Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > DNS Server > dns record for an external bdc

Reply
Thread Tools Display Modes

dns record for an external bdc

 
 
Hal
Guest
Posts: n/a

 
      05-22-2009
Hello

I have 2 servers called main.ourdomain.local and remote.ourdomain.local both
are domain controllers with dhcp and dns. Main is the gc and has an internal
ip address of 192.168.0.1 and a public address of xx.xx.xx.xx. Remote has an
internal ip address of 192.168.254.1 and a public address of yy.yy.yy.yy.
Both servers have 1 nic card each.

In the DSN i see the 192 records but I need to system to talk to each other
over the internet with out a vpn do to replication.

What do I need to put into the dns so that main can address remote at
yy.yy.yy.yy and visa versa ?
 
Reply With Quote
 
 
 
 
Kevin D. Goodknecht [MVP]
Guest
Posts: n/a

 
      05-25-2009

"Hal" <> wrote in message
news:2046DA6A-5BC8-4BEF-9D33-...
> Hello
>
> I have 2 servers called main.ourdomain.local and remote.ourdomain.local
> both
> are domain controllers with dhcp and dns. Main is the gc and has an
> internal
> ip address of 192.168.0.1 and a public address of xx.xx.xx.xx. Remote has
> an
> internal ip address of 192.168.254.1 and a public address of yy.yy.yy.yy.
> Both servers have 1 nic card each.
>
> In the DSN i see the 192 records but I need to system to talk to each
> other
> over the internet with out a vpn do to replication.
>
> What do I need to put into the dns so that main can address remote at
> yy.yy.yy.yy and visa versa ?


You are asking for major security risks for opening up your DCs to the
internet, if you're going to do that why even have a private network, I can
guarantee your DCs are going to come under immediate attack from malicious
users. You need a firewall and a site to site VPN, don't try to do this with
multihomed DCs. All IPs on both your DCs will need to be accessible from
both networks, because there is no way to guarantee which address record DNS
will give out.

--
--
Best regards,
Kevin D. Goodknecht Sr. [MVP]
Hope This Helps

===================================
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
===================================
http://www.lonestaramerica.com/
http://support.wftx.us/
http://message.wftx.us/
===================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
===================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
===================================


 
Reply With Quote
 
Ace Fekay [Microsoft Certified Trainer]
Guest
Posts: n/a

 
      05-25-2009
"Hal" <> wrote in message news:2046DA6A-5BC8-4BEF-9D33-...
> Hello
>
> I have 2 servers called main.ourdomain.local and remote.ourdomain.local both
> are domain controllers with dhcp and dns. Main is the gc and has an internal
> ip address of 192.168.0.1 and a public address of xx.xx.xx.xx. Remote has an
> internal ip address of 192.168.254.1 and a public address of yy.yy.yy.yy.
> Both servers have 1 nic card each.
>
> In the DSN i see the 192 records but I need to system to talk to each other
> over the internet with out a vpn do to replication.
>
> What do I need to put into the dns so that main can address remote at
> yy.yy.yy.yy and visa versa ?



I must agree with Kevin to not put your DC on the internet, and to not multihome it. Multihoming a DC will definitely cause issues with DC and AD functionality.

There are hardware based firewall solutions that offer site to site, as well as secured client access VPN features that you will be better off and much more secure. These solutions are not that expensive at all. Take a look at a Cisco ASA5505. There are competitive products from Netscreen, SonicWall, etc.


--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSA Messaging, MCT
Microsoft Certified Trainer


For urgent issues, you may want to contact Microsoft PSS directly. Please
check http://support.microsoft.com for regional support phone numbers.

"Efficiency is doing things right; effectiveness is doing the right things." - Peter F. Drucker
http://twitter.com/acefekay

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Internal AD DNS record for external domain Bucket DNS Server 3 02-02-2009 01:47 PM
record to external hard drive mjl Windows Media Center 5 03-20-2008 10:00 PM
Internal and External (same as parent folder) record question Jaycee DNS Server 1 07-20-2006 01:42 PM
External MX record Jim Zula DNS Server 1 07-12-2006 03:19 PM
Record External Sources. Jordi Novavenda Windows Media Center 1 12-28-2005 10:20 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59