heterogenous-multidomain-splitdns

  • Thread starter Thread starter Matt
  • Start date Start date
M

Matt

This post, if anyone is willing to participate may go on for a while. I am
hoping to create a dialog for my sake as well as the sake of others. If you
wish to participate and have useful input, please by all means I'd
appreciate your help.

I recently took a job at a company where I am tasked with "cleaning up the
dns." It was presented as an easy task and I think it may be harder and
will encompass more than just a flick of a switch. Without further ado,
here is the environment:

One forest.
One domain tree we'll call domain.com.
Eight child domains of domain.com e.g. abc.domain.com.
Six physical multi-continental sites - no logical sites used in active
directory.
Two domain controllers in the root domain domain.com we'll call the
controllers AD01.domain.com and AD02.domain.com.
Each of the eight domains has one domain controller and every one is a
global catalog.
AD01 (win2k3) runs a third party DNS package called Meta IP from
www.metainfo.com.
AD02 (win2k) runs win2k DNS as secondary's for all the zones on AD01.
Nothing is active directory integrated.
No remote sites have dns servers. The remote sites all point backwards
across the world to AD01 thru WAN links.
AD01 is set to forward to unix servers in our DMZ that host our public zones
(stupid).

My goal is to get rid of Meta IP and make every physical site have its own
active directory integrated DNS server.

Where is a good place to start. I feel overwhelmed!!!

I know this is a hodge podge of info and may not be enough. that is why i
am trying to start a dialog.

Please respond back with questions if you have them.

Thank you
Matt
 
hey Matt,
i think the best way to do this thing is to have one new child domain
created and have its DNS locally managed, either AD integrated or
otherwise.Then for all forward lookups you can use local ISP DNS and make
secondary zones for rest of your DNS zones on that server.This way for one
test child domain you are bypassing metainfo, once you see how the whole
situation will work out, you can start migrating DNS service locally and
getting secondary replications from other zones.
At any point in time, you need help you can email microsoft and they will
give u a response in 99 $..just a thought.If it is a mulitnational company
and spending yearly to outsource DNS/DHCP..they can afford this much.
Later

Raj
 
Back
Top