»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 02-24-2004, 08:08 PM   #1 (permalink)
Registered User
 
Join Date: Dec 2001
Location: Adelaide, Australia
Posts: 5,267
Mickwish is on a distinguished road
Kids Setting up Active Directory and DNS

OK, I'm trying to fiddle with ADS on my home LAN. Not that it needs it, just for my own information.

I have an internal server running win2k Advanced Server. The LAN currently uses workgroup config, and accesses the net using an IPCop linux firewall/router. At present, I resolve DNS through IPCop.

Now, as I understand it, to set up ADS I MUST have a DNS server on a win2k server machine and create a FQDN for use. Firstly, is that right? Is there any way I can run a DNS server ONLY for the LAN, and still use IPCop to resolve for internet addresses??? Or some other way to make it work?? Does the FQDN for local use have to be internet registered?

I know this is a field all of it's own, but I'm trying to get a handle on how it could work for me.

Can anyone give me some tips, in posts less that 50 pages long or with some useful links? This is an area of networking I have yet to explore muich, so go easy on the acronyms and terminology, please.

Thanks
Mick

Mickwish is offline   Reply With Quote
Old 02-24-2004, 08:18 PM   #2 (permalink)
Registered User
 
M_Six's Avatar
 
Join Date: Oct 2001
Location: Urbana, Illinois
Posts: 1,845
M_Six is on a distinguished road
You could set your DNS server to forward only. Set the forwarder IP to the IPCop DNS server. (I know it sounds weird, but the "forwarder" is the server you forward DNS requests to. In other words, the outside DNS server.)

And yes, you must have a DNS server to run AD, but it does not need to be a registered domain name. Make sure you set your firewall to block all incoming DNS requests.
__________________
Mark}--->8-8->
If you're not the lead dog, the scenery never changes.
M_Six is offline   Reply With Quote
Old 02-24-2004, 08:22 PM   #3 (permalink)
Registered User
 
Join Date: Dec 2001
Location: Adelaide, Australia
Posts: 5,267
Mickwish is on a distinguished road
Thanks M-Six. I will try that, but I hit a slight snag. It won't let me start the DNS service at all - something to do with root hints??? Any clues?

Thanks
Mick
__________________
Testing, testing....
Mickwish is offline   Reply With Quote
Old 02-24-2004, 08:23 PM   #4 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
Quote:
ADS I MUST have a DNS server on a win2k server machine and create a FQDN for use. Firstly, is that right?
no. But the DNS server must bsupport Service Locator (SRV) resource records (defined in RFC 2782). Some versions of BIND do this too.

Quote:
Is there any way I can run a DNS server ONLY for the LAN
yes (but why would you want to?)


Quote:
Does the FQDN for local use have to be internet registered?
no
DVNT1 is offline   Reply With Quote
Old 02-24-2004, 08:25 PM   #5 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
oops, that last post took a while to finish (got side tracked )


Here's a decent AD link to start with http://labmice.techtarget.com/active...ry/default.htm
DVNT1 is offline   Reply With Quote
Old 02-24-2004, 08:27 PM   #6 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
link on some DNS help http://support.microsoft.com/default...b;en-us;301197
DVNT1 is offline   Reply With Quote
Old 02-24-2004, 08:27 PM   #7 (permalink)
Registered User
 
Join Date: Dec 2001
Location: Adelaide, Australia
Posts: 5,267
Mickwish is on a distinguished road
Quote:
Originally posted by DVNT1
yes (but why would you want to?)
'Cause I'm a fiddlin' fool, that's why.

Actually I thought if I could use ADS and still use IPCop for DNS it would be easier. But maybe I would be better off using the win2k server box to do all DNS for me. If I can ever get DNS service started, that is.

Cheers
Mick
Mickwish is offline   Reply With Quote
Old 02-24-2004, 08:31 PM   #8 (permalink)
Registered User
 
Join Date: Oct 2001
Location: TOO close to Wash DC
Posts: 7,956
vass0922 is on a distinguished road
make sure you delete the ROOT dns '.' ... you are definately not a root dns server

Sorry to inform you
__________________
<< Insert exceedingly large and overly verbose message of how 1337 you are here including full specs of every vehicle you've ever driven and PC you've owned >>
vass0922 is offline   Reply With Quote
Old 02-24-2004, 08:32 PM   #9 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
Quote:
Originally posted by Mickwish
...I thought if I could use ADS and still use IPCop for DNS it would be easier. But maybe I would be better off using the win2k server box to do all DNS for me....
I would setup your LAN DNS to use the W2K DNS only, and have it resolve DNS using your ISP's DNS IP addresses listed in the Forwarders. Often this is the fastest way to resolve host names.

You could have the W2K server simply not resolve Internet hosts and put two DNS IP adddresses in your clients (W2k server as Primary DNS, and IPCOP as secondary DNS).



Quote:
Originally posted by vass0922
make sure you delete the ROOT dns '.' ...
..and instructions for that are at the bottom of the last link I posted
DVNT1 is offline   Reply With Quote
Old 02-24-2004, 08:37 PM   #10 (permalink)
Registered User
 
Join Date: Dec 2001
Location: Adelaide, Australia
Posts: 5,267
Mickwish is on a distinguished road
Ah, I think I found it. I installed ADS before I tried to coinfigure DNS. Am deleting ADS now, so will see if I can configure DNS after that.

Cheers
Mick
__________________
Testing, testing....
Mickwish is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 06:15 PM.