I inherited a Root / Child domain that is relatively simple except for the network/DNS config. The domain consists of a single empty Root domain (single DC) and a single Child domain (with two DC's). Everything is within a single Forest / Site. All three DC's are running DNS. I noticed that there are replication errors, specifically when running DNSLint on the Root DC, I get an error stating "Total number of CNAME records missing on this server: 2". All other DNSLint, DCDiag and NetDiag tests pass.
The confusion comes in with the networking setup. Due to security requirements, the child DC's are multi-homed, but the root DC is not. I've attached a sample diagram which should help clarify. What I'm trying to determine is how DNS should be configured in this scenario to allow for proper AD operation. I want to add a second DC to the Root for redundancy, but would like to first get DNS setup properly.