In
Wallace said:
Example:
DNS Server: 192.168.1.10
All other servers: 192.168.1.10 - 20
Admin clients: 192.168.2.21 - 30
Regular clients: 192.168.2.30 - 80
I want to allows the entire 192.168.1.x network to have access to do
"ls", or zone transfers.
Do I have to put in each IP address, or can I put in a network range?
That is the only way you can do it you cannot just put in a Network range.
You can't do it in the registry either here is the paragraph that refers to
zone transfers from the below link.
The Microsoft DNS server allows specification of a secondary server list.
Note that it is a list of secondaries for this zone on this server. It need
not be a complete list of secondaries for the zone. Its purpose is to give
administrators a fine degree of control over the replication graph for a
zone.
This list has two functions:
a.. Servers in this list are notified when a new version of the zone is
available.
b.. If the SecureSecondaries registry key (see below) is used, zone
transfers are refused to servers not in this list.
The SecondaryServers key is not a list of dotted IP strings, but a counted
array of raw IP addresses in net byte order. It should be configured through
the Zone Properties, Notify dialog box in the administrator tool. Editing
the registry key is discouraged. Especially, do NOT delete this registry key
to attempt to create an empty secondary list.
198408 Microsoft DNS Server Registry Parameters, Part 1 of 3
http://support.microsoft.com/default.aspx?scid=kb;EN-US;198408
The only other option is to allow zone transfers to all IP addresses.