dns replication in a single forest w/ multiple child domains
i'm trying find out what's best practice and/or suggestions replicating dns zones in ad environment. in our environment, root domain set replicate "all dns servers in forest" while child domains configured replicate "to domain controllers in active directory domain child.domain.local. dns servers configured forwarders forward "all other dns domains" requests respective isp's dns servers.
1. should root dns zone replicating dns servers in forest. allow child domain admin edit, delete or add records in root dns zone since it's being replicated dns server under control?
2. should child domains "change zone replication scope" changed "to domain controllers in active directory domain child.domain.local" "to dns servers in active directory domain child.domain.local." i've read "to domain controllers in active directroy domain.." legacy compatibility , shouldn't used if of domain controllers 2003/2008 case us.
in advance suggestions or links documents might give me better understanding on how should proceed. thanks.
hi
configuring dns zone replications depends upon requirements. if child domain contains editable copies of root dns zone(ad integrated primary zones) admin child domain can make changes root dns zone.
you can 1 thing create secondary zone or stub zone of root dns zone on child dns server. make sure wont have editable copies of dns records on child dns servers. or can use conditional forwarder.
change zone replication scope dns servers in active directory domain in child domain.
thanks
dinesh
please vote if answer helped you.
Windows Server > Network Infrastructure Servers
Comments
Post a Comment