Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Reverse lookup from child domain to parent domain

Status
Not open for further replies.

endodave

IS-IT--Management
Feb 24, 2008
5
US
i am trying to do a reverse lookup in the child domain against a machine in the parent domain. it replies, however, it doesn't return the machine name. i have been told this is normal operation in w2k server as the ip addy scheme is the same subnet in both domains. i was told if the ip scheme was different in both domains, this would work across both domains. instead, the child answers the request by saying "i know that ip addy, but i don't have the machine name in my database." it then does not forward to the parent for the machine name answer. it just returns the reply that the ip is pingable. i was told this was rectified in w2k3 server as DNS can be forest-based if you choose.

can anyone validate that in w2k server, this is true and there is no way for me to do a reverse lookup from the child to parent or vice versa unless i change the ip addy scheme in one of the domains? and if it's not true, how do i set up DNS in both domains (2 parent DC's, 3 child DC's) so this reverse lookup will work no matter what ip addy i am trying to get lookup? thanks.
 
what are you using the query? nslookup?

what does ping -a <x.x.x.x> come back with? The FQDN, or just the IP again?

-Brandon Wilson
MCSE00/03, MCSA:Messaging00, MCSA03, A+
Sr. Infrastructure Management Analyst
Distributed Systems Engineering
ACS, Inc.
 
yes - nslookup

ping -a reveals just the ip, not the name. i could add all the entries in to the parent dns manually, but that seems silly.
 
how is your dns configured currently? my assumption here is that you have a forest root domain (probably empty), which at least 1 child domain. Is this accurate?

-Brandon Wilson
MCSE00/03, MCSA:Messaging00, MCSA03, A+
Manager - Global AD Operations
ACS, Inc.
 
hi, i'm not sure how simply i can answer in this post about how our DNS is configured, but essentially, there is a parent domain and one child. the child can't reverse lookup anything in the parent and vice versa. actually, the lookup is successful, but it only returns the ip address. also, microsoft dns support specialists set up our dns for us, but i still don't buy the fact that the child can't get a reverse name resolution on a machine in the parent unless manually added to dns. seems silly.
 
if you got someone from the networking ggroup to set up dns for you, its likely done improperly for AD operational functionality. In my days at Microsoft, this was virtually always the case.

What I mean on how is configured is:

1. Does the root domain have its own AD integrated zone (domain.local let's say)?
2. Does the child domain have its own AD integrated DNS zone (lets say child.domain.local)?
3. Are forwarders or root hints being used in the child domain?
4. Are forwarders or root hints being used in the forest root?
5. Is number 1 above true, but the child domain delegated out from the forest root?


Come ot think of it, an ldifde dump of the MicrosoftDNS container in AD should get the info I'm looking for, if you're able to post it.

-Brandon Wilson
MCSE00/03, MCSA:Messaging00, MCSA03, A+
Manager - Global AD Operations
ACS, Inc.
 
i ran the export. how can i get it to without posting it here? here are the answers to your questions:

1. Does the root domain have its own AD integrated zone (domain.local let's say)? Yes
2. Does the child domain have its own AD integrated DNS zone (lets say child.domain.local)? Yes and it has the parent as a secondary zone.
3. Are forwarders or root hints being used in the child domain? Yes, both
4. Are forwarders or root hints being used in the forest root? Yes, both
5. Is number 1 above true, but the child domain delegated out from the forest root? Yes
 
You can send it to my hotmail if you'd like...Brandon_WilsonSr at hotmail dot com

-Brandon Wilson
MCSE00/03, MCSA:Messaging00, MCSA03, A+
Manager - Global AD Operations
ACS, Inc.
 
thanks, i sent it this morning. i look forward to your thoughts.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top