Maual Widows Domai 1: Cofigurig Domai Name System (DNS) for Active Directory Cofigure zoes I Domai Name System (DNS), a DNS amespace ca be divided ito zoes. The zoes store ame iformatio about oe or more DNS domais. For each DNS domai ame that is icluded i a zoe, the zoe becomes the authoritative source for iformatio about that domai. A zoe starts as a storage database for a sigle DNS domai ame. If other domais are added below the domai that is used to create the zoe, these domais ca either be a part of the same zoe or belog to aother zoe. DNS zoes ca be stored i the domai or applicatio directory partitios of Active Directory Domai Services (AD DS). A partitio is a data cotaier i AD DS that distiguishes data for differet replicatio purposes. You ca specify i which Active Directory partitio to store the zoe ad, cosequetly, the set of domai cotrollers amog which that zoe s data will be replicated. Cofigurig DNS Server Active Directory Itegratio The DNS Server service ca be cofigured to use AD DS to store zoe data. This makes it possible for the DNS server to rely o directory replicatio, which ehaces security, reliability ad ease of admiistratio. Follow these steps to create a DNS applicatio directory partitio: 1. Ope a commad prompt 2. Type the followig commad, ad press ENTER: dscmd <ServerName> /CreateDirectoryPartitio <FQDN> 3. After you create a Domai Name System (DNS) applicatio directory partitio to store a zoe, you must elist the DNS server that hosts the zoe i the applicatio directory partitio. To accomplish this, type the followig commad, ad press ENTER: dscmd <ServerName> /ElistDirectoryPartitio <FQDN> The followig table details the parameters i the above commads: Parameter dscmd <ServerName> /CreateDirectoryPartitio /ElistDirectoryPartitio <FQDN> Descriptio Specifies the ame of the commad-lie tool for maagig DNS servers. Required. Specifies the DNS host ame of the DNS server. You ca also type the IP address of the DNS server. To specify the DNS server o the local computer, you ca also type a period (.). Required. Creates a DNS applicatio directory partitio. Required. Elists a DNS server i a DNS applicatio directory partitio. Required. Specifies the ame of the ew DNS applicatio directory partitio. You must use a DNS fully qualified domai ame (FQDN). LearSmart Cloud Classroom: Video Traiig Mauals
Maual Widows The followig are some factors to cosider whe creatig a Active Directory Itegrated DNS zoe: Whe you decide which replicatio scope to choose, cosider that the broader the replicatio scope, the greater the etwork traffic caused by replicatio. For example, if you decide to have AD DS itegrated DNS zoe data replicated to all DNS servers i the forest, this will produce greater etwork traffic tha replicatig the DNS zoe data to all DNS servers i a sigle AD DS domai i that forest. AD DS-itegrated DNS zoe data that is stored i a applicatio directory partitio is ot replicated to the global catalog for the forest. The domai cotroller that cotais the global catalog ca also host applicatio directory partitios, but it will ot replicate this data to its global catalog. AD DS-itegrated DNS zoe data that is stored i a domai partitio is replicated to all domai cotrollers i its AD DS domai, ad a portio of this data is stored i the global catalog. This settig is used to support Widows 2000. If a applicatio directory partitio's replicatio scope replicates across AD DS sites, replicatio will occur with the same iter-site replicatio schedule as is used for domai partitio data. Widows Server 2008 supports the same zoe types as earlier versios of Microsoft Widows Servers alog with several ew features, icludig: backgroud zoe loadig for large DNS zoes, IP versio 6 (IPv6) support ad support for read-oly domai cotrollers (RODCs). The followig table lists the differet types of zoes that ca be cofigured i Widows Server 2008: Zoe Type Primary Secodary Stub GlobalNames Descriptio A primary zoe is the primary source for iformatio about this zoe, ad it stores the master copy of zoe data i a local file or i AD DS. Whe the zoe is stored i a file, by default, the primary zoe file is amed zoe_ame.ds ad is located i the %widir%\system32\ds folder o the server. A secodary zoe is the secodary source for iformatio about this zoe. The zoe at this server must be obtaied from aother remote DNS server computer that also hosts the zoe. This DNS server must have etwork access to the remote DNS server that supplies it with updated iformatio about the zoe. Because a secodary zoe is merely a copy of a primary zoe that is hosted o aother server, it caot be stored i AD DS. A stub zoe is a copy of a zoe that cotais oly the resource records that are ecessary to idetify the authoritative DNS servers for that zoe. A stub zoe keeps a DNS server hostig a paret zoe aware of the authoritative DNS servers for its child zoe. This helps maitai DNS ame-resolutio efficiecy. The GlobalNames zoe was added i Widows Server 2008 to hold sigle-label ames ad provide support for orgaizatios still utilizig WINS. Ulike WINS, the GlobalNames zoe is iteded to provide sigle-label ame resolutio for a limited set of host ames, typically corporate servers ad Web sites that are cetrally (IT) maaged. The GlobalNames zoe is ot iteded to be used for peer-to-peer ame resolutio, such as ame resolutio for workstatios, ad dyamic updates i the GlobalNames zoe are ot supported. Istead, the GlobalNames zoe is most commoly used to hold CNAME resource records to map a sigle-label ame to a fully qualified domai ame (FQDN). Table cotiued o ext page LearSmart Cloud Classroom: Video Traiig Mauals
Maual Widows Forward lookup Reverse lookup Forward lookup zoes support the primary fuctio of Domai Name System (DNS), that is, the resolutio of host ames to IP addresses. Forward lookup zoes provide ame-to-address resolutio. A reverse lookup zoe cotais poiter (PTR) resource records that map IP addresses to the host ame. Some applicatios, such as secure Web applicatios, rely o reverse lookups. A admiistrator creates a reverse lookup zoe oly if applicatios ruig o your etwork require it. There are two ways to cofigure a DNS zoe: 1. Use the New Zoe wizard i the DNS Maager. 2. Use the dscmd commad from a commad prompt. As Microsoft started with Widows Server 2003, there are more optios for cofigurig DNS available through the commad prompt tha from the GUI DNS Maager. Usig the New Zoe Wizard: 1. Ope DNS Maager. 2. I the cosole tree, right-click a Domai Name System (DNS) server, ad click New Zoe to ope the New Zoe Wizard. At this poit, the New Zoe Wizard has three choices: a. Primary Zoe b. Secodary Zoe c. Stub Zoe 3. Follow the wizard s istructios to create a Primary, Secodary or Stub Zoe. Usig a Commad Prompt: 1. Ope a Commad Prompt. 2. Type the followig, ad press ENTER: dscmd ServerName /ZoeResetType ZoeName Property [MasterIPaddress...] [/file FileName] {/OverWrite_Mem /OverWrite_Ds /DirectoryPartitio FQDN} LearSmart Cloud Classroom: Video Traiig Mauals
Maual Widows The followig table describes the optios for the dscmd commad: Value dscmd ServerName ZoeName Descriptio Specifies the ame of the commad-lie tool. Required. Specifies the DNS host ame of the DNS server. You ca also type the IP address of the DNS server. To specify the DNS server o the local computer, you ca also type a period (.). Required. Specifies the fully qualified domai ame (FQDN) of the zoe. Required. Oe of the followig zoe types: /Primary Stadard primary zoe. The FileName must be required. Property /DsPrimary Active Directory itegrated primary zoe. /Secodary Secodary zoe. You must specify at least oe MasterIPaddress. /Stub Stub zoe. You must specify at least oe MasterIPaddress. /DsStub Active Directory-itegrated stub zoe. You must specify at least oe MasterIPaddress. /file FileName MasterIPaddress... /OverWrite_Mem /OverWrite_Ds /Directory PartitioFQDN Required for /Primary. Specifies a file for the ew zoe. This parameter is ot valid for the /DsPrimary zoe type. Required for /Primary. Specifies the ame of the zoe file. This parameter is ivalid for the /DsPrimary zoe type. Required for /Secodary, /Stub ad /DsStub. Specifies oe or more IP addresses for the master servers of the secodary or stub zoe, from which it copies zoe data. /OverWrite_Mem overwrites existig DNS data usig the data i AD DS. /OverWrite_Ds overwrites Active Directory data with data i DNS. / DirectoryPartitio stores the ew zoe i the applicatio directory partitio that is specified by FQDN, such as: DomaiDsZoes.corp. example.microsoft.com. LearSmart Cloud Classroom: Video Traiig Mauals
Maual Widows Cofigurig a GlobalNames zoe While the specific steps for deployig a GlobalNames zoe ca vary somewhat depedig o the AD DS topology of differet etworks, the followig steps cover most situatios. 1. Create the GlobalNames zoe Create the zoe o a DNS server that is a domai cotroller ruig Widows Server 2008. The GlobalNames zoe is ot a special zoe type; rather, it is simply a AD DS-itegrated forward lookup zoe that is called GlobalNames. 2. Eable GlobalNames zoe support The GlobalNames zoe is ot available to provide ame resolutio util GlobalNames zoe support is explicitly eabled by usig the followig commad o every authoritative DNS server i the forest: dscmd <ServerName> /cofig /eableglobalamessupport 1 where ServerName is the DNS ame or IP address of the DNS server that hosts the GlobalNames zoe. To specify the local computer, replace ServerName with a period (.), for example: dscmd. /cofig /eableglobalamessupport 1. 3. Replicate the GlobalNames zoe a. To make the GlobalNames zoe available to all DNS servers ad cliets i a forest, replicate the zoe to all domai cotrollers i the forest; that is, add the GlobalNames zoe to the forest-wide DNS applicatio partitio. b. To limit the servers that will be authoritative for the GlobalNames zoe, create a custom DNS applicatio partitio for replicatig the GlobalNames zoe. 4. Populate the GlobalNames zoe For each server that will be able to provide sigle-label ame resolutio, add a alias (CNAME) resource record to the GlobalNames zoe. 5. Publish the locatio of the GlobalNames zoe i other forests If you wat DNS cliets i other forests to use the GlobalNames zoe for resolvig ames, add service locatio (SRV) resource records to the forest-wide DNS applicatio partitio, usig the service ame _globalames._msdcs ad specifyig the FQDN of the DNS server that hosts the GlobalNames zoe. I additio, ru the dscmdservername/cofig /eableglobalamessupport 1 commad o every authoritative DNS server i the forests that do ot host the GlobalNames zoe. Updatig DNS Servers Oce DNS has bee istalled ad cofigured, the ext step is to cofigure which type of update to allow from cliet ad server computers to the DNS Server. There are three choices: 1. Dyamic DNS (DDNS) 2. No-dyamic DNS (NDDNS) 3. Secure Dyamic DNS (SDDNS) Dyamic update eables DNS cliet computers to register ad dyamically update their resource records with a DNS server wheever chages occur. This reduces the eed for maual admiistratio of zoe records, especially for cliets that frequetly move or chage locatios ad use Dyamic Host Cofiguratio Protocol (DHCP) to obtai a IP address. LearSmart Cloud Classroom: Video Traiig Mauals