Solved

DNS Question _msdcs

Posted on 2014-11-25
4
163 Views
Last Modified: 2014-11-25
HI
I keep getting an error form the best practice analyzer. It is commenting on me missing this _msdcs zone, but as you can see in my pic attached it is under my domain name zone.
I looked around and a saw one example where someone had this zone right under the forward lookup zones main root as _msdcs.mydomain.com and then their mydomain.com was under that and also contained this zone.
Any ideas??
Thanks.
pic.jpg
0
Comment
Question by:valmatic
  • 2
  • 2
4 Comments
 
LVL 39

Accepted Solution

by:
footech earned 500 total points
ID: 40465139
Either configuration is valid (having it as a subdomain of your domain zone, or having it as a separate zone).  By default, new AD domains created with Server 2003+ configure it as its own domain.  Here's a link with some more relevant info.
http://support.microsoft.com/kb/817470

If you want to change your configuration, all you do is delete the _msdcs subdomain, then create a new forward lookup zone called "_msdcs.yourdomain.com" with a replication scope of "all DNS servers in the forest".  Create a delegation under the yourdomain.com zone called "_msdcs" and add your DNS servers as the name servers.  Now restart the Netlogon service and the DC will autopopulate the _msdcs zone with its records (you'll want to do this for all DCs).
0
 
LVL 7

Author Comment

by:valmatic
ID: 40465245
thanks, yes i heard this _msdsc folder populates itself just seemed to good to be true haha. Yes since mine is under my domain folder i am guessing it has been taggging along since the server 200 days.
So if i add one under the forward lookup zones i call it _msdcs.mydomain.com? Then restart netlogon and let it populate? Then wehn it is done remove the one under mydomain.com or does it even matter if it is there?
I wonder if this will get rid of my error that i dont have any ldap srv records which i clearly do.
Thanks.
0
 
LVL 39

Expert Comment

by:footech
ID: 40465290
I can't recall which takes precedence if you have both the explicit zone and under your domain zone.  Best to delete the one under your domain (and remember to create the delegation).
0
 
LVL 7

Author Closing Comment

by:valmatic
ID: 40465332
thanks
0

Featured Post

Are your corporate email signatures appalling?

Is it scary how unprofessional your email signatures look? Do users create their own terrible designs and give themselves stupid job titles? You can make this a lot easier for yourself by choosing an email signature management solution from Exclaimer today.

Join & Write a Comment

Suggested Solutions

Understanding the various editions available is vital when you decide to purchase Windows Server 2012. You need to have a basic understanding of the features and limitations in each edition in order to make a well-informed decision that best suits y…
The article will show you how you can maintain a simple logfile of all Startup and Shutdown events on Windows servers and desktops with PowerShell. The script can be easily adapted into doing more like gracefully silencing/updating your monitoring s…
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now