Module 6: Designing Name Resolution. Module Overview Collecting Information for a Name Resolution Design Designing a DNS Server Strategy Designing a DNS.

Slides:



Advertisements
Similar presentations
Chapter 8 Managing Windows Server 2008 Network Services
Advertisements

MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 6 Managing and Administering DNS in Windows Server 2008.
Objectives Install, configure, and troubleshoot DNS
2.1 Installing the DNS Server Role Overview of the Domain Name System Role Overview of the DNS Namespace DNS Improvements for Windows Server 2008 Considerations.
Implementing Domain Name System
Describe four (4) services that are part of the TCP/IP protocol suite that would probably be implemented within a network centre to manage: naming within.
DNS的配置和排错 刘道军老师主讲 Module 1 如有疑问请与我联系: D
Chapter 9: Configuring DNS for Active Directory
Chapter 7 HARDENING SERVERS.
4.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Hands-On Microsoft Windows Server 2003 Networking Chapter 6 Domain Name System.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 8: Managing and Troubleshooting DNS.
Lesson 20 – OTHER WINDOWS 2000 SERVER SERVICES. DHCP server DNS RAS and RRAS Internet Information Server Cluster services Windows terminal services OVERVIEW.
11.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 11: Introducing WINS, DNS,
Hands-On Microsoft Windows Server 2003 Networking Chapter 7 Windows Internet Naming Service.
Hands-On Microsoft Windows Server 2003 Administration Chapter 9 Administering DNS.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 5 Introduction to DNS in Windows Server 2008.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 7: Planning a DNS Strategy.
Chapter 10 Configuring DNS
Domain Name Services Oakton Community College CIS 238.
Understanding Active Directory
Windows Server 2008 Chapter 8 Last Update
Copyright line. Configuring DNS EXAM OBJECTIVES  An Introduction to Domain Name System (DNS)  Configuring a DNS Server  Creating DNS Zones  Configuring.
Lecturer : Ms.Trần Thị Ngọc Hoa Chapter 2 Methods Configuring Name Resolution Methods.
Hands-On Microsoft Windows Server 2008 Chapter 8 Managing Windows Server 2008 Network Services.
Configuring and Managing the DNS Server Role Lesson 4.
11.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 11: Introducing WINS, DNS,
Chapter 7 Configuring & Managing Distributed File System
DNS and Active Directory Integration
Chapter Overview Understanding DNS Creating Zones
11 REVIEWING MICROSOFT ACTIVE DIRECTORY CONCEPTS Chapter 1.
Name Resolution Domain Name System.
(ITI310) By Eng. BASSEM ALSAID SESSIONS
Implementing DNS Module D 7: Implementing DNS
CN2140 Server II Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+
Module 2: Implementing DNS to Support Active Directory
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 7: Domain Name System.
CHAPTER 4 PLANNING A NAME RESOLUTION STRATEGY. Determining Name Resolution Requirement What is name resolution ? ◦ The name into 32-bit IP address conversion.
Module 5: Planning a DNS Strategy. Overview Planning DNS Servers Planning a Namespace Planning Zones Planning Zone Replication and Delegation Integrating.
October 8, 2015 University of Tulsa - Center for Information Security Microsoft Windows 2000 DNS October 8, 2015.
Module 4: Planning, Optimizing, and Troubleshooting DHCP
DNS Zones. DNS records kept in zones DNS server is authoritative for a domain if it hosts the zone for that domain Sub-domains can be kept in same zone.
Windows routing and resolution. Basic concepts  Host name: machine.sub-domain.domain example: mail.ubalt.edu same machine name in Windows in NetBIOS.
Module 11: Implementing ISA Server 2004 Enterprise Edition.
Objectives Discuss the basics of the Domain Name System (DNS) and its terminology Configure DNS clients Install a standard DNS server on Server 2008 Create.
1 Administering Shared Folders Understanding Shared Folders Planning Shared Folders Sharing Folders Combining Shared Folder Permissions and NTFS Permissions.
Module 6: Managing and Monitoring Domain Name System (DNS)
Configuring and Troubleshooting Domain Name System
Configuring Name Resolution and Additional Services Lesson 12.
Windows Server 2003 DNS 安裝設定與管理維護 林寶森
Domain Name System (DNS). DNS Server Service Overview of Domain Name System What Is a Domain Namespace? Standards for DNS Naming.
Configuring File Services. Using the Distributed File System Larger enterprises typically use more file servers Used to improve network performce Reduce.
Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.
2.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 2: Examining.
DNS DNS overview DNS operation DNS zones. DNS Overview Name to IP address lookup service based on Domain Names Some DNS servers hold name and address.
Module 4: DNS As a Solution for Name Resolution. Overview Introducing DNS Designing a Functional DNS Solution Securing DNS Enhancing a DNS Design for.
Introduction to Active Directory
11.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 11: Introducing WINS, DNS,
Module 11: Configuring and Managing Distributed File System.
DNS, DHCP and VPN Borislav Varadinov Telerik Software Academy academy.telerik.com System Administrator
Configuring and Managing the DNS Server Role Lesson 4.
Planning Infrastructure Services Lesson 2. Dynamic Host Configuration Protocol (DHCP) The Dynamic Host Configuration Protocol (DHCP) is a service that.
Module 11 Configuring and Managing Distributed File System.
System Administration(SAD622S) Name of Presenter: Shadreck Chitauro Lecturer 18 July 2016 Faculty of Computing and Informatics.
Services DFS, DHCP, and WINS are cluster-aware.
Module 5: Resolving Host Names by Using Domain Name System (DNS)
IMPLEMENTING NAME RESOLUTION USING DNS
Configuring and Troubleshooting DNS
Configuring and Managing the DNS Server Role
(DNS – Domain Name System)
Presentation transcript:

Module 6: Designing Name Resolution

Module Overview Collecting Information for a Name Resolution Design Designing a DNS Server Strategy Designing a DNS Namespace Designing DNS Zone Implementation Designing Zone Replication and Delegation

Lesson 1: Collecting Information for a Name Resolution Design Physical Location Considerations for a Name Resolution Design NetBIOS Resources

Physical Location Considerations for a Name Resolution Design TypePhysical location consideration Locations Number of locations Hosts Number of hosts at each location DNS servers Existence of any prior DNS servers Active Directory Existence of, or plans to include an Active Directory infrastructure Client computers Location of client computers in relation to a WINS server

NetBIOS Resources Identify systems and applications that rely on NetBIOS for name resolution, including:  Windows 98, Windows NT  Windows workgroups that do not implement Active Directory  Some applications and services Determine the impact of removing NetBIOS If NetBIOS is used by a critical application, continue to use WINS

Lesson 2: Designing a DNS Server Strategy How Clients Resolve Host Names Consideration for Placing DNS Servers DNS Server Roles Securing DNS Servers

How Clients Resolve Host Names Clients can use the following methods to resolve host names: DNS cache (includes contents of HOSTS file) DNS server NetBIOS name resolution methods DNS name resolution is controlled by: Root hints Caching Delegation Forwarding Conditional forwarding

Considerations for Placing DNS Servers For DNS server placement, consider: Network traffic over WAN links Availability, if a WAN link fails Redundancy, if a DNS server fails Client impact, if DNS is unavailable Application impact, if DNS is unavailable

DNS Server Roles RoleSituation Caching-only servers A remote office has a limited amount of available bandwidth Non-recursive servers You have Internet-facing DNS that are authoritative for one or more zones Forward-only servers You want to manage the DNS traffic between your network and the Internet Conditional forwarders You want DNS clients on separate networks to resolve each others’ names without having to query the DNS server on the Internet

Securing DNS Servers Options for securing Microsoft DNS servers: Firewalls, including Windows Firewall Restricting zone transfers Securing dynamic updates Active Directory Integrated zones Forwarding, to limit Internet name resolution

Lesson 3: Designing a DNS Namespace DNS Namespace Options Selecting DNS Namespace Option Hosting Options for DNS Guidelines for Designing DNS Namespaces

DNS Namespace Options Same Namespace Same Namespace Subdomain Unique Namespace Unique Namespace nwtraders.com nwtraders.localcorp.nwtraders.com nwtraders.com Internal Namespace Internal Namespace Internal Namespace Internal Namespace Internal Namespace Internal Namespace Public DNS Namespace

Selecting DNS Namespace Option Unique namespace:  Record synchronization is not required  Existing DNS infrastructure is unaffected  Clearly delineates between internal and external DNS Same namespace: Internal records should not be available externally Records may need to be synchronized between internal and external DNS Subdomain: Record synchronization is not required Contiguous namespace is easy to understand

Hosting Options for DNS External and internal DNS are hosted on separate servers One external server host resolves local records only One external server resolves non-local records only Split-Split DNS External and internal DNS are hosted on separate servers Internal DNS servers can forward Internet DNS requests Increased security over complete DNS Split DNS All internal and external on a single server Simple deployment DescriptionOption Complete DNS

Guidelines for Designing DNS Namespaces Carefully select your internal namespace before installing Active Directory Use an internal domain that is a sub-domain of the external domain, for simplicity Use unrelated namespaces if you cannot create your internal domain as a subdomain on the external domain Avoid using the same internal and external namespace

Lesson 4: Designing DNS Zone Implementation Selecting Zone Types Selecting Zone Data Location Zone Security Considerations

Selecting Zone Types Zone type Available disk locations Zone information Use this zone to: Primary Active Directory Replicated to other Active Directory- integrated zones Act as the point of update for the zone Have a read/write copy of the zone information Administer zone information separately File Transferred to secondary zone servers Secondary File Provides limited fault tolerance Have a read-only copy of the zone information Improve availability of primary zones Improve performance at local and remote locations Stub Active Directory Periodically queries the target zone name servers for updates Improve the efficiency of name resolution Simplify DNS administration File

Selecting Zone Data Location Used by Active Directory-integrated zones Automatic replication to all domain controllers Allows multiple servers to update zone data Active Directory Used to integrate with traditional DNS Active Directory-integrated zones act as primary to traditional secondary zones Combination Used by traditional primary and secondary zones Chosen for integration into existing infrastructure Does not require server to be a DC Disk

Zone Security Considerations Secured dynamic updates in Active Directory Dynamic DNS updates from DHCP DNS client dynamic updates Zone permissions

Lesson 5: Designing Zone Replication and Delegation Zone Replication Zone Transfers Zone Delegation

Zone Replication Performing incremental replication between DNS servers Adjusting the Active Directory replication schedule Active Directory – integrated zone Replicating between primary and secondary zones Performing an incremental rather than a complete zone transfer Traditional DNS zone Replication optionsZone type Active Directory–Integrated Zones Traditional DNS Zones Active Directory- Integrated Zone Primary Zone Secondary Zone Replication Zone Transfer

Zone Transfers Reduce zone transfer impact by: Using fast zone transfers to compress data Replicating outside of peak hours Using incremental zone replication Security options for zone transfers are: Restricting zone transfers Securing zone transfers with VPN or IPSec Using Active Directory-integrated zones to automatically secure replication