"Zzzzzz" <iscubafanatic[ at ]hotmail.com> wrote in message news:1176750982.160297.34350[ at ]n59g2000hsh.googlegroups.com...
[Quoted Text] > Hi Herb > > Thanks for the information; I would like to ask for clarification on > two points? > > In regards to the first question on Preferred and Alternate DNS > settings, part of your answer was: > "Usually I would say, point them to themselves as Preferred for WAN > separated DCs and at each other for DNS servers local to each other." > > I am unclear as to what you mean by "WAN separated DCs"
Separated by WAN lines. DC(s) at one site, other DC(s) at another site.
> and "local to each other";
DCs within the same Site, or high-speed LAN location.
> do you mean, in my case Preferred on DC1 points to DC2's > DNS and vice versa as they are local to each other, and Alternate to > themselves?
Yes. This avoids the spurious startup errors for AD Integrated DNS and isn't terribly inefficient since they are within the same (high speed, reliable) network.
> Also > > In regards to using recursion, you said: > "Generally you do NOT want DCs or even other internal DNS servers > doing recursion -- this would mean they would need to (possibly) visit > "EvilHackersRUs.com". > > Are you suggesting clicking the check box "Do not user recursion for > this domain"
Yes. My focus was on setting them to use forwarders - best at your OWN firewall/gateway to the Internet, but the ISP is not a terrible choice in most cases.
Once you have a reliable forwarder, check that box on the Forwarders tab.
-- Herb Martin, MCSE, MVP http://www.LearnQuick.Com (phone on web site)
|