In
news.microsoft.com said:
What do you mean "Maybe you can get another box internally"?
port remap the new DNS server why?
And why we can't mix public and private data on a DNS.
Regards,
Mircea
If you look a few threads below this post to a thread called:
DNS A record has local IP NAT to a global ip, does it work??
I posted an explanation. I will re-post it here for your convenience, but I
would urge you to read the whole thread.
<start of post>
===========================
In
Joe M said:
Yes my Active directory Domain is eg.. mydomain.local.
No, the public domains are standard primary and there's 3 of them.
mydomain.net
mydomain.com
mydomain.org
This is how I typically set entries in one of them, it works
intermittently..
same as parent soa june.mydomain.net
same as parent ns june.mydomain.net
june A 192.168.100.60
june A 203.145.145.145
surfer A 192.168.100.70
surfer A 203.145.145.200
www alias june.mydomain.net (the 203.145.145.200
entry)
It's works intermittently. I want my DNS to support all 3 + more
domain names.
Your mixed private and public IPs in your zone just confirms what I
mentioned. You cannot mix these up in a zone or you will get the
undesireable effects you're experiencing. You'll have to separate them on
separate DNS servers. No real way around this, especially if the internal
servers are needed for AD. If not needed for AD, you'll still need two, one
for public data, one for private data or the internal folks will get an
external IP that is your NAT's WAN IP, which the NAT device will NOT send
the traffic back in so they won;'t be able to get to the web page.
They (either internal or external users) can get lucky due to Round Robin
functionality where it may just happen to give them the internal IP to get
to the internal site or the external IP to the external users. But it's a
50-50 shot. So they're either getting the private IP or public, so about 50%
of Internet users will get the public IP, the other 50% will get the private
IP, which would be useless to them.
Seaparate DNS servers...
========================================
<end of post>
--
Regards,
Ace
Please direct all replies to the newsgroup so all can benefit.
This posting is provided "AS IS" with no warranties.
Ace Fekay, MCSE 2000, MCSE+I, MCSA, MCT, MVP
Microsoft Windows MVP - Active Directory