PC Review


Reply
Thread Tools Rate Thread

DNS and Zone transfer

 
 
KJ
Guest
Posts: n/a
 
      11th May 2004
If the sending DNS server(WIn2k3 upgraded from win2k), a
subdomain, sends it's Zone file to the main, root, DNS
server(Unix), and the zone is Active Directory
Integrated, is there any reason the Unix box would
receive errors or fail to keep the zone file loaded? It
sometimes gets errors and at others, it receives zone
transfer. Is it necessary to send any zone file transfer
once you start pulling your own in? Is there any reason
to forward to root, especially if you have root hints
still installed?
 
Reply With Quote
 
 
 
 
Ace Fekay [MVP]
Guest
Posts: n/a
 
      12th May 2004
In news:b4b001c43784$fa61f130$(E-Mail Removed),
KJ <(E-Mail Removed)> posted their thoughts, then I
offered mine
> If the sending DNS server(WIn2k3 upgraded from win2k), a
> subdomain, sends it's Zone file to the main, root, DNS
> server(Unix), and the zone is Active Directory
> Integrated, is there any reason the Unix box would
> receive errors or fail to keep the zone file loaded? It
> sometimes gets errors and at others, it receives zone
> transfer. Is it necessary to send any zone file transfer
> once you start pulling your own in? Is there any reason
> to forward to root, especially if you have root hints
> still installed?



Doesn't sound like the ideal scenario. If you have child domains, the best
practice and recommendation is to use delegation from the DNS server hosting
the parent zone to the child DNS servers hosting the child zone. Then use a
forwarder back to the parent DNS.

AD Integrated zones act like a Primary zone for zone transfers, so I can't
remember any issues between BIND and MS DNS. I woiuld just insure there are
no firewalls in between and that zone transfers are allowed, maybe even try
specifically to the IP, or allow all.

I wouldn't alter the Root hints, that just complicates matters when
diagnosing and is not necessarily recommended. Just use the forwarders. If
already using Root Hints, then no forwarder is required. But would rather
see you use forwarding.

--
Regards,
Ace

Please direct all replies to the newsgroup so all can benefit.
This posting is provided "AS-IS" with no warranties and confers no
rights.

Ace Fekay, MCSE 2000, MCSE+I, MCSA, MCT, MVP
Microsoft Windows MVP - Active Directory

HAM AND EGGS: A day's work for a chicken; A lifetime commitment for a
pig. --
=================================


 
Reply With Quote
 
KJ
Guest
Posts: n/a
 
      12th May 2004
Started out supposedly being delegated, but the new
Internal network (behind firewall) needed a push to it so
went with zone transfer, then lost any delegation it
seemed because local web sites were not found, then after
receiving a zone transfer, it starts working. There still
are some glitches that users are not getting past Citrix
Nfuse site into that domain even though there are zone
files available on both sides now.

>-----Original Message-----
>In news:b4b001c43784$fa61f130$(E-Mail Removed),
>KJ <(E-Mail Removed)> posted their

thoughts, then I
>offered mine
>> If the sending DNS server(WIn2k3 upgraded from win2k),

a
>> subdomain, sends it's Zone file to the main, root, DNS
>> server(Unix), and the zone is Active Directory
>> Integrated, is there any reason the Unix box would
>> receive errors or fail to keep the zone file loaded? It
>> sometimes gets errors and at others, it receives zone
>> transfer. Is it necessary to send any zone file

transfer
>> once you start pulling your own in? Is there any reason
>> to forward to root, especially if you have root hints
>> still installed?

>
>
>Doesn't sound like the ideal scenario. If you have child

domains, the best
>practice and recommendation is to use delegation from

the DNS server hosting
>the parent zone to the child DNS servers hosting the

child zone. Then use a
>forwarder back to the parent DNS.
>
>AD Integrated zones act like a Primary zone for zone

transfers, so I can't
>remember any issues between BIND and MS DNS. I woiuld

just insure there are
>no firewalls in between and that zone transfers are

allowed, maybe even try
>specifically to the IP, or allow all.
>
>I wouldn't alter the Root hints, that just complicates

matters when
>diagnosing and is not necessarily recommended. Just use

the forwarders. If
>already using Root Hints, then no forwarder is required.

But would rather
>see you use forwarding.
>
>--
>Regards,
>Ace
>
>Please direct all replies to the newsgroup so all can

benefit.
>This posting is provided "AS-IS" with no warranties and

confers no
>rights.
>
>Ace Fekay, MCSE 2000, MCSE+I, MCSA, MCT, MVP
>Microsoft Windows MVP - Active Directory
>
>HAM AND EGGS: A day's work for a chicken; A lifetime

commitment for a
>pig. --
>=================================
>
>
>.
>

 
Reply With Quote
 
Ace Fekay [MVP]
Guest
Posts: n/a
 
      15th May 2004
In news:bb7c01c43810$c7737000$(E-Mail Removed),
KJ <(E-Mail Removed)> posted their thoughts, then I
offered mine
> Started out supposedly being delegated, but the new
> Internal network (behind firewall) needed a push to it so
> went with zone transfer, then lost any delegation it
> seemed because local web sites were not found, then after
> receiving a zone transfer, it starts working. There still
> are some glitches that users are not getting past Citrix
> Nfuse site into that domain even though there are zone
> files available on both sides now.
>


I cannot see how a delegation can be lost, if that is what you're hinting
at. A delegation just has pointers for the parent DNS to know what DNS
server hosts the child zone, so there is no zone transfers in a delegation
scenario.


--
Regards,
Ace

Please direct all replies to the newsgroup so all can benefit.
This posting is provided "AS-IS" with no warranties and confers no
rights.

Ace Fekay, MCSE 2000, MCSE+I, MCSA, MCT, MVP
Microsoft Windows MVP - Active Directory

HAM AND EGGS: A day's work for a chicken; A lifetime commitment for a
pig. --
=================================


 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
difference between zone transfer / reload zone Tim Moor Microsoft Windows 2000 DNS 4 7th Apr 2006 08:42 PM
Stub zone and zone transfer Wensi Peng Microsoft Windows 2000 DNS 0 13th Apr 2005 06:28 PM
Zone transfer and AD danieltan@time.net.my Microsoft Windows 2000 DNS 4 30th Mar 2005 06:40 AM
The zone is locked for zone transfer or update Irena Microsoft Windows 2000 DNS 3 25th Aug 2004 04:26 AM
Re: dns zone transfer Ace Fekay [MVP] Microsoft Windows 2000 Active Directory 0 22nd Jul 2003 03:48 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 02:52 PM.