Welcome to Dirteam.com/ActiveDir.org Blogs Sign in | Join | Help
 
 
Making Active Directory more useful on a daily basis!
in Search

tonymurray

Enabling a new DC as a DNS Server - a cautionary tale.

I recently came across a fairly serious DNS issue.  Here's what had happened.

A customer had decided to add a new DC.  They had run DCPROMO and everything ran without a hitch.  After the reboot they thought that it would be good to enable the DC as a DNS server (fair enough).  The existing zone was AD-integrated. 

Here's where things went awry.  There are a couple of ways in which a DC can be made a DNS Server.  The one that is probably most familiar to us is to go to Control Panel -> Add/Remove Programs -> Add/Remove Windows Components -> Networking Services -> Details -> Domain Name System (DNS).

This method would have been fine.

The alternative method is to use the Configure Your Server Wizard to add a role, as shown below.

At the next screen (after simply selecting Next above) things get a little tricky.  All you want to do is to install DNS Server on this machine.  That's it.  Finshed.  Nothing else to do, because we know AD Integrated DNS will simply replicate the zone infromation to our new DC without any other effort required.  But the wizard doesn't know this and so tries to be helpful by suggesting you do something else (see below) when you select Next.

Clicking Cancel at this point will achieve the desired result.  Unfortunately, my customer became confused and went ahead and created the forward lookup zone THAT ALREADY EXISTED.  The effect of this was to overwrite the existing zone information.  Oops - not good.

Personally, I think it would be helpful if the wizard offered an extra option in the screen above.  For example, something that says, "This is a DC in an existing forest with these AD integrated zones (X, Y and Z) already configured."

Tony

www.activedir.org

Published Monday, August 07, 2006 2:28 AM by tonymurray

Comments

 

carlos said:

EXCELLENT post Tony ;) And welcome
August 8, 2006 1:49 AM
 

tomek said:

That's why I don't like wizards, sometimes wizard is introducing "assumptions" which may be dengerous.

Welcome on board Tony :)
August 8, 2006 7:33 AM
 

carlos said:

Tomek,

I dont know if I agree. If you take the amount of times a user will screw things up Vs. the amount of time Wizards screw things up you are better off with Wizards.
August 10, 2006 5:50 AM
Anonymous comments are disabled
Powered by Community Server (Personal Edition), by Telligent Systems