Jump to content

Recommended Posts

Posted

What is the best practice for setting up AD?

 

How should I go about setting up the name space? If I had a domain what are the reasons not to setup the domain name in AD the same as my external one?

 

I had a look but I could not find anything set in stone on the web so after your thoughts on this one.

Posted

Hi

 

There's plenty on these specific topics on the MSFT website to include best practices.

 

Generally you should keep your external and internal namespace separate, this can cause issue with DNS and lookups. For detailed explanation see the AD planning guide on the MSFT website, if you can find I'll send the link.

 

Sukh

Posted
Cheers for that Sukh. You put the right keywords in there which seems to have put the right results up in Google!!

 

:)

 

Once you know how to Google! you can work out anything hehe

 

Key is just to keep AD organized and structured, keep external and internal name space separate (shocking how many people don't)

 

James.

Posted

 

Key is just to keep AD organized and structured, keep external and internal name space separate (shocking how many people don't)

 

 

I know that split DNS can be useful (so if you query my public facing DNS you only see the records I want you to see and you don't see the details of my internal servers) but why else is it needed? (I've worked in places which do split and don't split and have good reasons for that so I'd guess I'm wondering why you're so definite that you should split)

Posted
I know that split DNS can be useful (so if you query my public facing DNS you only see the records I want you to see and you don't see the details of my internal servers) but why else is it needed? (I've worked in places which do split and don't split and have good reasons for that so I'd guess I'm wondering why you're so definite that you should split)

 

Don't get me wrong I have seen it setup not splitting the DNS before i in fact worked with it prior to moving over the split DNS, I guess people do have right reasons as to why they do it that way but there has been a few common faults with doing it. I'm not saying that if someone already has it in place it is a massive problem that they need to change but if your looking at re-building your Domain then I personally recommend and as sukh pointed out it is MSFT best practice to do so, and therefore in this case i am recommending that the OP considers the split dns route. :)

 

James.

Posted

Also - try to aVoid .local if you really want to future proof. Just in case someone gets the bright idea for some dumb reason to want Macs integrated into your network. Macs use .local which conflicts with heir bonjour service. There are work arounds but to be safe you could avoid it by not using .local.

 

I work for Paradise Unified School District. To make it simple our domain is paradise.usd. :). Looks neat too! Lol. Ohh the joys

Of bein in IT. haha.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...