Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

DNS - use Internal or External (performance)

Posted on 2016-10-14
6
Medium Priority
?
54 Views
Last Modified: 2016-10-25
Hi
Can someone help me gauge whether or not its best to use internal DNS servers or use say the ISP DNS servers?
We are using internal, 4x DCs with DNS on over two sites recently performance of internet has dropped.  Not sure if this is o365 related or not either, however when a DC goes offline it causes much issue and takes a lot of time for logons to work etc.
Wondered if pointing DNS externally will help with the above or anything else?
thanks
0
Comment
Question by:CHI-LTD
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 22

Accepted Solution

by:
CompProbSolv earned 1000 total points
ID: 41843369
Are you asking if local workstations should use the local DCs or your ISP DNS servers for DNS?  Definitely the local DCs.  The primary reason is that your ISPs DNS servers won't know how to resolve local addresses which will cause you no end of problems.

You can configure the DNS servers in your local DCs to use the ISP DNS servers for forwarding if those servers seem reasonable.
0
 
LVL 7

Expert Comment

by:Niten Kumar
ID: 41843378
Logon problems means issues with your dc's.  What kind of problems do you have when a particular dc goes offline? How many sites do you have and how are the dc's distributed amongst the sites. Are sites properly defined and have you checked dc and replication health.
0
 
LVL 1

Author Comment

by:CHI-LTD
ID: 41843394
ok will leave clients pointing to local dcs.
will give server dns changes some more thought.

So if one DC was offline for maintenance other servers (not sure about clients) would say there are no logon servers to process account (or similar) but there is still one other DC available.  

I have 4x DCs.  2x at site a and 2 at site b.

The clients point to site a and also have the site b in the tcpip settings, but down the list.

dcdiag reports fine
0
Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

 
LVL 7

Expert Comment

by:Niten Kumar
ID: 41843400
Can you type set at command prompt on the machines that cause logon problems and check what is displayed under logon server
0
 
LVL 7

Assisted Solution

by:Niten Kumar
Niten Kumar earned 1000 total points
ID: 41843401
The computers at site b should output the one of the dcs at site b as the logon server. Likewise for site a.
0
 
LVL 1

Author Closing Comment

by:CHI-LTD
ID: 41858303
let using local, but may look at pointing internal DNS servers to Google.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

660 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question