+ Post New Thread
Page 1 of 2 12 LastLast
Results 1 to 15 of 17
Wireless Networks Thread, DNS Configuration on DC's in Technical; Hi I'm kind of working through a list of things I've noticed, most of which is going on to another ...
  1. #1
    Cache's Avatar
    Join Date
    Apr 2008
    Location
    Cumbria
    Posts
    1,303
    Thank Post
    487
    Thanked 190 Times in 184 Posts
    Blog Entries
    3
    Rep Power
    67

    Question DNS Configuration on DC's

    Hi

    I'm kind of working through a list of things I've noticed, most of which is going on to another list such as the backups, and have now arrived to DNS.

    At the moment, all clients and servers, have the 2 DC's DNS and the ISP's DNS and I have left this as it is for the time being because it's carried on working and since it did that I wasn't to worried.

    Anyway, in order to correct this, I'm planning on getting rid of the ISP's DNS and hopefully the system is going to go to using the DC's DNS and the forwarders configured. Now, there's a couple of questions before I go changing things on the DC's.

    1. The DC's I'm assuming shouldn't have the ISP's DNS either, right? If not, then presumably, the Main DC has it's self configured as the primary DNS and the other DC as it's Secondary DNS and then the forwarders will take care of that, is that right?

    2. Should the other DC follow the same rule, so the Primary DNS is the Main DC and it's self as the Secondary DNS, or is its self which should be the Primary DNS? I've had a scout about on the net and can't really find an answer. Probably the search terms I'm using.

    3. Reverse lookup zones. I currently don't have any. Searching the edugeek most people say it will work without, but it's easy enough to set up so might as well be there. So, having found a simple guide on how to do it, probably a daft question, but do I create a primary zone for each of the ranges I've got? So if I had 10.10.1.0, 10.10.2.0 and 10.10.3.0, I'd create a primary zone for each one?

    Thanks

    Cache

  2. #2

    SYNACK's Avatar
    Join Date
    Oct 2007
    Posts
    11,271
    Thank Post
    884
    Thanked 2,749 Times in 2,322 Posts
    Blog Entries
    11
    Rep Power
    785
    Quote Originally Posted by Cache View Post
    1. The DC's I'm assuming shouldn't have the ISP's DNS either, right? If not, then presumably, the Main DC has it's self configured as the primary DNS and the other DC as it's Secondary DNS and then the forwarders will take care of that, is that right?
    Nope, just itself as the primary and the other DC as the secondary, all external DNS resolution should be handled by the fowarders in the DNS server.

    Quote Originally Posted by Cache View Post
    2. Should the other DC follow the same rule, so the Primary DNS is the Main DC and it's self as the Secondary DNS, or is its self which should be the Primary DNS? I've had a scout about on the net and can't really find an answer. Probably the search terms I'm using.
    I usually have them reffering to themselves first then another second.

    Quote Originally Posted by Cache View Post
    3. Reverse lookup zones. I currently don't have any. Searching the edugeek most people say it will work without, but it's easy enough to set up so might as well be there. So, having found a simple guide on how to do it, probably a daft question, but do I create a primary zone for each of the ranges I've got? So if I had 10.10.1.0, 10.10.2.0 and 10.10.3.0, I'd create a primary zone for each one?
    I would create reverse lookup zones for each of the subnets that your DNS covers as it makes certain things quicker. Can't remember the eaxct steps but it is not to hard, just right click on the reverse zones bit in DNS and add a new one.

  3. Thanks to SYNACK from:

    Cache (14th June 2009)

  4. #3
    Cache's Avatar
    Join Date
    Apr 2008
    Location
    Cumbria
    Posts
    1,303
    Thank Post
    487
    Thanked 190 Times in 184 Posts
    Blog Entries
    3
    Rep Power
    67

    Thumbs up

    Thanks for that SYNACK, put my mind at rest about what I'd planned to do.

    Does it make any difference whether I make the other DC have the Main DC as it's primary DNS server or not? Any advantages/disadvantages having it either way?

  5. #4


    Join Date
    Feb 2007
    Location
    Northamptonshire
    Posts
    4,706
    Thank Post
    354
    Thanked 807 Times in 722 Posts
    Rep Power
    348
    My personal view would be that if you're running DNS on the box itself should be the primary with A-N-Other as the secondary. No point forcing queries out to the main dc if 'itself' could handle it.

  6. Thanks to kmount from:

    Cache (14th June 2009)

  7. #5

    SYNACK's Avatar
    Join Date
    Oct 2007
    Posts
    11,271
    Thank Post
    884
    Thanked 2,749 Times in 2,322 Posts
    Blog Entries
    11
    Rep Power
    785
    Quote Originally Posted by kmount View Post
    My personal view would be that if you're running DNS on the box itself should be the primary with A-N-Other as the secondary. No point forcing queries out to the main dc if 'itself' could handle it.
    I agree, it also means they boot up much happier if the other server is offline.

  8. Thanks to SYNACK from:

    Cache (14th June 2009)

  9. #6


    Join Date
    Feb 2007
    Location
    Northamptonshire
    Posts
    4,706
    Thank Post
    354
    Thanked 807 Times in 722 Posts
    Rep Power
    348
    True that.

  10. #7
    Cache's Avatar
    Join Date
    Apr 2008
    Location
    Cumbria
    Posts
    1,303
    Thank Post
    487
    Thanked 190 Times in 184 Posts
    Blog Entries
    3
    Rep Power
    67
    That's fine then, I'll make a note to change the settings that way.

    Thanks again!

  11. #8

    m25man's Avatar
    Join Date
    Oct 2005
    Location
    Romford, Essex
    Posts
    1,680
    Thank Post
    49
    Thanked 481 Times in 348 Posts
    Rep Power
    143
    If you use the reverse zones option as desribed by Synack remember to configure the scavenging for all zones correctly and keep a close eye on the database for duplicate entries.
    Normally the zones will look after themselves but it's all to easy to fall into the polluted rDNS trap.

  12. #9

    Geoff's Avatar
    Join Date
    Jun 2005
    Location
    Fylde, Lancs, UK.
    Posts
    11,850
    Thank Post
    110
    Thanked 598 Times in 514 Posts
    Blog Entries
    1
    Rep Power
    227
    Just a minor nitpick, you should setup another dc as your dcs primary dns and itself as the secondary. The reason for this is it stops the nasty messages in the system event log when the dc can't register it's SRV records in DNS because although networking has come up the DNS server hasn't started.

  13. #10

    Join Date
    Aug 2005
    Location
    London
    Posts
    3,159
    Thank Post
    116
    Thanked 529 Times in 452 Posts
    Blog Entries
    2
    Rep Power
    125
    Quote Originally Posted by SYNACK View Post
    I agree, it also means they boot up much happier if the other server is offline.
    I think this is what the term "blissful ignorance" can be used to describe :-)

    Actually, the more technical phrase is "DNS Island". This was a real issue for Windows 2000; I can't find definitive info to say if it was fixed in 2003 and later (I think it was) but, basically, if each server points to itself then you can get to a situation where they stop talking to each other and this is a bad thing...

    I'm probably teaching egg sucking but, in general, a good starting point is to ask Microsoft how they think you should configure their products. Try googling:

    dns "best practice" site:microsoft.com

    (put whatever you're interested in in place of DNS!)

    This won't always get what you want - some of MS guidance is not sensible in schools (full control permissions on user folders, for example) - but it makes sense to start by looking at what they say.

  14. #11

    Geoff's Avatar
    Join Date
    Jun 2005
    Location
    Fylde, Lancs, UK.
    Posts
    11,850
    Thank Post
    110
    Thanked 598 Times in 514 Posts
    Blog Entries
    1
    Rep Power
    227

  15. #12

    sparkeh's Avatar
    Join Date
    May 2007
    Posts
    7,218
    Thank Post
    1,438
    Thanked 1,858 Times in 1,251 Posts
    Blog Entries
    22
    Rep Power
    559
    This reminds of something that said at the last EMBC conference when we were told that all machines should have their DNS servers in the list beneath our own internal DNS, incase our DNS was unavailable.

  16. #13

    Geoff's Avatar
    Join Date
    Jun 2005
    Location
    Fylde, Lancs, UK.
    Posts
    11,850
    Thank Post
    110
    Thanked 598 Times in 514 Posts
    Blog Entries
    1
    Rep Power
    227
    No no no no no no no! That's wrong.

  17. #14

    sparkeh's Avatar
    Join Date
    May 2007
    Posts
    7,218
    Thank Post
    1,438
    Thanked 1,858 Times in 1,251 Posts
    Blog Entries
    22
    Rep Power
    559
    Quote Originally Posted by Geoff View Post
    No no no no no no no! That's wrong.
    Well natually I didn't follow this as I thought it was wrong.

  18. #15

    SYNACK's Avatar
    Join Date
    Oct 2007
    Posts
    11,271
    Thank Post
    884
    Thanked 2,749 Times in 2,322 Posts
    Blog Entries
    11
    Rep Power
    785
    Quote Originally Posted by srochford View Post
    I think this is what the term "blissful ignorance" can be used to describe :-)

    Actually, the more technical phrase is "DNS Island". This was a real issue for Windows 2000; I can't find definitive info to say if it was fixed in 2003 and later (I think it was) but, basically, if each server points to itself then you can get to a situation where they stop talking to each other and this is a bad thing...

    I'm probably teaching egg sucking but, in general, a good starting point is to ask Microsoft how they think you should configure their products. Try googling:

    dns "best practice" site:microsoft.com

    (put whatever you're interested in in place of DNS!)

    This won't always get what you want - some of MS guidance is not sensible in schools (full control permissions on user folders, for example) - but it makes sense to start by looking at what they say.
    Hey, you're ruining my bliss and my carefully crafted ignorance

    I have configured them like this for quite some time under 2003 and have not had any issues with DNS over that time but I could just be lucky. I had a look at the MS post from Geoff but it does say that it reffers to Windows 2000 era servers. At that point my schools only had one each so it didn't affect me then either. Not sure of the best practice but will look it up at some point to see what MS's current opinion is on the matter



SHARE:
+ Post New Thread
Page 1 of 2 12 LastLast

Similar Threads

  1. DNS Flush / DNS Register
    By brahma in forum Windows
    Replies: 1
    Last Post: 18th July 2008, 10:29 AM
  2. DNS Problems... DCHP correct, DNS wrong
    By burgemaster in forum Windows
    Replies: 7
    Last Post: 27th June 2008, 12:05 PM
  3. Sophos configuration
    By Bobo in forum Windows
    Replies: 4
    Last Post: 27th June 2008, 11:52 AM
  4. 2 Seperate DC's Syncing users?
    By techyphil in forum Windows
    Replies: 8
    Last Post: 3rd June 2008, 12:37 PM
  5. Office configuration
    By mseaney in forum Windows
    Replies: 6
    Last Post: 1st December 2005, 01:38 PM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •