In news:2485FA9F-9244-4C9A-A705-(E-Mail Removed),
Ken <(E-Mail Removed)> posted a question
Then Kevin replied below:
> There are 10 DC's total. They are in one forest: domain.com.
> I have 2 DC's each in 4 child domains: na.domain.com; dev.domain.com;
> apac.domain.com; emea.domain.com.
>
> For example: NA.domain.com zone
> On the NA.domain.com DNS server - it says it is AD-Integrated.
> On the Apac.domain.com DNS server - that same zone says it is a
> secondary domain.
>
> That's just one example. I would like to change all my 2ndary zones
> to AD integrated.
Using your example, only the domain contollers for na.domain.com can have a
replicating AD integrated zone for na.domain.com.
This is where it is going to confuse you, while you can make apac.domain.com
AD integrated on the na.domain.com DC, BUT it will NOT replicate from the DC
for apac.domain.com. Only the DCs in apac.domain.com domain will get a
replicated zone for apac.domain.com.
However, the method of using Secondary zones on the DCs is incorrect you are
probably getting a lot of runtime errors due to all the zone transfers,
aren't you?
Here is how ir should be done.
On the forest parent DC for domain.com create these delegations in the
domain.com zone:
na
dev
apac
emea
Make these delegations to the DCs for these domains.
Then on all the child DCs make them forward ONLY to the Forest parent DNS
server AND check the box "Do not use recursion"
255248 - HOW TO Create a Child Domain in Active Directory and Delegate the
DNS Namespace to the Child Domain
http://support.microsoft.com/default...b;en-us;255248
>
> Can I just simply flip a switch to make that AD-Integrated, is it as
> simple as changing the type? Thanks.
It won't work this way in Windows 2000 the zone will not replicate across
domain partitions. Win2k3 would work better in your situation because Win2k3
allows DNS replication forest wide.
In the absence of Win2k3 the best situation for your scenario is to have a
parent DC with all the delegated child names at each location with the child
DCs and forward to it. Or for that fact you can use the Parent DC for all
DNS and it will replicate to all DCs in the Parent domain at all locations.
It would be less expensive to upgrade to Win2k3.
--
Best regards,
Kevin D4 Dad Goodknecht Sr. [MVP]
Hope This Helps
============================
--
When responding to posts, please "Reply to Group" via your
newsreader so that others may learn and benefit from your issue.
To respond directly to me remove the nospam. from my email.
==========================================
http://www.lonestaramerica.com/
==========================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
==========================================
Keep a back up of your OE settings and folders with
OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
==========================================