Subscribe to Windows IT Pro
May 14, 2001 12:00 AM

DNS Zone Types

Windows IT Pro
InstantDoc ID #21068
Rating: (1)

DNS plays an important role in creating an effective Windows 2000 Active Directory (AD) implementation. AD requires DNS and uses it for name resolution and, with the help of a new Resource Record (RR) type called SRV Records, for service location. Because AD relies on DNS for these services, Win2K offers a more scalable and efficient solution than Windows NT 4.0, which uses WINS. A DNS database known as a zone file contains RRs to link host names with their corresponding IP addresses. Win2K DNS supports two kinds of zone files, standard and AD integrated.

Standard Zone Files
Standard zone files are traditional DNS zone files. To use standard zone files, you create a zone on the DNS server that you plan to use to perform DNS database administration. This server becomes the primary zone server where all updates, such as RR additions or deletions, occur. When you create a DNS server to function as a secondary zone server, you specify the name or IP address of the primary zone server that will provide a copy of the zone file. You can use secondary zone servers to provide load balancing and a certain degree of fault tolerance. Secondary zone servers provide only limited fault tolerance because they continue to respond to DNS queries; secondary zone servers can’t perform any updates because they only have a read-only copy of the zone file. The primary zone server periodically replicates its zone file to the secondary zone server to ensure that the secondary zone server's copy is current. With earlier versions of Microsoft DNS, the primary zone server transfers a full copy of the zone file and overwrites the existing zone file on the secondary zone server. Win2K DNS supports Incremental Zone Transfers, which means that the primary zone server sends only changes that have occurred to the zone file since the last replication.

AD Integrated Zone Files
With Win2K, you can also use AD integrated zone files to incorporate zone file information into AD. With this approach, DNS uses AD for zone file storage and replication, which has advantages over standard zone types. Because the AD integrated zone file process uses AD's replication service, you don’t need to configure a separate replication topology. AD integrated zone files also eliminate the single point of failure that arises when a standard primary server goes down. With AD’s multimaster approach, you can make DNS changes at any domain controller (DC), and the changes automatically replicate to the other DCs in the domain according to AD’s default replication topology. Although both zone types support the dynamic update protocol, dynamic DNS (DDNS), only AD integrated zones support secure dynamic updates, which let you control who can update DNS and reserve a particular name for a specific server to use.

Keep in mind is that AD integrated zone files don't replicate between domains. This limitation follows the usual AD replication model in that most information replicates only to other DCs in the same domain. This issue is especially confusing because the Microsoft Management Console (MMC) DNS snap-in lets you create zones in multiple domains with the same name.

Creating Zones and Changing Zone Types
To create a new zone, right-click either the Forward or Reverse look up folder in the MMC DNS snap-in, and chose New Zone. A wizard appears and asks what type of zone you want to create. However, note that the option to create an AD integrated zone won't appear if you haven't already run DCPROMO. In such cases, you can create a standard zone and change it after you create your AD by right-clicking the zone name in the DNS snap in and choosing Properties. You can follow this same procedure whenever you need to change zone types.

Related Content:

ARTICLE TOOLS

Comments
  • Anonymous User
    7 years ago
    Feb 06, 2005

    What are the pros and cons of an ADIZ DNS??

  • Anonymous User
    7 years ago
    Feb 04, 2005

    No dog clues here. jtl

  • Cory Reed
    9 years ago
    Oct 28, 2003

    My Zones are AD Intergrated. Replication is scheduled for after hours, how does is changes made if Replication is not scheduled. Example I create a record for a machine in site1 and need it to be transfered to site2. If Replication is scheduled for off hours, how would this change be realized by remote sites.

  • Zoran Draganic
    11 years ago
    Sep 05, 2001

    I would like to add a short comment on this part of the text saying:
    " Keep in mind is that AD integrated zone files don't replicate between domains. This limitation follows the usual AD replication model in that most information replicates only to other DCs in the same domain. This issue is especially confusing because the Microsoft Management Console (MMC) DNS snap-in lets you create zones in multiple domains with the same name. "
    It's truth the replication of the dns file (rather object) goes with the replication of the Active Directory Domain partition, within the same domain, but it's still possible and will very often be a case during a migration process, that one Active Directory Integrated zone acts as a Master for the same Secondary zone running in another domain.
    regards

  • Troy Hiatt
    11 years ago
    May 29, 2001

    I have setup AD on a server along with NAT Routing. I want to use the DNS server to resolve internet names for browsing. How do I do it?

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.