Account Options

  1. Sign in
The old Google Groups will be going away soon, but your browser is incompatible with the new version.
Google Groups Home
« Groups Home
Zone "type forward" vs. sub-domain delegation.
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  4 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Gabriele  
View profile  
 More options Sep 13 2007, 7:06 pm
Newsgroups: comp.protocols.tcp-ip.domains
From: "Gabriele" <ga...@gabro.net>
Date: Fri, 14 Sep 2007 01:06:07 +0200
Local: Thurs, Sep 13 2007 7:06 pm
Subject: Zone "type forward" vs. sub-domain delegation.
I would like to build a DNS hierarchy with a company-internal
"mycompany.com." domain (hosted on name servers running BIND) and an
"ad.mycompany.com." subdomain delegated to DNS administrators of a Microsoft
Active Directory environment.

I've seen that setting either forwarders (1) or zone-delegation (2) make
name resolution work even for sub-domain hosts:

1) zone "ad.mycompany.com" IN {
 type forward;
 forwarders {10.0.0.1; 10.0.0.2;};

};

2) $ORIGIN ad.mycompany.com.
@             IN      NS     ns1.ad.mycompany.com.
@             IN      NS     ns2.ad.mycompany.com.
ns1           IN      A      10.0.0.1
ns2           IN      A      10.0.0.2

Even if both works, I think option 2 is best as forwarders are set in
"named.conf" per-server configuration file, while the delegation is set in
the "domain.com" zone file that would be transfered to any secondary (slave)
name server.

What's your opinion?

Thanks in advance. - Gabriele


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Barry Margolin  
View profile  
 More options Sep 13 2007, 9:10 pm
Newsgroups: comp.protocols.tcp-ip.domains
From: Barry Margolin <bar...@alum.mit.edu>
Date: Thu, 13 Sep 2007 21:10:57 -0400
Local: Thurs, Sep 13 2007 9:10 pm
Subject: Re: Zone "type forward" vs. sub-domain delegation.
In article <fccfp1$lh...@nnrp.ngi.it>, "Gabriele" <ga...@gabro.net>
wrote:

Forwarding won't work if you're getting requests from caching
nameservers.  They send non-recursive requests, and forwarding is only
followed for recursive requests.  Also, the caching servers can cache
the delegation records, so from then on they'll go directly to the
ad.mycompany.com servers, rather than going through the mycompany.com
servers.

If the client machines are pointing directly to the mycompany.com
servers in their resolver configurations then there's not much
difference, other than the one you point out about only having to change
things in one place.

--
Barry Margolin, bar...@alum.mit.edu
Arlington, MA
*** PLEASE post questions in newsgroups, not directly to me ***
*** PLEASE don't copy me on replies, I'll read them in the group ***


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Gabriele  
View profile  
 More options Sep 19 2007, 5:51 pm
Newsgroups: comp.protocols.tcp-ip.domains
From: "Gabriele" <ga...@gabro.net>
Date: Wed, 19 Sep 2007 23:51:14 +0200
Local: Wed, Sep 19 2007 5:51 pm
Subject: Re: Zone "type forward" vs. sub-domain delegation.

"Barry Margolin" <bar...@alum.mit.edu> wrote in message

news:barmar-F86AD9.21105713092007@comcast.dca.giganews.com...

Thanks for your valuable insight about potential problems coming from
caching nameservers.

Is there a way to retrieve configuration information from a DNS server to
understand if a certain zone is set as type-forward or delegated? Can
NSLOOKUP assist in this investigation if I do not have administrative rights
over the parent DNS server?

Thanks in advance.
Gabriele


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Barry Margolin  
View profile  
 More options Sep 19 2007, 11:45 pm
Newsgroups: comp.protocols.tcp-ip.domains
From: Barry Margolin <bar...@alum.mit.edu>
Date: Wed, 19 Sep 2007 23:45:09 -0400
Local: Wed, Sep 19 2007 11:45 pm
Subject: Re: Zone "type forward" vs. sub-domain delegation.
In article <fcs5lc$np...@nnrp.ngi.it>, "Gabriele" <ga...@gabro.net>
wrote:

> Is there a way to retrieve configuration information from a DNS server to
> understand if a certain zone is set as type-forward or delegated? Can
> NSLOOKUP assist in this investigation if I do not have administrative rights
> over the parent DNS server?

No.  If you want to know how a nameserver is configured, you need to
have access to the configuration files.

If you aren't an administrator of the server, why do you care how it
does it?  All that matters is that it gives the correct answers.

--
Barry Margolin, bar...@alum.mit.edu
Arlington, MA
*** PLEASE post questions in newsgroups, not directly to me ***
*** PLEASE don't copy me on replies, I'll read them in the group ***


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »