Solved

DNS delegation option?? when promoting DC

Posted on 2015-01-28
3
183 Views
Last Modified: 2015-02-10
Hello,
Do we need to say Yes to "createDNSDelegation" option  when promoting 2012 DC? We want it to be DNS as well and we have DNS integrated zones. Do we need to say yes or no to CreateDNSDelegation?

THank you.

#
# Windows PowerShell script for AD DS Deployment
#

Import-Module ADDSDeployment
Install-ADDSDomainController `
-CreateDnsDelegation:$false `
0
Comment
Question by:creative555
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 58

Expert Comment

by:Cliff Galiher
ID: 40576673
If there was a straight answer then it wouldn't be a choice. They include the option because you may or may not need it, depending on your unique environment. We can't answer that in a void.
0
 
LVL 6

Expert Comment

by:JeffG2583
ID: 40576677
Do you have a single domain under a single forest? How many DCs in the forest? You are fine answering No to creating a DNS delegation if you aren't interested in load balancing a lot of DNS requests. Here is a better description of it.

https://technet.microsoft.com/en-us/library/cc771640.aspx
0
 
LVL 37

Accepted Solution

by:
Mahesh earned 500 total points
ID: 40576896
If you are promoting DC in root domain (single domain) \ Tree Root Domain then you would select No ($false) because domain.com is the authoritative zone for that DC for which delegation is not required

However if you are creating DC in child domain (child.domain.com), child domain by default is not authoritative for domain.com zone and hence delegation is required.
in that case you would select Yes ($true), in that case DNS delegation will be created on parent DNS server
If you have already logged on server with domain admins of parent domain the delegation will be automatically created OR you would be prompted for parent domain "domain admins" credentials so that delegation can be created in parent zone on parent dns server with the name of child domain (child)
This delegation contains NS record of child domain DNS server
The purpose of this delegation is to resolve queries related to child domain from parent domain
When you deploy 1st DC in child domain, delegation would be created in parent dns zone, when you add new DC in child domain, it will update that delegation by adding new NS record in existing delegation in parent zone
0

Featured Post

What Is Blockchain Technology?

Blockchain is a technology that underpins the success of Bitcoin and other digital currencies, but it has uses far beyond finance. Learn how blockchain works and why it is proving disruptive to other areas of IT.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
Let's recap what we learned from yesterday's Skyport Systems webinar.
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

626 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question