[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

Adding Parent AD DNS Zone to an existing child DNS Zone

Posted on 2013-11-19
6
Medium Priority
?
324 Views
Last Modified: 2014-09-03
Our current AD domain name is similar to x.y.com.  We currently have an external DNS for y.com (non-AD "Parent").  It appears that we can add the y.com as an AD integrated zone to our DCs, even though it is essentially the "parent" of our existing zone.  It is like brining in a new parent to an existing child domain, if that makes sense.  It resolves any added DNS entries under the parent y.com Zone in AD DNS, but will it cause any issues with AD?

Doing some testing, any DNS resolution will use the x.y.com domain first, then the y.com domain, which is what we want.

I was not sure if you can add a new parent to an existing child, as I was always told the "child" will think it is the top level for that domain (since it is the only one).  But maybe that is only for AD Domains and not DNS Domains as they are semi-seperate in this case.

So are their any concerns with doing this in a production environment?  Any downsides or things we need to test?  If at worst case, we need to remove the new Zone from AD DNS (Integrated), will that cause any foreseen issues?  Are their any white papers or information from MS?  Thanks!
0
Comment
Question by:ubsoc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 14

Expert Comment

by:Ram Balachandran
ID: 39660608
You will not able to add parent domain to the Windows AD infrastructure.
0
 
LVL 5

Author Comment

by:ubsoc
ID: 39660619
Actually I was already able to add a parent DNS domain (y.com) as an AD Integrated Zone in our test environment (x.y.com).  My question relates to that and what affects it may have, but it does appear to be working.

I did not add an AD Domain, only a DNS Domain.
0
 
LVL 38

Expert Comment

by:Mahesh
ID: 39660678
You need to add conditional forwarding in child domain pointing to parent domain and its dns server ip address.
U don't required ad integrated zone of parent domain in child dns server.

Alternatively you can enable zone transfer on dns zone in parent domain for child dns server
and add secondary zone in child dns server pointing to parent dns server as master

Thanks
0
Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

 
LVL 27

Expert Comment

by:DrDave242
ID: 39660814
What do you intend to accomplish by doing this? I'm fairly certain it can be done, but I don't see the purpose behind it.
0
 
LVL 14

Accepted Solution

by:
Ram Balachandran earned 750 total points
ID: 39661389
By doing this you just differentiate parent and child only in the DNS name space.
But I doubt how it impact your active Directory infrastructure - i mean the purpose of Child - Parent concept will not be benefited here - say Trust relationships etc.
You can just have some computers with Computer.y.com and computer.x.y.com, apart from that i don't see any benefit here.

I am not sure how complex applications that use AD concept behave when you have this custom settings
Also, i think it would be difficult to troubleshoot and get support from MS in case you have custom DNS configuration.
0
 
LVL 38

Assisted Solution

by:Mahesh
Mahesh earned 750 total points
ID: 39661759
In parent child domain scenario you must have some DNS name resolution mechanism in order to get proper name resolution between both otherwise you will face problem when accessing resources vice versa.
the standard practise of name resolution between microsoft AD DNS is as below
Parent to child name resolution:
create domain delegation on parent domain dns zone pointing to child domain with child domain dns server.
this will ensure all queries came to parent domain for child domain resources will be resolved by child domain dns server.

child to parent name resolution:
You need to add conditional forwarding in child domain pointing to parent domain and its dns server ip address.
this will ensure that any queries came to child domain for parent domain resopurces will be forwarded to parent domain DNS server

Alternatively you can have secondary zone with zone transfer transfer enabled vice versa in parent and child domain

thanks
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For anyone that has accidentally used newSID with Server 2008 R2 (like I did) and hasn't been able to get the server running again because you were unlucky (as I was) and had no backups - I was able to get things working by doing a Registry Hive rec…
In the absence of a fully-fledged GPO Management product like AGPM, the script in this article will provide you with a simple way to watch the domain (or a select OU) for GPOs changes and automatically take backups when policies are added, removed o…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question