Solved

2008 DNS - Switching to AD stored zones

Posted on 2011-09-08
6
181 Views
Last Modified: 2012-06-27
Our school district has 40 sites, originally utilizing a seperate NT4 domain in each site.  We then upgraded to Windows 2000, and converted to a parent domain and 39 child domains.  (we are working on a plan to finally go to a single flat domain, but that will take time..)  
In the present model, each domain including the parent has its own DNS zone, integrated into AD, but only replicated to DCs in that domain via AD.  Each child domain has a secondary zone (file-based) for the parent domain, replicated from the parent domain DNS servers. Delegation records in the parent DNS zone for each child zone finish the picture.  DNS resolution is complete, and works well, BUT it's a pain to maintain!

Now that we have finally eliminated the last Windows 2000 DC, (and all but two of the 2003 DCs) I am interested in switching to a DNS structure entirely stored and replicated by DNS.  Nothing I've read, so far, answers two questions I have:
1. Currently, when we install a new child-domain DC, DNS is autmatically configured with the domain's DNS zone.  Then we have to manually add and configure the secondary zone for the parent domain.  If the parent domain was set to replicate to all DCs in the forest, would that secondary zone also be automatically created?
2. How would I manage the switchover?  After I set the parent DNS zone to replicate to all servers in the forest, what changes would I have to make to the child domain DNS servers?  (There are a lot of them...)

Dann Cox,
Infrastructure Administrator,
School Distruict 68
0
Comment
Question by:danncox
  • 4
  • 2
6 Comments
 
LVL 10

Expert Comment

by:SuperTaco
Comment Utility
before I answer anything, are any of your DNS zones AD integrated?
0
 

Author Comment

by:danncox
Comment Utility
As stated,  each domain's own zone is AD-integrated, but only for that domain - none are set to replicate to the entire forest.
0
 
LVL 10

Expert Comment

by:SuperTaco
Comment Utility
You could try creating stub zones for each sub-domain in every other domain.
0
Complete Microsoft Windows PC® & Mac Backup

Backup and recovery solutions to protect all your PCs & Mac– on-premises or in remote locations. Acronis backs up entire PC or Mac with patented reliable disk imaging technology and you will be able to restore workstations to a new, dissimilar hardware in minutes.

 

Author Comment

by:danncox
Comment Utility
I am not sure how this would work - Reading the MS info on Stub zones, they only mention stub zone in the parent for the child zones, not the other way around.  If so that would not help much?
I'd better go do some more reading on stub zones.

Dann
0
 

Accepted Solution

by:
danncox earned 0 total points
Comment Utility
I wasn't really getting much information, here or elsewhere, so created a test child-domain and did some testing.  At least in our forest, setting the parent domain DNS to publish to all DNS servers in the forest worked.  We did have to go to each child-domain DNS server, and remove the (file-based) secondary zone for the parent domain.  After re-starting DNS, replication quickly replaced the zone from AD.
We have left the delegation records in place for the child domains, as we are moving fairly quickly to get rid of child domains.
0
 

Author Closing Comment

by:danncox
Comment Utility
worked it out myself - Stub zones may have been the answer, but I never really figured them out.
0

Featured Post

Promote certifications in your email signature

Has your company recently won an award or achieved a certification? They'll no doubt want to show it off. Email signature images used to promote certifications & awards can instantly establish credibility with a recipient and provide you with numerous benefits.

Join & Write a Comment

One of the most often confused topics in the area DNS is the idea of GLUE records. Specifically, what they are, when they are needed, when they are provided, and how they are created. First, WHAT IS GLUE? To understand GLUE, you must first under…
BIND is the most widely used Name Server. A Name Server is the one that translates a site name to it's IP address. There is a new bug in BIND (https://kb.isc.org/article/AA-01272), affecting all versions of BIND 9 from BIND 9.1.0 (inclusive) thro…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

8 Experts available now in Live!

Get 1:1 Help Now