just that. In this Article I'll show how to deploy printers automatically with group policy and then using security fil…
If you have a multi-homed DNS setup in windows, you can have issues with connectivity to the server that hosts the DNS services (or even member servers of your domain if this same DNS server is a DC). This is because windows registers all of its IPs…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

7 Experts available now in Live!

Get 1:1 Help Now