Link to home
Start Free TrialLog in
Avatar of nassr101
nassr101

asked on

Change DNS zone to "secure only" dynamic update

Hi All

I have a forward look up AD integrated zone (main one for my organization) which is currently set to "Non secure and secure" dynamic updates in DNS (Server 2008 R2). We have enabled "Name protection" in DHCP to prevent rouge devices taking over important server names but this requires DNS to be set to Secure only dynamic updates.

My question is can this be done without any distruptions? Will the existing records in DNS still be there? Will DHCP still be able to update DNS for domain computers? I can manually add the non domain ones to DNS. Can someone confirm that my intended change will not get rid of the exisitng records and cause more headaches. Thanks
ASKER CERTIFIED SOLUTION
Avatar of Mahesh
Mahesh
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
My question is can this be done without any distruptions?
There shouldn't be any disruption if you're not deleting records that already exist.

Will the existing records in DNS still be there?
Yes, only manual deletion or the DNS scavenging task does any deletions from the DNS zone.

Will DHCP still be able to update DNS for domain computers?
Yes, but only if the DHCP server has permissions to update those records.
You need to remember (in AD2008) that when you enable AD-integration on DNS zones then the default is set to "enable secure updates." You also need to remember that the permissions on DNS records in AD integrated zones are like any other AD object. If the user or system has permissions to update a record then it will. If the user/system does not have any permissions then the record cannot be updated.

I can manually add the non domain ones to DNS. Can someone confirm that my intended change will not get rid of the exisitng records and cause more headaches. Thanks

Some useful links about DHCP and DNS
http://technet.microsoft.com/en-us/library/cc771732.aspx
http://technet.microsoft.com/en-us/library/ee941150(v=ws.10).aspx
http://technet.microsoft.com/en-us/library/cc732584.aspx
secure DNS updates just restricts who/what can make changes.
Domain joined PCs and your existing AD approved DHCP servers are included so shouldn't be affected.

Non secure & secure updates is normally enabled if you have other devices on site that may nee to make DNS changes, but are not Windows domain based machines (eg routers, printers etc)

Most companies are fine on secure only. It makes no changes and doesn't stop anything working on your existing network. The only real issue occurs if you do have non-windows systems that are trying to make DNS changes (eg DHCP on a router)
Avatar of nassr101
nassr101

ASKER

Thanks Mahesh. I changed the zone type yesterday and it went smoothly