T
tjadmsn
We have just migrated our DC's to 2003. We have our 2 internal DC's
running DNS and forwarding to our third DC in the DMZ, that is also a
DNS server, forwarding to our ISP. The internal DC's are pinging the
living mess out of the servers on the root hints page, and nothing is
getting through due to rules on our firewall. DNS is active directory
integrated and setup for secure transfers amongst themselves.
Is there anyway to keep the root hints on the DNS server in the DMZ
without having them replicate to the two internal DNS servers? Such as
"Do Not use Recursion" on the internal DNS servers? Deleting the
cache.dns did not work.
Also what constitutes the primary and secondary DNS servers? The
largest SOA? Our clients will be getting their configurations through
DHCP. For load balancing reasons we have DHCP configured to point the
clients to a primary DNS server that doesn't have the FSMO roles, and
the one that holds the roles as secondary DNS. My understanding is,
that if DNS is integrated, all the DNS servers can be considered
primary dns servers?
running DNS and forwarding to our third DC in the DMZ, that is also a
DNS server, forwarding to our ISP. The internal DC's are pinging the
living mess out of the servers on the root hints page, and nothing is
getting through due to rules on our firewall. DNS is active directory
integrated and setup for secure transfers amongst themselves.
Is there anyway to keep the root hints on the DNS server in the DMZ
without having them replicate to the two internal DNS servers? Such as
"Do Not use Recursion" on the internal DNS servers? Deleting the
cache.dns did not work.
Also what constitutes the primary and secondary DNS servers? The
largest SOA? Our clients will be getting their configurations through
DHCP. For load balancing reasons we have DHCP configured to point the
clients to a primary DNS server that doesn't have the FSMO roles, and
the one that holds the roles as secondary DNS. My understanding is,
that if DNS is integrated, all the DNS servers can be considered
primary dns servers?