I'm setting up a consolidated platform, but I've gotten a little lost in DNS.
With the Backnet DNS on the AD01 (and AD02, as I want 2) you set the DNS to deny recusrion, and delete the root hints.
On the FE server you set the Frontnet NIC to use its internal DNS server, and the Backnet NIC to use the AD01 DNS.
So here's where I am lost.![]()
How does the FE server get DNS updates for internet clients?
Are the Backnet Servers DNS all pointing to the AD DNS? I expect so, or they won't be able to register in the AD DNS properly. As they are pointing to a Local only DNS, they can't get on the net. Is the intent of this foe security? Doesn't it mandate the use of a WSUS server?
Is the stripping of the backnet DNS to save load on the AD server? With 2 AD servers, and 2 DNS on the backnet, am I ok to leave them able to use forwarders?
I'm thinking I can do what I want, but I'm also guessing there's a reason for doing it this way...
![]()
Shanky








Reply With Quote



Bookmarks