Solved

Best practice on how to create a DNS sub domain in windows server 2008 r2

Posted on 2011-09-08
3
1,984 Views
Last Modified: 2012-05-12
I work for a large scale company and we are cleaning up our DNS in addition to implementing new Windows Server 2008 R2 systems. We have multiple domains that have been created throughout the years. I have noticed a sub-domain that is giving us an error with the DNS Best Practice Analyzer. It appears they originally clicked on the zone and selected "New Domain" instead of just creating a separate zone. I have not seen this method used before. I have been searching for the Microsoft Best Practice method to prove of disprove this configuration should be changed to it's own new zone. Can anyone help me answer this?

Your help is greatly appreciated.

ProBSD
0
Comment
Question by:ProBSD
  • 2
3 Comments
 
LVL 20

Accepted Solution

by:
wolfcamel earned 500 total points
ID: 36507959
As best as I can explain ..it is an issue because..
for example two domains
domain.local
sub.domain.local

domain.local will have properly created subdomains such as server.domain.local, www.domain.local

the risk/issue is that if a workstation looks up sub.domain.local that the server may lookup domain.local and notice that there is no a record for sub.domain.local and then reply that it doesnt exist without noticing that there is a completely seperate domain.
It "SHOULD" notice the second domain exists, but the risk that it doesnt is the issue
0
 

Assisted Solution

by:ProBSD
ProBSD earned 0 total points
ID: 36598910
I finally broke down and contacted Microsoft to see what is best practice. In Server 2003 you could use this method even though it is not best practice, however in 2008 they recommend only creating a separate zone for each sub-domain. The only time it is recommended to create a domain under a zone is if the domain points to another domain in a different forest. In my situation this is not the case so we removed the domains, created new zones and then created delegations under the original zone to point to the new sub-domain's new zone.

Wolfcamel, thank you for your input however I feel this does not answer my original question, only why it may not work. But since you are the only person that has try to assist me I will still give you credit for assisting solution.

Thank you
ProBSD
0
 

Author Closing Comment

by:ProBSD
ID: 36895817
Wolfcamel, thank you for your input however I feel this does not answer my original question, only why it may not work. But since you are the only person that has try to assist me I will still give you credit for assisting solution.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Mapping Drives using Group policy preferences Are you still using old scripts to map your network drives if so this article will show you how to get away for old scripts and move toward Group Policy Preference for mapping them. First things f…
This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now