Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Windows 2000 Forest, DNS, and client internet access!?

Status
Not open for further replies.

Jpoandl

MIS
Jun 23, 2000
2,008
0
0
US
Here's the situation.. We are designing AD for a forest that will house multiple TREES.

For example:

ForestRoot.com------------------
/ company1.com company2.com
/ us.company1.com us.company2.com
/ uk.company1.com uk.company2.com


We think we want forestroot.com to hold the internal ".". Therefore, we do not want to delete the "." internal DNS root and have it forward to the internet ISP DNS servers (We don't want to do this because the companies actually span multiple countries....and don't UK companies having to query through the US-based forestroot)

Our theory is that we leave the "." root in ForestRoot.com and have delegations from ForestRoot.com for zones like company1.com, company2.com, etc. This seems to work fine in our test lab. We can resolve every record within our forest.

The question is...how should we configure INTERNET resolution? From reading Technet, it looks like we may need a PROXY(ISA) server to resolve internet based requests. This would work for us because every company can set up thier own proxies....that are linked to thier own ISP's.

The other option we are considering is FORWARDING from the root sub-trees (Company1.com or Company2.com) to the internet.

Any suggestions? or a place to look for more information?
Joseph L. Poandl
MCSE 2000

If your company is in need of experts to examine technical problems/solutions, please check out
 
Hi,

ISA can do in some configuration the resolving on the Internet, but... it depends on the type of client used (web proxy client, firewall client or SecureNAT client). I think the best and most stable solution is to use forwarders on each DNS server.

For more info have a look at
Greetings,
Stefaan
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top