Link to home
Start Free TrialLog in
Avatar of Stuart
StuartFlag for United Kingdom of Great Britain and Northern Ireland

asked on

2008 r2 DNS Conditional forwarders

When upgrading DC's to 2008 R2 (ADI DNS) conditional forwarders do not work. In the console they fail to resolve and validate with the error 'not authoritative for the namespace) my question is what are the requirements for a conditional forwarders and have they changed since 2003

I presume 2003 conditional forwarders were happy with receiving referrals from conditional forwarders and processing them
Avatar of Mark Bill
Mark Bill
Flag of Ireland image

we do not want forwarders in DNS, yes they should work but its actually Microsoft recomended to use root hints.

Why dont you try to enable root hints and remove your forwarders?
Also if you were going to use forwarders you should be forwarding to your ISP DNS server and the ipconfig of domain controllers should be like this.

IP: ip address
Mask: mask
Gateway: your gateway
DNS1: domaincontroller IP
DNS2: domaincontroller IP

Active directory domain controllers should only be pointing to domain controllers who are doing DNS for the domain whether your using root hints or forwarders.
conditional meaning you have a specific domain name or are you forwarding all non ad domain based requests.

As Mark pointed out, forwarding was used to offload load/traffic, but it was susseptible to poisoning, ...... And ....

are pointing to IPs or names?
Avatar of Stuart

ASKER

I'm not forwarding, conditional forwarders are added for specific domains in a partner organisation. These are not resolvable from the Internet.
The DNS,you are pointing to are not authoritative for the domain according to the error you got.  An alternative to forwarders is the use of stub zones that achieve a similar result. I.e. Your DNS will get the DNS responsive and will send the requests there. Another option is to setup the other domains as a secondary zones that your DNS will transfer directly from the other server who will need to be configured to allow zone transfers to your server.
Avatar of Stuart

ASKER

Hi I agree with your thinking but stub and secondary zones are not allowed in this instance. What I am trying to find out is do the conditional forwards have to be to only servers authoritative for that zone because it can't of been the case in 2003. I'm struggling to find any Microsoft documentation to support this
2003 did not have this check. The check is to avoid domain hijacking/DNS poisoning.

You can use plain forwarders by specifying the domain there.......


While not an answer why, it covers the question you posed, and the requirement that conditional must point to anauthoritative DNS server for the domain in question, is that an issue?
I.e. Your side can not get to the authoritative servers on the other end?
https://social.technet.microsoft.com/Forums/windowsserver/en-US/6d22c645-3e25-4e28-9c5d-815276c4446f/conditional-forwarding-with-non-authoritative-dns-server?forum=winserverNIS
Avatar of Stuart

ASKER

Hi firewall changes can be made to allow c.fwdr to point to the authoritative server, it was more a case of understanding why pointing to a non authoritative server doesn't now work on 2008 and a supporting article from Microsoft to explain. I appreciate your comments :)
Avatar of Stuart

ASKER

This was resolved by re creating the conditional forwarders and restarting the DNS service... It does look like the servers have to be authoritative.. Hmmm
Avatar of Stuart

ASKER

I've requested that this question be closed as follows:

Accepted answer: 0 points for Solacement's comment #a40879052

for the following reason:

Resolution of the issue
I believe my comments have guided you to this solution meaning making sure your conditional forwarders are. Authoritative for the conditional domain.
ASKER CERTIFIED SOLUTION
Avatar of Stuart
Stuart
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
The functionality is not in dispute, the question dealt with when setting up the conditional forwarding the wizard failed to resolve and validate with the error dealing with the referenced servers being non-authoritative.