Read inline please.
In
Bob Dole said:
Good answers but I still don't get it. Do I have to have 2 DNS
servers then? Yes.
One to be authoritative for my websites, email server
and then another to be recursive for my internal network? Yes.
I have
looked for a DNS layout/design setup but can't find one anywhere.
I'm getting ready to switch to a Windows 2003 network so I would like
to set it up correctly.
Here is the main thing you have to look at, your internal network must have
a DNS server that can resolve internet names and resolve servers on the
internal network to the local IP addresses. If you also want to host your
own public zones, that DNS server must return only IP addresses that can be
used by internet users. If your DNS returns records that have internal IPs,
your sites and servers will not be available.
Right now my clients have their primary DNS setting pointing to my
Authoritative DNS server (which is set to be NOT recursive) so that
really doesn't make any sense at all because the clients are really
get the recursive lookup from the secondary DNS setting.
It really looks like I need 4 DNS servers. 2 to be authoritative for
my websites, email server. And then 2 to be my internal Primary and
Secondary DNS that I set my clients to use. So these will be
recursive and Open. Is that what I have to do???
RFCs require at least two DNS servers for public domains. It doesn't mean
you need two DNS servers, but you need someone to host Secondary zones for
you it you don't. It is wise to have someone else host Secondary zones and a
backup mail server so that if your link goes down you're not dead in the
water without a row. Some ISPs will do this for you, whether yours does or
not you'll need to drop them a line to find out. As for whether you actually
need two internal DNS servers for your clients, that depends on how many
clients you have and how important it is to you to have internal redundancy.
--
Best regards,
Kevin D. Goodknecht Sr. [MVP]
Hope This Helps
===================================
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
===================================
http://www.lonestaramerica.com/
http://support.wftx.us/
http://message.wftx.us/
===================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
===================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
===================================