Solved

resolve external child domain

Posted on 2014-02-25
14
449 Views
Last Modified: 2014-02-26
Hi, hopefully someone can help with this.

We have a few domains all hosted externally on the same ip. If i browse to any of them externally everything is fine, if i try to browse to them from the LAN only the parent domain resolves, all the others are blank. ( i can resolve www.school.com but not www.child.school.com)

Things are a little mixed up as we have our own exchange server which uses the same domain name as our externally hosted website, lets call it for this purpose school.com. To overcome any mail issues ect we have a lookup zone called school.com this zone holds 'A records' for school.com which it resolves to the hosting IP, and webmail.school.com which points to our exchange servers, and www which resolves to the externally hosted website '80.10.1.56' for example.

When i try to add either a 'A record' or a CNAME to this zone it makes no difference. For example a CNAME which points child.school.com to school.com. The parent will resolve on the internal DNS fine but the child won't

Am i barking up the wrong tree here? Any help would be greatly appreciated.
0
Comment
Question by:PTemporal
  • 7
  • 5
  • 2
14 Comments
 
LVL 31

Expert Comment

by:Frosty555
ID: 39886765
Since your internal domain is also "school.com", the problem is that when you try to resolve "www.child.school.com" from within your internal network, the name resolution is being done by your domain controller, and NOT the public nameservers provided by your webhost.

This is called a "split DNS".  It is a supported configuration and is particularly useful when creating SSL certificates for the Exchange server.

The simplest solution is simply to add the necessary DNS records to your domain controller's DNS service by using the dnsmgmt.msc console. If you don't have many records, you can just keep your public nameserver's records and your internal domain controller's records in sync manually.

Chances are your domain controller already has an A record defined for "www", which is why it resolves but nothing else does.
0
 

Author Comment

by:PTemporal
ID: 39886773
Thanks for the quick response Frosty.

I will try this in the morning. Split DNS sounds messy, can you suggest a better way to set this up?
0
 
LVL 31

Expert Comment

by:Frosty555
ID: 39886787
I know Split DNS sounds messy, but it's the best way to do it. Overall it is a small amount of manual work, and your webserver public IP addresses probably aren't going to change too often.

Don't try going down the tempting path of trying to make the domain controller forward requests to your public nameservers.

Some networks have a different internal domain from their external domain, e.g. your internal domain would be school.local, instead of school.com. This gives you a bit more elegant control over internal vs external DNS resolution, but there are other challenges when you set the network up that way. In any case, it's a moot point because it isn't feasible for you to change your domain name, it's already been set up.
0
 
LVL 35

Expert Comment

by:Mahesh
ID: 39886947
What is dns zone name in child domain and is it ad integrated ?

I mean do you have active directory as well ?
0
 

Author Comment

by:PTemporal
ID: 39886976
Hi There,

Yes the ad domain runs DNS on school.local the zone name is school.com. This we use for exchange as it is also school.com.

I thought i could just add an Arecord or CNAME but this doesn't seem to work.

Thanks.
0
 
LVL 35

Expert Comment

by:Mahesh
ID: 39887024
So you have only one AD domain (school.Local) and external domain (school.com) ?

On the internet you are also having child.school.com zone right ?

Now from internal network you are not able to resolve child.school.com, is that your issue ?

Just trying to understand your question 1st please

Mahesh
0
 

Author Comment

by:PTemporal
ID: 39887045
Thanks for your patience Mahesh.

We have 4 DC's three running DNS and one a rodc. From within the LAN/Domain i can resolve school.com (which is external) but i cant resolve child.school.com.

I tried adding child.school.com as an A Record and as a CNAME to the school.com zone but it still wont resolve.

The school.com and child.school.com are both hosted externally.

Yes i cant resolve child.school.com
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 35

Expert Comment

by:Mahesh
ID: 39887078
Ok, thanks for clarification

Your comment
( i can resolve www.school.com but not www.child.school.com)

You must create sub folder named child under school.com zone and within child sub folder you need to create www as host (A) record so that it will be resolved as www.child.school.com from internal network

Mahesh
0
 

Author Comment

by:PTemporal
ID: 39887114
Mahesh, thanks.

My appologies, what i'm saying is wrong.

I'm in the UK and at home now. I VPN'd in to check the setup.

I have the A record www and you are correct that is what i need. The issue, (apologies again) is that FQDN something.com is hosted on the same ip address and DNS (to my mind) must be trying to resolve something.com to with the zone record for www

Do i have to create a new zone for something.com?

Thanks again for your advice.
0
 
LVL 35

Accepted Solution

by:
Mahesh earned 500 total points
ID: 39887153
Your comment:
FQDN something.com is hosted on the same ip address and DNS (to my mind)

So you mean to say that www.school.com and www.child.school.com are both having same public IP address ?

You can have multiple (Host A) records pointing to same IP
Just right click school.com zone and select new domain
There type in child and that's all
Now you can create www (host A) record under child folder
Then it will resolve that
0
 

Author Comment

by:PTemporal
ID: 39887171
Thanks i'll have a look in the morning and let you know how i get on.

thanks.
0
 

Author Comment

by:PTemporal
ID: 39888374
I've requested that this question be closed as follows:

Accepted answer: 0 points for PTemporal's comment #a39887171

for the following reason:

Working now
0
 
LVL 35

Expert Comment

by:Mahesh
ID: 39888363
Have you got the solution or not..

have you changed any thing according to my comment ?
0
 

Author Comment

by:PTemporal
ID: 39888372
Hi Mahesh,

I was led up the garden path by the web developer.

All working now, child.school.com is resolving thanks to your help.

I already accepted your contribution as the solution.
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

This is the first one of a series of articles I’ll be writing to address technical issues that are always referred to as network problems. The network boundaries have changed, therefore having an understanding of how each piece in the network  puzzl…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now