PC Review


Reply
Thread Tools Rate Thread

DNS devolution

 
 
=?Utf-8?B?UGF1bCBDb29r?=
Guest
Posts: n/a
 
      9th Mar 2007
I have a question in regards to DNS using the 'Append parent suffixes of the
primary DNS suffix'.
Example:
Windows 2000 domain (corp.123.net.au)
External DNS is 123.net.au
Internal zone is corp.123.net.au
Forwarders set to external DNS
Clients have 'Append parent suffixes of the primary DNS suffix' set by
default.

Client tries to lookup workstation1
corp.123.net.au is appended first (not found), 123.net.au is then appended
(still not found), it then appends .net.au which is then forwarded off to a
root zone. Not good business.

Is there a way to stop this on the DNS server or do you have to modify each
client and set the search list which turns this option off on the client?
 
Reply With Quote
 
 
 
 
Kevin D. Goodknecht Sr. [MVP]
Guest
Posts: n/a
 
      11th Mar 2007
Read inline please.
In news:2A2969B7-7BB8-47C6-AF72-(E-Mail Removed),
Paul Cook <(E-Mail Removed)> typed:
> I have a question in regards to DNS using the 'Append parent suffixes
> of the primary DNS suffix'.
> Example:
> Windows 2000 domain (corp.123.net.au)
> External DNS is 123.net.au
> Internal zone is corp.123.net.au
> Forwarders set to external DNS
> Clients have 'Append parent suffixes of the primary DNS suffix' set by
> default.
>
> Client tries to lookup workstation1
> corp.123.net.au is appended first (not found), 123.net.au is then
> appended (still not found), it then appends .net.au which is then
> forwarded off to a root zone. Not good business.
>
> Is there a way to stop this on the DNS server or do you have to
> modify each client and set the search list which turns this option
> off on the client?


There is a Group Policy you can apply to XP and later clients to stop DNS
Suffix devolution.
Or you can also apply a custom DNS suffix search list that does not include
the parent suffixes.

Both are found here:
Computer Configuration
-Administrative templates
-Network
-DNS Client


--
Best regards,
Kevin D. Goodknecht Sr. [MVP]
Hope This Helps
Send IM: http://www.icq.com/people/webmsg.php?to=296095728
===================================
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
===================================
http://www.lonestaramerica.com/
http://support.wftx.us/
http://message.wftx.us/
===================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
===================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
===================================


 
Reply With Quote
 
=?Utf-8?B?UGF1bCBDb29r?=
Guest
Posts: n/a
 
      11th Mar 2007
Thanks for the reply Kevin.

We have not implemented Group Policies as yet (it is on the cards) and there
are a mix of WinNT through to Win2k3 servers, so the the group policies will
be set for all new servers. Thought I might be scripting an update to all
machines.

Just in case anyone else needs to script this:
Registry key to update is:
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\SearchList
Just add a comma delimited list for Win2k and up and a space delimited list
for WinNT. You just need to determine if the machine is WinNT really.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
DNS Resolution - Domain devolution Mike Cavanagh Microsoft Windows 2000 DNS 4 19th Apr 2004 04:28 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 02:55 PM.