Friday, December 4, 2009

Setting Up the Domain Name System for Active Directory

Summary

The Domain Name System (DNS) is the Active Directory locator in Windows 2000. Active Directory clients and client tools use DNS to locate domain controllers for administration and logon. You must have a DNS server installed and configured for Active Directory and the associated client software to function correctly. This article guides you through the required DNS configuration.

NetBIOS name resolution (WINS server, LMHosts file, or NetBIOS broadcast) is still required for earlier versions of Windows to resolve network resources on an Active Directory domain.

NOTE: A Windows 2000 Server CD-ROM is required to complete Setup. Installing the operating system from a network share does not work in some scenarios.

Experienced DNS administrators are encouraged to read the steps involved in configuration, and modify them to suit different scenarios. The steps in this article outline a single, simple configuration and do not represent the only possible configuration.

MORE INFORMATION
DNS Server Requirements Microsoft recommends that you use Microsoft DNS Server...

DNS Server Requirements

Microsoft recommends that you use Microsoft DNS Server as supplied with Windows 2000 Server as your DNS server. However, Microsoft DNS is not required. The DNS server that you use:
  • Must support the SRV RR (RFC 2052).
  • Supports the dynamic update protocol (RFC 2136).
Version 8.1.2 and later of BIND (a popular DNS server implementation) supports both the SRV RR and dynamic update. (Version 8.1.1 does support dynamic updates but it has flaws that were fixed in 8.1.2.) If you are using a version of BIND that does not support dynamic update, you need to manually add records to the DNS server.

NOTE: Microsoft DNS, as included with Microsoft Windows NT 4.0 Server, does not support the SRV record. Use DNS Server that is provided with Windows 2000 Server.


Starting with a Windows 2000-Based Stand-Alone Server

This server becomes a DNS server for your network. You can also promote it to the domain controller role at a later time.

In the first step, you assign this server a static Internet Protocol (IP) configuration. DNS servers should not use dynamically assigned IP addresses, because a dynamic change of address could cause clients to lose contact with the DNS server.

Configure TCP/IP

  1. Click Start, point to Settings and then click Control Panel.
  2. Double-click Network and Dial-up Connections.
  3. Right-click Local Area Connection, and then click Properties.
  4. Click Internet Protocol (TCP/IP), and then click Properties.
  5. Assign this server a static IP address, subnet mask, and gateway address.
  6. Click Advanced.
  7. Click the DNS Tab.
  8. Select "Append primary and connection specific DNS suffixes"
    Check "Append parent suffixes of the primary DNS suffix"
    Check "Register this connection's addresses in DNS"

    If this Windows 2000-based DNS server is on an intranet, it should only point to its own IP address for DNS; do not enter IP addresses for other DNS servers here. If this server needs to resolve names on the Internet, it should have a forwarder configured.
  9. Click OK to close the Advanced TCP/IP Settings properties.
  10. Click OK to accept the changes to your TCP/IP configuration.
  11. Click OK to close the Local Area Connections properties.

    NOTE: If you receive a warning from the DNS Caching Resolver service, click OK to dismiss the warning. The caching resolver is trying to contact the DNS server, but you have not finished configuring the server.
  12. Continue to the next step to install Microsoft DNS Server.

Install Microsoft DNS Server

  1. Click Start, point to Settings, and then click Control Panel.
  2. Double-click Add/Remove Programs.
  3. Click Add and Remove Windows Components.
  4. The Windows Components Wizard starts. Click Next.
  5. Click Networking Services, and then click Details.
  6. Click to select the Domain Name System (DNS) check box, and then click OK.
  7. Click OK to start server Setup. The DNS server and tool files are copied to your computer.
  8. Continue to the next step to configure the DNS server.

Configure the DNS Server Using DNS Manager

These steps guide you through configuring DNS by using the DNS Manager snap-in in Microsoft Management Console (MMC).
  1. Click Start, point to Programs, point to Administrative Tools, and then click DNS Manager. You see two zones under your computer name: Forward Lookup Zone and Reverse Lookup Zone.
  2. The DNS Server Configuration Wizard starts. Click Next.
  3. Right-click Forward Lookup Zone, and then click Properties.
  4. Choose your DNS server to be a root server. Click Next.
  5. Choose to add a forward lookup zone. Click Next.
  6. The new forward lookup zone must be a primary zone so that it can accept dynamic updates. Click Primary, and then click Next.
  7. The new zone contains the locator records for this Active Directory domain. The name of the zone must be the same as the name of the Active Directory domain, or be a logical DNS container for that name.

    For example, if the Active Directory domain is named "support.microsoft.com", legal zone names are "support.microsoft.com", "microsoft.com", or "com". Type the name of the zone, and then click Next.

    NOTE: If you name the zone "com" we will believe that we are authoritative for the "com" domain and never forward any requests that we can not answer out to the real "com" domain servers. The same would be true if you named it "microsoft.com", you would never use your forwarder to resolve requests from the real "microsoft.com" servers.
  8. Accept the default name for the new zone file. Click Next.
  9. Choose not to add a reverse lookup zone now. Click Next.

    NOTE: Experienced DNS administrators may want to create a reverse lookup zone, and are encouraged to explore this branch of the wizard.
  10. Click Finish to complete the Server Configuration Wizard.
  11. After the Server Configuration Wizard is finished, DNS Manager starts. Proceed to the next step to enable dynamic update on the zone you just added.

Enable Dynamic Update on the Forward Lookup Zone

  1. In DNS Manager, expand the DNS Server object. Expand the Forward Lookup Zones folder.
  2. Right-click the zone you created, and then click Properties.
  3. On the General tab, click to select the Allow Dynamic Update check box, and then click OK to accept the change.
  4. DNS server configuration is finished. Proceed to the next step if you want to promote this DNS server to be the first domain controller in the enterprise. This is the recommended path.
  5. If you decide to use a different computer as your first domain controller, the configuration instructions in the previous sections of this article apply to that domain controller after you have installed Windows 2000.

Promote This Server to Domain Controller (Optional--Recommended)

Promote this server to the domain controller role by using the Dcpromo.exe utility.

For additional information about promoting and demoting domain controllers, click the article number below to view the article in the Microsoft Knowledge Base:
238369 (http://support.microsoft.com/kb/238369/EN-US/ ) How to Promote and Demote Domain Controllers in Windows 2000
After the server has been promoted to the domain controller role, the DNS server can use the Active Directory Storage Integration feature (this is the recommended path). Proceed to the next step if you want to use Active Directory Storage Integration for DNS.

Enable Active Directory Integrated DNS (Optional--Recommended)

Active Directory Integrated DNS uses the directory for the storage and replication of DNS zone databases. If you decide to use Active Directory Integrated DNS, DNS runs on one or more domain controllers and you do not need to set up a separate DNS replication topology.
  1. In DNS Manager, expand the DNS Server object.
  2. Expand the Forward Lookup Zones folder.
  3. Right-click the zone you created, and then click Properties.
  4. On the General tab, the Zone Type value is set to Primary. Click Change to change the zone type.
  5. In the Change Zone Type dialog box, click DS Integrated Primary, and then click OK.
  6. The DNS server writes the zone database into Active Directory.
  7. Right-click the zone named ".", and then click Properties.
  8. On the General tab, the Zone Type value is set to Primary. Click Change to change the zone type.
  9. In the Change Zone Type dialog box, DS Integrated Primary, and then click OK.


APPLIES TO
  • Microsoft Windows 2000 Server
  • Microsoft Windows 2000 Advanced Server
  • Microsoft Windows 2000 Datacenter Server

No comments:

Post a Comment