Forwarders

G

Guest

I have a couple of issues going on.

I am working on a network which has the IPSs DNS servers listed on the name
server tab on the forward lookup zones. The DC is able to resolve websites.
When I take the DNS servers out of the Name Server listing and add them as
forwaders I lose internet on the DC as well as across the network. I am at a
loss to explain why.

I have two forward DNS zones. One zone appears to be normal with subfolders
listed such as _msdcs _sites etc. The second zone does not which tells me
that I need to reset the DNS. I need to know the procedure to allow active
directory to rebuild the zone properly.

I also need to know about recursive and if it is recommended to have on or
off.
 
H

Herb Martin

jjarmel said:
I have a couple of issues going on.

I am working on a network which has the IPSs DNS servers listed on the
name
server tab on the forward lookup zones.

Of the DNS Server console, right?
The DC is able to resolve websites.
When I take the DNS servers out of the Name Server listing and add them as
forwaders I lose internet on the DC as well as across the network. I am
at a
loss to explain why.

If those other DNS servers cannot resolve Internet names this makes
perfect sense, and why would you wish to forward to internal Server
anyway, unless they are for "other zones" inside a multi-domain environment?
I have two forward DNS zones. One zone appears to be normal with
subfolders
listed such as _msdcs _sites etc. The second zone does not which tells
me
that I need to reset the DNS.

What is the PURPOSE of the "second zone"? Who put it there? What is its
name (in relation to your "AD Support Zone")?

Might be perfectly normal.
I need to know the procedure to allow active
directory to rebuild the zone properly.

Unless it is for an AD Domain it is likely just fine.

Is it for an AD domain?
I also need to know about recursive and if it is recommended to have on or
off.

Normally you should let the INTERNAL DNS Server FORWARD to the
DNS server at your ISP or at your Firewall/Gateway to the Internet.

If you do this is is normal to CHECK "Do not use recursion" on the
Forwarding
tab of the INTERNAL DNS Servers -- this will make them totally dependent
on the reliability of the Forwarders (ISP or Gateway) but if those are
reliable then
this is the most secure and more efficient way to do it.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top