2.1 Installing the DNS Server Role Overview of the Domain Name System Role Overview of the DNS Namespace DNS Improvements for Windows Server 2008 Considerations.

Slides:



Advertisements
Similar presentations
Sergei Komarov. DNS  Mechanism for IP hostname resolution  Globally distributed database  Hierarchical structure  Comprised of three components.
Advertisements

MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 6 Managing and Administering DNS in Windows Server 2008.
Web Server Administration
Implementing Domain Name System
Domain Name System. DNS is a client/server protocol which provides Name to IP Address Resolution.
1 DNS. 2 BIND DNS –Resolve names to IP address –Resolve IP address to names (reverse DNS) BIND –Berkeley Internet Name Domain system Version 4 is still.
DNS的配置和排错 刘道军老师主讲 Module 1 如有疑问请与我联系: D
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 2: Name Resolution and DNS.
Chapter 9: Configuring DNS for Active Directory
4.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Hands-On Microsoft Windows Server 2003 Networking Chapter 6 Domain Name System.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 8: Managing and Troubleshooting DNS.
11.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 11: Introducing WINS, DNS,
Hands-On Microsoft Windows Server 2003 Administration Chapter 9 Administering DNS.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 5 Introduction to DNS in Windows Server 2008.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 7: Planning a DNS Strategy.
Chapter 10 Configuring DNS
Domain Name Services Oakton Community College CIS 238.
Windows Server 2008 Chapter 8 Last Update
Copyright line. Configuring DNS EXAM OBJECTIVES  An Introduction to Domain Name System (DNS)  Configuring a DNS Server  Creating DNS Zones  Configuring.
Lecturer : Ms.Trần Thị Ngọc Hoa Chapter 2 Methods Configuring Name Resolution Methods.
Hands-On Microsoft Windows Server 2008 Chapter 8 Managing Windows Server 2008 Network Services.
Configuring and Managing the DNS Server Role Lesson 4.
11.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 11: Introducing WINS, DNS,
DNS and Active Directory Integration
Chapter Overview Understanding DNS Creating Zones
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
Name Resolution Domain Name System.
TELE 301 Lecture 11: DNS 1 Overview Last Lecture –Scheduled tasks and log management This Lecture –DNS Next Lecture –Address assignment (DHCP)
Chapter 16 – DNS. DNS Domain Name Service This service allows client machines to resolve computer names (domain names) to IP addresses DNS works at the.
Module Overview Installing the DNS Server Role Configuring the DNS Server Role Configuring DNS Zones Configuring DNS Zone Transfers Managing and Troubleshooting.
Implementing DNS Module D 7: Implementing DNS
1 Objectives Discuss the basics of the Domain Name System (DNS) and its terminology Configure DNS clients Install a standard DNS server on Server 2008.
CN2140 Server II Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+
Windows Server 2008 R2 Domain Name System Chapter 5.
Module 2: Implementing DNS to Support Active Directory
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 7: Domain Name System.
Module 5: Planning a DNS Strategy. Overview Planning DNS Servers Planning a Namespace Planning Zones Planning Zone Replication and Delegation Integrating.
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 6: Name Resolution.
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network, Enhanced Chapter 6: Name Resolution.
October 8, 2015 University of Tulsa - Center for Information Security Microsoft Windows 2000 DNS October 8, 2015.
Fully Qualified Domain Names FQDNs. DNS Database A distributed, hierarchical database Resolves Fully Qualified Domain Names (FQDNs) to IP addresses –
1 Week 7 – DNS and ADDS Integration Review of DNS Concepts, Components, and Processes Install and Configure DNS in an AD DS Domain AD DS, DNS, and Windows.
Objectives Discuss the basics of the Domain Name System (DNS) and its terminology Configure DNS clients Install a standard DNS server on Server 2008 Create.
Module 6: Managing and Monitoring Domain Name System (DNS)
Configuring and Troubleshooting Domain Name System
Configuring Name Resolution and Additional Services Lesson 12.
Windows Server 2003 DNS 安裝設定與管理維護 林寶森
Domain Name System (DNS). DNS Server Service Overview of Domain Name System What Is a Domain Namespace? Standards for DNS Naming.
Module 6: Designing Name Resolution. Module Overview Collecting Information for a Name Resolution Design Designing a DNS Server Strategy Designing a DNS.
1 Internet Network Services. 2 Module - Internet Network Services ♦ Overview This module focuses on configuring and customizing the servers on the network.
DNS DNS overview DNS operation DNS zones. DNS Overview Name to IP address lookup service based on Domain Names Some DNS servers hold name and address.
Linux Operations and Administration
Web Server Administration Chapter 4 Name Resolution.
NT1330 Client Server Networking 2
Internet Naming Service: DNS* Chapter 5. The Name Space The name space is the structure of the DNS database –An inverted tree with the root node at the.
DNS, DHCP and VPN Borislav Varadinov Telerik Software Academy academy.telerik.com System Administrator
Configuring and Managing the DNS Server Role Lesson 4.
KAPLAN SCHOOL OF INFORMATION SYSTEMS AND TECHNOLOGY IT375 Window Enterprise Administration Course Name – IT Introduction to Network Security Instructor.
Understand Names Resolution
Module 5: Resolving Host Names by Using Domain Name System (DNS)
IMPLEMENTING NAME RESOLUTION USING DNS
Configuring and Troubleshooting DNS
Configuring and Managing the DNS Server Role
Working at a Small-to-Medium Business or ISP – Chapter 7
Working at a Small-to-Medium Business or ISP – Chapter 7
Managing Name Resolution
Working at a Small-to-Medium Business or ISP – Chapter 7
Chapter-2-NameServices
Windows Name Resolution
Presentation transcript:

2.1 Installing the DNS Server Role Overview of the Domain Name System Role Overview of the DNS Namespace DNS Improvements for Windows Server 2008 Considerations for Deploying the DNS Server Role

Overview of the Domain Name System role Domain Name System (DNS) is a name-resolution service that resolves names to numbers DNS is a hierarchical distributed database, this means that the database is separated logically, allowing many different servers to host the worldwide database of DNS names DNS is a system for naming computers and network services that is organized into a hierarchy of domains DNS is the foundation of the Internet naming scheme DNS supports accessing resources by using alphanumeric names InterNIC & MyNIC are responsible for managing the domain namespace DNS was created to support the Internet’s growing number of hosts

Overview of the DNS Namespace The DNS Namespace facilitates how a DNS client locates a computer It is organized hierarchically or in layers to distribute information across many servers

DNS Improvements for Windows Server 2008 New or enhanced features in the Windows Server 2008 version of DNS include: - Background zone loading - IP version 6 support - Support for read-only domain controller - Global single names

Considerations for Deploying the DNS Server Role The DNS Server role is critical in the configuration of Active Directory and Windows Network infrastructure When planning to deploy DNS, there are several considerations that need to be reviewed: - Server capacity planning - Where to place DNS servers - Service availability

2.2 Configuring the DNS Server Role What are the components of a DNS solutions DNS Resource Records What are Root Hints What is a DNS Query What are Recursive Queries What are Iterative Queries What is a Forwarder What is Conditional Forwarding How DNS Sever Caching works

What are the components of a DNS solution The components of a DNS solution include DNS servers, DNS servers on the Internet, and DNS clients

DNS Resource Records DNS resource records include : - SOA: Start of Authority - A: Host record - CNAME: Alias record - MX: Mail Exchange record - SRV: Service resources - NS: Name Servers - AAAA: IPv6 DNS record

What are Root Hints Root Hints contain the IP addresses for DNS root servers Root Hints are the list of 13 servers on the Internet that the Internet Assigned Numbers Authority (IANA) maintains and that the DNS server uses if it cannot resolve a DNS query by using DNS forwarder or its own cache The Root Hints are the highest servers in the DNS hierarchy and can provide the necessary information for a DNS server to perform an iterative query to the next lowest layer of the DNS namespace

What is a DNS Query A query is a request for name resolution and is directed to a DNS server Queries are recursive or iterative DNS clients and DNS servers both initiate queries DNS servers are authoritative or nonauthoritative for a namespace An authoritative DNS server for the namespace will either: - Return the requested IP address - Return an authoritative “No” A nonauthoritative DNS server for the namespace will either: - Check its cache - Use forwarders - Use root hints

What are Recursive Queries A recursive query is sent to a DNS server and requires a complete answer A recursive query can have 2 possible results: - It returns the IP address of the host requested - The DNS server cannot resolve an address For security reasons, it sometimes is necessary to disable recursive queries on a DNS server

What are Iterative Queries An iterative query directed to a DNS server may be answered with a referral to another DNS server Iterative queries provide a mechanism for accessing domain name information that resides across the DNS system, and enable servers to quickly and efficiently resolve names across many servers

What is a Forwarder A forwarder is a DNS server designated to resolve external or offsite DNS domain names A forwarder is a network DNS server that forwards DNS queries for external DNS names to DNS servers outside that network

What is Conditional Forwarding Conditional forwarding forwards requests using a domain name condition Conditional forwarding forwarder is a DNS server on a network that forwards DNS queries according to the query’s DNS domain name

How DNS Server Caching works DNS caching increases the performance of the organization’s DNS system by decreasing the time it takes to provide DNS lookups When a DNS server resolves a DNS name successfully, it adds the name to its cache Over time, this builds a cache of domain names and their associates IP addresses for the most common domains that the organization uses or accesses

2.3 Configuring DNS Zones What is a DNS Zone What are the DNS Zone types What are Forward and Reverse Lookup Zones What are Stub Zones DNS Zone Delegation

What is a DNS Zone A DNS zone hosts all or a portion of a domain and its subdomains

What are the DNS Zone Types ZonesDescription PrimaryRead/write copy of a DNS database SecondaryRead-only copy of a DNS database StubCopy of a zone that contains only records used to locate name servers Active Directory integratedZone data is stored in Active Directory rather than in zone files

What are Forward and Reverse Lookup Zones The forward lookup zone resolves host names to IP addresses and hosts the common resources records: A, CNAMES, SRV, MX, SOA and NS The reverse lookup zone resolves an IP address to a domain name and hosts SOA, NS and PTR records

What are Stub Zones A stub zone is a copy of a zone that contains only those resource records necessary to identify that zone’s authoritative DNS servers A stub zone resolves names between separate DNS namespaces, which may be necessary when a corporate merger requires that the DNS servers for 2 separate DNS namespaces resolve names for clients in both namespaces

DNS Zone Delegation DNS is a hierarchical system and zone delegation connects the DNS layers together A zone delegation points to the next hierarchical level down and identifies the name servers responsible for lower-level domain

2.4 Configuring DNS Zone Transfer What is a DNS Zone Transfer How DNS Notify works Securing Zone Transfers

What is a DNS Zone Transfer A DNS zone transfer is the synchronization of authoritative DNS zone data between DNS servers A zone transfer occur when you transfer the DNS zone that is on one server to another DNS server Zone transfer synchronize primary and secondary DNS server zones. Discrepancies in primary and secondary zones can cause service outages and host names that are resolved incorrectly

How DNS Notify works A DNS notify is an update to the original DNS protocol specification that permits notification to secondary servers when zone changes occur This is useful in a time-sensitive environment, where data accuracy is important

Securing Zone Transfers Zone information provides organizational data, so you should take precautions to ensure it is secure from malicious access and that it cannot be overwritten with bad data (known as DNS poisoning) One way in which you can protect the DNS infrastructure is to secure the zone transfers and use secure dynamic updates

2.5 Managing and Troubleshooting DNS What is Time to Live, Aging and Scavenging Demonstration: Managing DNS Records Testing the DNS server configuration Tools that identify problems with DNS Monitoring DNS using the DNS Event Log and Debug Logging

What is Time to Live, Aging and Scavenging FeaturesDescription Time to Live (TTL)Indicates how long a DNS record will remain valid AgingOccurs when records that have been inserted into the DNS server reach their expiration and are removed ScavengingPerforms DNS server resource record grooming for old records in DNS

Testing the DNS Server Configuration You can test the DNS server configuration by using: - A simple query to ensure that the DNS service is answering - A recursive query to ensure that the DNS server can communicate with the upstream DNS service

Tools that Identify Problems with DNS Issues can occur when you do not configure the DNS server and its zones and resource records properly When resource records are causing issues, it can sometimes be more difficult to identify the issue because configuration problems are not always obvious ToolUsed to: NslookupTroubleshoot DNS problems DnscmdEdit the DNS configuration DnslintDiagnose common DNS issues

Monitoring DNS using the DNS Event Log and Debug Logging Monitor DNS events in the event log to: - Monitor zone transfer information - Monitor computer events Enable DNS debug logging to view granular verbose information about DNS activities

End of Chapter 2