Solved

Change DNS zone to "secure only" dynamic update

Posted on 2014-03-17
4
524 Views
Last Modified: 2014-03-24
Hi All

I have a forward look up AD integrated zone (main one for my organization) which is currently set to "Non secure and secure" dynamic updates in DNS (Server 2008 R2). We have enabled "Name protection" in DHCP to prevent rouge devices taking over important server names but this requires DNS to be set to Secure only dynamic updates.

My question is can this be done without any distruptions? Will the existing records in DNS still be there? Will DHCP still be able to update DNS for domain computers? I can manually add the non domain ones to DNS. Can someone confirm that my intended change will not get rid of the exisitng records and cause more headaches. Thanks
0
Comment
Question by:nassr101
4 Comments
 
LVL 36

Accepted Solution

by:
Mahesh earned 250 total points
ID: 39936942
Nothing will be impacted at all

This is what needs to be done in case of AD integrated Zones

Also ensure that your DNS-DHCP integration is set perfectly according to below EE articles
http://www.experts-exchange.com/Networking/Protocols/DNS/Q_28379478.html
http://www.experts-
http://www.experts-exchange.com/Networking/Protocols/DNS/Q_28361151.html
http://www.experts-exchange.com/Networking/Protocols/DNS/Q_28376098.html

Please check my comments in above articles

Mahesh
0
 
LVL 26

Expert Comment

by:Leon Fester
ID: 39937169
My question is can this be done without any distruptions?
There shouldn't be any disruption if you're not deleting records that already exist.

Will the existing records in DNS still be there?
Yes, only manual deletion or the DNS scavenging task does any deletions from the DNS zone.

Will DHCP still be able to update DNS for domain computers?
Yes, but only if the DHCP server has permissions to update those records.
You need to remember (in AD2008) that when you enable AD-integration on DNS zones then the default is set to "enable secure updates." You also need to remember that the permissions on DNS records in AD integrated zones are like any other AD object. If the user or system has permissions to update a record then it will. If the user/system does not have any permissions then the record cannot be updated.

I can manually add the non domain ones to DNS. Can someone confirm that my intended change will not get rid of the exisitng records and cause more headaches. Thanks

Some useful links about DHCP and DNS
http://technet.microsoft.com/en-us/library/cc771732.aspx
http://technet.microsoft.com/en-us/library/ee941150(v=ws.10).aspx
http://technet.microsoft.com/en-us/library/cc732584.aspx
0
 
LVL 27

Expert Comment

by:Steve
ID: 39937249
secure DNS updates just restricts who/what can make changes.
Domain joined PCs and your existing AD approved DHCP servers are included so shouldn't be affected.

Non secure & secure updates is normally enabled if you have other devices on site that may nee to make DNS changes, but are not Windows domain based machines (eg routers, printers etc)

Most companies are fine on secure only. It makes no changes and doesn't stop anything working on your existing network. The only real issue occurs if you do have non-windows systems that are trying to make DNS changes (eg DHCP on a router)
0
 

Author Closing Comment

by:nassr101
ID: 39952407
Thanks Mahesh. I changed the zone type yesterday and it went smoothly
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you need to start windows update installation remotely or as a scheduled task you will find this very helpful.
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This Micro Tutorial will give you a basic overview of Windows DVD Burner through its features and interface. This will be demonstrated using Windows 7 operating system.
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question