nslookup from root domain cannot resolve child domain records
hi there,
i'm not sure if design or problem, wondered if 1 clear me.
i have root domain (domain.local) , 1 child domain (child.domain.local). dns child.domain.local has been delegated domain controllers child.domain.local. runs fine. however, if perform lookup on machine connected domain.local, cannot resolve of hosts in child.domain.local, except first dc. if enter fqdn, or change local machine's dns suffix search list include child.domain.local, can resolve hosts.
is design, or should dns server on domain.local attempt resolve hosts through every zone holds? if should, thoughts on resoling problem.
all servers windows 2008, , domains running windows 2003 functional level.
thanks
mr quantic
i'm not sure if design or problem, wondered if 1 clear me.
i have root domain (domain.local) , 1 child domain (child.domain.local). dns child.domain.local has been delegated domain controllers child.domain.local. runs fine. however, if perform lookup on machine connected domain.local, cannot resolve of hosts in child.domain.local, except first dc. if enter fqdn, or change local machine's dns suffix search list include child.domain.local, can resolve hosts.
is design, or should dns server on domain.local attempt resolve hosts through every zone holds? if should, thoughts on resoling problem.
all servers windows 2008, , domains running windows 2003 functional level.
thanks
mr quantic
+ when send query dns server fqdn , not host name.
example - "test.domain.local" , not"test"
which mean dns server domain.local zone , dns not touch other zone holds. if able resolve fqdn, mean have proper delegation in place.
this design. use suffix search list when resolve names across forest single label.
example - ping test, add first suffix , packet reach dns server test.domain.local , negative answer, client send second request test.child.domain.local (based on suffix list) , time dns forward correct answer.
we can push suffix search list through gpo.
hope helps
example - "test.domain.local" , not"test"
which mean dns server domain.local zone , dns not touch other zone holds. if able resolve fqdn, mean have proper delegation in place.
this design. use suffix search list when resolve names across forest single label.
example - ping test, add first suffix , packet reach dns server test.domain.local , negative answer, client send second request test.child.domain.local (based on suffix list) , time dns forward correct answer.
we can push suffix search list through gpo.
hope helps
Windows Server > Network Infrastructure Servers
Comments
Post a Comment