Тёмный

DNS and Active Directory 

ITFreeTraining
Подписаться 214 тыс.
Просмотров 111 тыс.
50% 1

Active Directory requires DNS in order to operate. This videos looks at how Active Directory uses DNS and thus improves your understanding of how to support Active Directory and ensures your DNS infrastructure will support the requirements for Active Directory.
PDF itfreetraining.com/handouts/dn...
Demonstration
To access DNS Manager, open Server Manager and select DNS from the tools menu.
The DNS records required for Active Directory are located under Forward Lookup zones under the DNS name of your domain. There are a number of different containers in here. The DNS records in each container have different uses to clients on the network.
_tcp container
This container contains services that are available via TCP or reliable transport. The container contains 4 different types of records. These are _gc, _kerberos, _kpasswd and _ldap. These allow clients to find services on the network by searching for these records. For example, if a client wants to find a global catalog server, it will look for the DNS records _gc. Under _tcp, this will contain all the global catalog servers that are available in the domain. A client needs to query this container using DNS and this will give the client a service record for a global catalog server in the domain. The default DNS server setting will attempt to return a global catalog server in the same network as the client. The _kerberos records are used by the client to locate servers on the network that can perform Kerberos authentication. The _kpasswd records tell the client where a server is that can perform Kerberos password changes. The _ldap tells the client where servers are located on the network that can perform Ldap lookups.
_udp container contains the same kind of records as _tcp, however these services are contactable with the UDP protocol.
Service records properties
Priority: When two or more records exist with the same name than the DNS record will be used with the lowest priority.
Weight: When two or more records exist that have the same lowest priority, the weight value is used to determine which record is used. For example, if one record had a value of 20 and the other 80, the first record would use 2 out of 10 requests and the second, 8 out of 10 records.
Port: The port number is the port the service can be contacted on.
Dynamic update and DNS
When services like Active Directory Domain Services starts up, it will automatically attempt to register service records in DNS. If you do not have dynamic updates enabled and you have scavenging enabled, the Active Directory DNS records will eventually be removed. Since the services records have been removed, clients will not be able to find Active Directory resources on the network. If you want to check if dynamic updates are enabled, open the properties of the zone file and make sure that dynamic updates is not disabled on the general tab.
DomainDNSZones and ForestDNSZones
These two containers contains DNS records that are relevant for the domain and forest.
_msdcs zone
This is a Microsoft specific zone that contains resource service records for the domain or forest. This zone contains DNS service records that are registered by Microsoft based services. Since there are other non-Microsoft Directory Services that use service records, in order for a client to be sure that it is obtaining service records for a Microsoft solution, a Microsoft only zone is required. This zone is available at the forest level and thus Domain Controllers can obtain service records for all Domain Controllers in the forest. Using this information, they can create replication that works at the domain and forest level.
Description to long for youtube. For the rest of the description please see.
itfreetraining.com/dns#ad
References
"MCTS 70-640 Configuring Windows Server 2008 Active Directory Second edition" pg 480
"Active Directory SRV Records" www.petri.co.il/active_directo...
"How DNS Support for Active Directory Works" technet.microsoft.com/en-us/li...

Опубликовано:

 

6 окт 2013

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 49   
@Taha-ik1pg
@Taha-ik1pg 6 лет назад
"I've deleted all service records - I do not recommend that you do this on a production network" Thank you for legit making me laugh while listening to this passively in the background at 1am in my home when everyone's asleep
@bxblack
@bxblack 9 лет назад
Best channel for IT videos ever... Thx
@itfreetraining
@itfreetraining 10 лет назад
No problem at all, thanks for watching.
@marioschmonsees9481
@marioschmonsees9481 9 лет назад
Thank you for this great Video from Germany.
@itfreetraining
@itfreetraining 9 лет назад
Thank you very much
@itfreetraining
@itfreetraining 10 лет назад
Thanks very much and thanks for watching.
@turtleban
@turtleban 8 лет назад
Been studying for the Microsoft AD certification exam for a while now, so far this is the most intuitive video that I've found that covers most of the essentials of DNS. Great job!
@itfreetraining
@itfreetraining 8 лет назад
+turtleban Thank you. We're glad you enjoy our videos
@talehalasgarov68
@talehalasgarov68 5 лет назад
Thanks for good job(As always)
@gadgetproblemnoproblem7613
@gadgetproblemnoproblem7613 8 лет назад
Thank you for this great Video once again
@itfreetraining
@itfreetraining 8 лет назад
+Gadgetproblem Noproblem Thanks! You're welcome.
@hyylo
@hyylo 7 лет назад
Hi Can you please tell me what all the pre-existing folders are for when you first open Active Directory Users & Computers option? There are several pre-existing folders: Builtin, Computers, Domain Controllers, Foreign Security Principles etc
@paulmangam
@paulmangam 6 лет назад
Grt, Thanks for video. It is spoon feeding for beginers.
@danielwillett7164
@danielwillett7164 3 года назад
Great in how you delivered the content.
@itfreetraining
@itfreetraining 2 года назад
Thanks very much.
@mikeshen2023
@mikeshen2023 7 лет назад
You have the best videos on AD..
@itfreetraining
@itfreetraining 7 лет назад
Thanks so much!
@itfreetraining
@itfreetraining 10 лет назад
Thanks very much
@TheAMOS45
@TheAMOS45 7 лет назад
Amazing . Good pictorial explanation .
@itfreetraining
@itfreetraining 7 лет назад
Thanks!
@hyylo
@hyylo 7 лет назад
Hi Can you please tell me what all the pre-existing folders are for when you first open Active Directory Users & Computers option? There are several pre-existing folders: Builtin, Computers, Domain Controllers, Foreign Security Principles etc
@Sam1986E
@Sam1986E 10 лет назад
Thank you very much.
@sachinbidwai
@sachinbidwai 8 лет назад
Very Very Helpful and Valuable information
@itfreetraining
@itfreetraining 8 лет назад
+Sachin Bidwai We're happy you found the information to be valuable. Thanks for watching!
@syalishandilya12
@syalishandilya12 6 лет назад
Thanks for the video.
@itfreetraining
@itfreetraining 6 лет назад
You're most welcome!
@mehakvirmani1972
@mehakvirmani1972 8 лет назад
a great learning source..!!!
@itfreetraining
@itfreetraining 8 лет назад
+mehak virmani Thank you! We're glad you think so! Thanks for watching.
@antoniogil5156
@antoniogil5156 7 лет назад
At 1:13 you say "On this network there are currently two domain controlers, so this means that there are 4 DNS records for each domain controler" Can you explain please? Thanks for the video.
@itfreetraining
@itfreetraining 10 лет назад
Have a look at the replication settings for the zone that forestdnszone is located in. This will determine if it is replicate to the domain or forest level.
@shadychords
@shadychords 5 лет назад
Wow this is veeeeery important
@itfreetraining
@itfreetraining 5 лет назад
We agree. :)
@rohithibare4609
@rohithibare4609 6 лет назад
Thank you very much Sir for valuable knowledge just love your videos they are so good hear, I just love your accent any TDH can comprehend for sure. kudos\m/, if possible is there any way wherein I can connect you
@sarleyman
@sarleyman 6 лет назад
Verry good!
@itfreetraining
@itfreetraining 6 лет назад
Thanks!
@HemendrGupta
@HemendrGupta Год назад
Thank You very much!. This video is missing in playlist 70-640 Active Directory Course
@rosselur
@rosselur 10 лет назад
Great video as always, but pick it up a notch.
@TheLashely
@TheLashely 3 года назад
how to install windows server 2019 active directory on vps and how to join local computer on that active directory server ?
@TiagoBigodeTI
@TiagoBigodeTI 9 лет назад
Parabéns!
@itfreetraining
@itfreetraining 9 лет назад
Tiago Toledo Faria Thank you
@spd8335
@spd8335 10 лет назад
thanks !!
@itfreetraining
@itfreetraining 10 лет назад
No problem at all, thanks for watching.
@vijayprabhu1983
@vijayprabhu1983 10 лет назад
how about forestdnszone will it replicate to all domain....i am unable to see ForestDnsZone in child domain....only domaindns zone is available sir..
@Rushikesh144
@Rushikesh144 2 года назад
Can AD Dns hold Records of multiple AD forest domains?
@itfreetraining
@itfreetraining 2 года назад
Replication is limited to the forest. See this page for more details. www.serverbrain.org/active-directory-planning-008/replication-boundary.html Given that active directory integrated zones are stored in an application partition, there is a lot of control how they are replicated. However, different forests have potentially difference schemas and thus replication is not possible. You could create a secondary zone in the other forest which would create a copy of the active directory integrated zones as a workaround.
@billyma.1235
@billyma.1235 2 месяца назад
What do you mean by replication? Thank you for your videos!
@itfreetraining
@itfreetraining Месяц назад
Replication is the action of copying or reproducing something. In the case of DNS, this is the process of making the DNS secondary zone match the primary zone. That is, replication process will add, change or delete records in the secondary zone to match the primary. In the case of Active Directory, when a record is changed it is replicated using Active Directory so all the other copies have the same copy. If to changes occur on different servers, Active Directory uses a last write win, that is, the newest change will be used.
@billyma.1235
@billyma.1235 Месяц назад
@@itfreetraining Thank you for your response, it is very helpful!
@itfreetraining
@itfreetraining 10 лет назад
Thanks very much and thanks for watching.
Далее
DNS Forwarding and Conditional Forwarding
4:08
Просмотров 88 тыс.
DNS Zones
11:05
Просмотров 182 тыс.
СОБАКИ ГОЛОДАЮТ ИЗ-ЗА ЛЕРЫ 🥲
01:00
D3 BMW XM LABEL Король.
31:52
Просмотров 797 тыс.
DNS and Active Directory Partitions
17:12
Просмотров 59 тыс.
Active Directory Domain Service Deep Dive
1:00:09
Просмотров 67 тыс.
Tech Talk: What is Public Key Infrastructure (PKI)?
9:22
DNS Time to live, aging and scavenging
17:22
Просмотров 57 тыс.
Kerberos Authentication Explained | A deep dive
16:52
Просмотров 333 тыс.
Configuring DNS Forwarding Conditional Forwarding
5:56
DNS Records Explained
14:14
Просмотров 286 тыс.
Subnet Mask - Explained
17:55
Просмотров 2,7 млн
DNS Namespace
7:41
Просмотров 96 тыс.