Tell the truth I hadn't really thought of a DNS-only server. It just gets to be second nature having DNS on your DCs. if I was in a high-security environment, I would probably take it as a good idea to separate the roles.
Still I also have the advantage of being able to log on to my workstation and administer the SAN and ESX servers without having any of the virtual guests turned on. I know I could just use a local account, but hey, that's a whole different user profile :-) 2009/4/1 Ken Schaefer <[email protected]> > Most of the shops I work in only have AD-related DNS in AD, and other DNS > running on other software. > > That all said, why have another DC just to run DNS? It becomes another box > to patch and secure. Why not just run a DNS server? Surely that's a far > lower risk box? > > Cheers > Ken > > ------------------------------ > *From:* James Rankin [[email protected]] > *Sent:* Wednesday, 1 April 2009 6:32 PM > > *To:* NT System Admin Issues > *Subject:* Re: Pros/Cons of putting PDC/2DC on Virtual Server > > Agreed, we have one physical DC, and it is there solely for the DNS. ESX > seems to be a bit twisty about booting in the absence of DNS (at least here, > anyways) > > 2009/3/31 Kurt Buff <[email protected]> > >> Yes, the FSMO roles are irrelevant to this purpose, so this is not a >> requirement, merely a personal preference. >> >> But, as I pointed out, most Windows shops (not all, just most) have >> their DNS AD-integrated and running on their DCs. Thus, it makes sense >> to keep one of your DCs physical, because it will also be running DNS. >> >> On Mon, Mar 30, 2009 at 21:47, Ken Schaefer <[email protected]> wrote: >> > I'm not aware of FSMO roles having anything to do with DNS. So why do >> you need a physical DC (with or without FSMO roles)? Just keep a physical >> DNS server around... >> > >> > Cheers >> > Ken >> > >> > ________________________________________ >> > From: Kurt Buff [[email protected]] >> > Sent: Tuesday, 31 March 2009 10:08 AM >> > To: NT System Admin Issues >> > Subject: Re: Pros/Cons of putting PDC/2DC on Virtual Server >> > >> > On Mon, Mar 30, 2009 at 15:30, Bill Songstad (WCUL) >> > <[email protected]> wrote: >> >> If my SAN had a major issue, neither my VMs or my physical DC would >> have >> >> anything to doÿÿ All my clients could authenticate, but they >> wouldnÿÿ™t >> >> have anything to access. >> >> >> >> >> >> >> >> I really feel like ÿÿ€™m missing an obvious underlying concept here and >> that >> >> makes me nervous. >> > >> > VMWare gets quite unhappy when it can't talk to a DNS server. In most >> > Windows environments, the DCs are also the DNS servers, therefore >> > virtualizing *all* of your DCs, or rather, virtualizing them all on >> > the *same* DC, puts that VMWare host at risk. >> > >> > That's reason enough for me to keep one DC (probably the one with the >> > FSMO roles) on its own physical machine. >> > >> > Kurt >> > ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ >> > ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~ >> > >> > >> >> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ >> ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~ >> >> > > > > > > > > > > ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~
