Need DNS to prefer IP's on my site

Andrew Hamilton
Andrew Hamilton used Ask the Experts™
on
I have multiple sites on my internal network all connected with IPSec tunnels.   Each site has a Windows domain controller.  In addition to the domain controller, each site also has a NAS which serves as a file server.   My issue is this.    I want to publish a specific DNS name within one of the internal zones.   Assign each site a version of this name that points to the local NAS device.      I have all the IP information defined in sites and services.   When I have the DNS name something like mydnsname.mydomain.com I want the systems to return the IP of the local device.  What I'm seeing is from corporate, when I reference the device I'm getting random responses from across all of the offices.    
  Is there a way to make DNS prefer IP's on the site I sit on instead of round robin looking through the list of available servers?
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Distinguished Expert 2018

Commented:
No. Your problem is that you literally have DNS entries that you don't want to replicate, which isn't possible.
JohnBusiness Consultant (Owner)
Most Valuable Expert 2012
Expert of the Year 2018

Commented:
If this is just your machine, put the IP to Name relationship in your local HOSTS file, save and restart. That works.
Andrew HamiltonDirector of Global Infrastructure

Author

Commented:
John;

  I need for this to work on a more global perspective.   In total we have 27 international locations.   This name is intended to be a shared resource that is initially replicated from corporate to their local NAS.  i.e. video's and other corporate content.  The preference is to have the data served locally from the device on their site instead of pulling in every time from corporate.
Ensure you’re charging the right price for your IT

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

JohnBusiness Consultant (Owner)
Most Valuable Expert 2012
Expert of the Year 2018

Commented:
Then I think what Mansrock said is correct here.
Distinguished Expert 2018

Commented:
I've already explained why it won't work from a DNS perspective: You literally cannot do it.

If you were going to try host files (Windows does check host files BEFORE DNS servers), you'd have to deploy a different host file to each site (presumably via GPO). That's going to get messy very fast, especially for either troubleshooting or systems that move across sites.
nociSoftware Engineer
Distinguished Expert 2018

Commented:
This can be easiliy solved when using bind.

Besides just DNS zone, bind can also handle so called views.
And views can be selected based on the source address of the system that does the DNS queries....

So in your case make zone f.e. storage.example.com   (and optionaly use a CNAME to the real system).
and put it in a view where one view would be selected by addresses from site A, and another view for addresses from site B etc. etc.
This whole stuff can be setup so all sites have the same configuration.

(or deploy an OpenVMS cluster with a DNS on board, that has exactly this functionality on board to choose nearest & surviving members from the cluster after a disaster.
Jeremy WeisingerSenior Network Consultant / Engineer

Commented:
You can probably accomplish this with DFS Namespace server. It is site aware and can direct each site to the local NAS.
Shaun VermaakTechnical Specialist
Awarded 2017
Distinguished Expert 2018

Commented:
You can only use DFS if the compute part is done by Windows. This means the NAS needs to be a Windows box or you need to attach the NAS storage to a Windows box (map, junction, storage spaces, VHDX etc.)

Is this the case/is this an option?

You can have multiple Host files, one per site, stored on DC DFS. You can then via GPOs assign a network host file. The GPOs can be linked to your AD sites.
Jeremy WeisingerSenior Network Consultant / Engineer

Commented:
I was under the impression that the namespace server and DFS folder hierarchy needs to be on windows and the folder targets can be any UNC path. Kinda old documentation but here's a snippet:
Link targets are typically shared folders or folders within shared folders. Link targets can be served by any network file system that is accessible by a UNC path, such as Server Message Block (SMB), NetWare Core Protocol (NCP) for NetWare, or Network File System (NFS) for UNIX. (The client computers must have the appropriate redirector installed to access link targets.) The UNC path can lead to shared folders in any workgroup, shared folders within the same domain as the namespace, shared folders in trusted domains, and shared folders in trusted forests.

Shared folders that are specified as link targets have no special settings that indicate that they are part of a DFS namespace. All existing shared folder permissions and NTFS permissions on the shared folder still apply when users access the shared folder through the namespace.

A link target can also be a DFS path in another namespace. For example, the Software link in \\Contoso.com\Public\Software might have a link target of \\Software\Public, which is a root within a stand-alone namespace. When using DFS paths as link targets, it is important to ensure that client failover works correctly. For more information, see “Linking to Different DFS Namespaces” later in this section.
from: https://technet.microsoft.com/pt-pt/library/cc782417%28v=ws.10%29.aspx?f=255&MSPPError=-2147217396#w2k3tr_dfs_how_sdzq
 It's possible that this has changed in the newer versions of Windows.
Shaun VermaakTechnical Specialist
Awarded 2017
Distinguished Expert 2018

Commented:
When you open the DFS namespace wizard you have to type in a server name. You can only provide a server that has DFS namespace installed so you cannot simply enter the NAS UNC path.

EEdfs.png
Andrew HamiltonDirector of Global Infrastructure

Author

Commented:
Noci;

    I'm not familiar with DNS Views.   Is this something support with Microsoft DNS?
Technical Specialist
Awarded 2017
Distinguished Expert 2018
Commented:
I'm not familiar with DNS Views.   Is this something support with Microsoft DNS?
No, that is in BIND
https://www.isc.org/downloads/bind/

Is Windows Server 2016 an option? It has DNS policies
Jody LemoineNetwork Architect

Commented:
This is a bit outside of the box, but rather than using DNS, have you considered using anycast addresses for the NAS units? Each unit would have a primary IP address that is unique to each site, but would also have a secondary address that is common to all and is advertised into the routing table. With this approach, you can advertise the common IP address across the organization and have each site automatically route to the closest unit. This approach also provides rudimentary failover. In the event that the local NAS is unavailable, the next closest unit will be used.
Andrew HamiltonDirector of Global Infrastructure

Author

Commented:
Shaun;
 
  With there being 27 different sites, transitioning from W2K12R2 to W2K16 is a fairly heavy lift.   Definitely not something I can do short term to address this need.      I appreciate the heads up however that the feature exists.  This knowledge and awareness will help drive the priority to get transitioned to W2K16 more quickly.

Thanks
Andrew HamiltonDirector of Global Infrastructure

Author

Commented:
Jody;

  I'm not familiar with anycast  or how to set it up.   I'll research it and see if this is a fit.  

Thanks
Jody LemoineNetwork Architect

Commented:
No problem. If I may ask, what kind of NAS units are you using and what routing protocol? I may be able to offer a bit more clarity if I have that information.
Top Expert 2014

Commented:
Since you asked if you can make DNS prefer IP's in the same site, subnet prioritization (a.k.a. netmask ordering) may work for you.  If you're using anything other than class C networks at each site, you'll have to adjust the LocalNetPriorityNetMask registry value (under the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters registry key) on each DNS server to match your netmask, otherwise you won't get expected results.

A couple links for reference:
https://blogs.msmvps.com/acefekay/2010/05/29/dns-and-subnet-priortization-amp-dns-round-robin/
https://support.microsoft.com/en-us/help/842197/description-of-the-netmask-ordering-feature-and-the-round-robin-featur
Andrew HamiltonDirector of Global Infrastructure

Author

Commented:
Jody;

  We are using Synology NAS unit's
Andrew HamiltonDirector of Global Infrastructure

Author

Commented:
I will review getting all of the DC's upgraded to W2K16 and implement DNS policies to do what I need.     While it's a big lift given the number of DC's in the field, I think that long term it checks most if not all of the boxes I need for functionality.  

Thanks all for you advise.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial