How to make this windows server 2003 accepting DNS update from primary DC ?

Hi All,

I wonder if it is possible to make this WIndows Server 2003 member server to receive DNS updates from my AD integrated DNS server on different site ?

Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

AkhaterSolutions ArchitectCommented:
yes on you Active Directory Integrated Zone add the IP of the member server in the allowed zone transfers tab on the member server create  a secondary zone and let it use the Active Directory zone IP as master server
You could setup a secondary zone on the member server and allow zone transfers to it from the AD integrated one.
jjozAuthor Commented:
thanks for the reply guys,

the scenario is like this

Site A (HQ): ServerA - Primary DC and DNS and DHCP

Site B (Branch): ServerB - DNS and DHCP for site B only

at the moment I have no plan to DCPROMO site B windows server box.

So does the DNS replication can still be going or not possible without making the AD integrated zone ?
Your Guide to Achieving IT Business Success

The IT Service Excellence Tool Kit has best practices to keep your clients happy and business booming. Inside, you’ll find everything you need to increase client satisfaction and retention, become more competitive, and increase your overall success.

AkhaterSolutions ArchitectCommented:
you can create a standard secondary zone for an AD integrated zone no problem just follow what I told you in my first post

1. on server A allow the IP of Server B in the allow Zone transfer tab
2. on server B create a Secondary Zone and when asked for the master zone put the IP of server A
jjozAuthor Commented:
ah.. ok, glad to hear that i don't have to make this server as DC and by following your instruction, i hope that site B server can just receive update from the site A (HQ)
Krzysztof PytkoSenior Active Directory EngineerCommented:
Yes, you can do that as guys described. But your DNS security would be vulnerable for tampering during zone transfer. AD Integrated zone is replicated as directory services replication (it secure and encrypted) whereas secondary zone is plain text file which is transfer unencrypted (so it's easy to overhear transfer or/and tamper it. Using DNS AD Integrated allows you to using secure updates that cannot be modified by other than requestor while secondary zone allows non-secure also.

I know that not always this is possible to have only AD-I but I think it's worth considering to promote siteB server to DC (I know that is also complicates life, because probably there is no server room and IT staff but.. ;) )

Hope I could clarify it a little bit more.


Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
jjozAuthor Commented:
Thanks man !
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2003

From novice to tech pro — start learning today.