Solved

issuing non ad intrigrated DNS servers as secondary dns to clients part of a win server domain

Posted on 2011-03-14
4
275 Views
Last Modified: 2012-05-11
Hi,

i know this is not best practice but i was wondering if someone can give me a detailed explanation why.

question has been posed by a work colleague and i really didn't have a good enough answer other then "dont do it"

i understand that the client may have trouble resolving dc srv records im guessing it could cause issues with ad/dns replication but i am unable to explain it in a clear fashion.

issue came about with dns in an 2008sbs domain (actual fault was with the forwarder which i resolved)

someone else had looked at it first and implemented a "work around" by adding the router ip to dhcp as the secondary dns. i told him that you should never add a external dns to a server or client in a windows domain. but couldn't give a good enough reason why.


any help clearing this up would be appreciated :)
0
Comment
Question by:Edgnett
  • 2
4 Comments
 
LVL 74

Expert Comment

by:Glen Knight
ID: 35134478
OK, well you are almost there.

By adding a secon DNS server as anything other than a Windows Server will mean that DNS lokups will fail.

The Windows client if for any reason is unable to perform a lookup on the primary server it will fail over to the secondary.  This could be because of a temporary load or temporary break in network communication.

It will not then fail over to the primary again until the secondary becomes unavailable or the cache is forcefully reset.

This will cause authentication as well as name lookup issues.
0
 
LVL 34

Expert Comment

by:Seth Simmons
ID: 35134495
Doing that in a Windows domain would cause problems with member systems (computers or servers) communicating on the internal network since it can't resolve using external DNS.  Not something you would want to do.  Would also cause login issues with users trying to access network resources (file shares, etc).
0
 
LVL 70

Accepted Solution

by:
KCTS earned 250 total points
ID: 35134534
Because of the way DNS works...

The alternaive DNS server (note alternative NOT secondary - a secondary zone means something very diffferent) is only ever used if the preferred (note NOT primary - again that is something very different) does not repond at all to a DNS lookup

The alternate DNS is never used if the preferred DNS server responds - even if the response is a 'not found' response.
It does not try the preferred server first then the alternate.

If you have an alternate DNS server configued that is not responsible for your domain DNS then it is possible, if your preferred DNS server is busy, that it will not respond within the timeout - in such as case then from that point on, all DNS referals will go to the alternae DNS server.

As the alternate DNS server dous not have the records for your domain, all subsequent internal DNS lookups will fail and your clients will be unable to locate any domain resources.
0
 
LVL 70

Assisted Solution

by:KCTS
KCTS earned 250 total points
ID: 35134571
I’ve re-worded my comment to try to make it make more sense

In normal circumstances the Preferred DNS server is queried to resolve a name to an IP address
The alternate DNS server is only ever used it the preferred server fails to respond (at all)

Note that even if the preferred servers’ response is ‘not found’ then that is a valid response and the alternate DNS server is not used.

If for some reason (such as heavy workload) the Preferred server fails to respond within the timeout all DNS lookups from that point on will be directed to the alternate DNS server.

If the alternate DNS server is ‘external’ then it will not have any of the DNS records for your domain and as a result internal DNS queries will be unable to be resolved. As a consequence you will be unable to locate any domain resources or services via DNS and your domain will fail.

Note the use here of PREFERRED and ALTERNATE servers

In simple terms a primary DNS zone is one which is a writeable copy and a secondary is a read only version and are not approriate here
0

Join & Write a Comment

You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
OfficeMate Freezes on login or does not load after login credentials are input.
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now