?
Solved

Question about creating a DNS load balance between domain controllers

Posted on 2012-12-29
7
Medium Priority
?
1,210 Views
Last Modified: 2013-01-15
Hi,
A small background before my question :) -
I had a need to create a load balance service name between all the domain controllers, i know i could use the default domain name instead, but it had connections to other servers except for the domain controllers.

So....
since i can't create the same multiple dns host to multiple servers i created a new subdomain and had all the domain controller's IP name SAME AS PARENT...so all would get the same DNS name of the new subdomain, hence creating a DNS Load Balance.

Here's my question though, how does it work? is it round robin? who answers first? the dc the computer is connected to or the DNS the computer is connected to?

AND the most important factor what if one of the domain controllers isn't available, will the be a timeout? or will the query never reach it in the first place?
0
Comment
Question by:johnnyjonathan
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
7 Comments
 
LVL 37

Expert Comment

by:Neil Russell
ID: 38729511
If all your DC's are running DNS then all you need to do is list all of he DC's IP addresses in the NIC cards DNS settings on all machines.  Windows will take care of the rest. No need for ANY load balancing, round robbins or square ones.
0
 

Author Comment

by:johnnyjonathan
ID: 38729529
I didn't understand how this will create a load balance?
my need is to ping a name for example (dns.company.com) and have a redundancy (perhaps i should have used that therm instead of the load balance since it explains my needs better) between all domain controllers.
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 38729746
Can you explain EXACTLY what it is you want to do and why?
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 

Author Comment

by:johnnyjonathan
ID: 38729781
I have several applications that connect to Active Directory using LDAP directly to a Domain controller server, i don't want to give them the name of 1 domain controller since if it's down then the service is down, so....i want to create a DNS alias name to hold behind it all available DC's
0
 
LVL 26

Accepted Solution

by:
DrDave242 earned 2000 total points
ID: 38732949
I'll get the easy part out of the way first:
Here's my question though, how does it work? is it round robin? who answers first? the dc the computer is connected to or the DNS the computer is connected to?
Yes, it's round-robin by default.  You can disable round-robin in the properties pages of the DNS servers (under the Advanced tab, I believe), but there's typically no reason to do this.  So the first time a DNS server is queried for that name, it'll return the IP address of the first corresponding host record.  The second time it's queried, it'll return the second one, etc.  It should be mentioned that you won't see this exact behavior on a client.  Multiple queries for the same name from a single client will return the same IP address for a while, because the client will have that address in its resolver cache and won't actually query a DNS server until the cached record expires or the entire cache is flushed.
i know i could use the default domain name instead, but it had connections to other servers except for the domain controllers.
Are you saying you've got blank host records in DNS (host records with the name "same as parent folder") referring to machines other than domain controllers?  If so, that's a problem.  Those records are used by domain members to locate a DC, and they shouldn't ever refer to anything but DCs.

To answer the question, there's no true load-balancing mechanism built into DNS.  Round-robin DNS does load balancing only on the most basic level; it doesn't care whether a given server is down and will return its IP address anyway.  Network Load Balancing (NLB) is outage-aware, but I can't think of a way to make it work in this scenario.  If those apps that you're running are AD-aware, they should be able to use AD's built-in mechanisms to locate a DC that's running.  Have you actually experienced problems with them?
0
 

Author Closing Comment

by:johnnyjonathan
ID: 38780863
Great Explanation!
Thank you so much!
0
 

Author Comment

by:johnnyjonathan
ID: 38780867
I haven't had any problems but yes the original DOMAINNAME.COM is full with other IP addresses that are not DC's, some are even external IP's i need to figure out how come it happened.
0

Featured Post

Bringing Advanced Authentication to the SMB Market

WatchGuard announces the acquisition of advanced authentication provider, Datablink, with one mission – to bring secure authentication to SMB, mid-market, and distributed enterprises with a cloud-based solution, ideal for resale via their established channel & MSSP community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question