Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium


DNS Conditional forwarders. How to forward some domains externally, some subdomains internally.

Posted on 2014-08-07
Medium Priority
Last Modified: 2014-09-05
I have remote site where users are logged into a windows domain. This site is not part of our main company. Say our main company is Microsoft.

Issue is, I want this remote site's DNS, to forward some DNS requests to our DNS servers for local resolution, and some DNS request on our domain to be resolved on the remote site DNS, which will get forwarded to the root server, AKA external websites.

So, by default I want ALL microsoft.com requests to forward on to our DNS server. However, there are some exceptions to that same domain, that need to resolve on that DNS/root dns servers, for public DNS resolution.

Only catch is our local DNS servers do NOT resolve externally domains at all.

AKA lets say mail.microsoft.com, remote.microsoft.com and login.microsoft.com I want to resolve externally, so those need to stay at the remote site. But ALL other microsoft.com subdomains need to get forwarded to our main company's DNS.

How would I do this on windows server 2003/2008?
Question by:LIBBB
LVL 14

Expert Comment

ID: 40245599
setup conditional forwarding on dns servers http://technet.microsoft.com/en-us/library/cc757172%28v=ws.10%29.aspx

Author Comment

ID: 40245613
Thanks. Any idea about the wildcards though? If I setup a forward for microsoft.com, will example.microsoft.com fall under that forward? Or can I setup *.microsoft.com forward?
LVL 39

Expert Comment

ID: 40245700
U cannot add *.domain.com as conditioanal forwarder

However if you add conditional forwarder to microsoft.com, then  query to example.microsoft.com will get forwarded to microsoft.com conditional forwarder

However if your forwarding domain is microsoft.com and you trying to resolve webcast.example.microsoft.com, it will not resolve that.

If you created contoso.com as dns forwader and corp.contoso.com as dns zone in local dns, then ur all queires like server1.corp.contoso.com will be resolved internally
If you trying to resolve server.contoso.com, queries will get forwarded to conditional forwarder contoso.com
Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!

LVL 10

Expert Comment

by:Pramod Ubhe
ID: 40246694
configure conditional forwarder for microsoft.com and create a forward lookup zone for example.microsoft.com on your internal dns (with @ record to the target IP). this will ensure that example.microsoft.com queries will be routed to @ record IP address and microsoft.com will go to the IP configured in conditional forwarder.

Author Comment

ID: 40249030
Hmm so far I don't know if I've found a solution. Because a good point has been brought up. There are other internal domains that multiple subdomains.


How would I send domains that end with microsoft.com over to the other DNS server, with multiple subdomains?
LVL 10

Accepted Solution

Pramod Ubhe earned 2000 total points
ID: 40249366
That is why you configure entire subdomain as forward lookup zone so that any queries to Microsoft.com will not resolve internally. It's up to you to have it resolved by Internet or conditional forwarder.

I had a setup in one of my prev org. Where we intentionally created zones for subdomains to avoid DNS resolution of main domain by internal DNS.

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Resolve DNS query failed errors for Exchange
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

578 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question