Tell the truth I hadn't really thought of a DNS-only server. It just gets to
be second nature having DNS on your DCs. if I was in a high-security
environment, I would probably take it as a good idea to separate the roles.

Still I also have the advantage of being able to log on to my workstation
and administer the SAN and ESX servers without having any of the virtual
guests turned on. I know I could just use a local account, but hey, that's a
whole different user profile :-)

2009/4/1 Ken Schaefer <[email protected]>

>  Most of the shops I work in only have AD-related DNS in AD, and other DNS
> running on other software.
>
> That all said, why have another DC just to run DNS? It becomes another box
> to patch and secure. Why not just run a DNS server? Surely that's a far
> lower risk box?
>
> Cheers
> Ken
>
>  ------------------------------
> *From:* James Rankin [[email protected]]
> *Sent:* Wednesday, 1 April 2009 6:32 PM
>
> *To:* NT System Admin Issues
> *Subject:* Re: Pros/Cons of putting PDC/2DC on Virtual Server
>
>  Agreed, we have one physical DC, and it is there solely for the DNS. ESX
> seems to be a bit twisty about booting in the absence of DNS (at least here,
> anyways)
>
> 2009/3/31 Kurt Buff <[email protected]>
>
>> Yes, the FSMO roles are irrelevant to this purpose, so this is not a
>> requirement, merely a personal preference.
>>
>> But, as I pointed out, most Windows shops (not all, just most) have
>> their DNS AD-integrated and running on their DCs. Thus, it makes sense
>> to keep one of your DCs physical, because it will also be running DNS.
>>
>> On Mon, Mar 30, 2009 at 21:47, Ken Schaefer <[email protected]> wrote:
>> > I'm not aware of FSMO roles having anything to do with DNS. So why do
>> you need a physical DC (with or without FSMO roles)? Just keep a physical
>> DNS server around...
>> >
>> > Cheers
>> > Ken
>> >
>> > ________________________________________
>> > From: Kurt Buff [[email protected]]
>> > Sent: Tuesday, 31 March 2009 10:08 AM
>> > To: NT System Admin Issues
>> > Subject: Re: Pros/Cons of putting PDC/2DC on Virtual Server
>> >
>> > On Mon, Mar 30, 2009 at 15:30, Bill Songstad (WCUL)
>> > <[email protected]> wrote:
>> >> If my SAN had a major issue, neither my VMs or my physical DC would
>> have
>>  >> anything to doÿÿ  All my clients could authenticate, but they
>> wouldnÿÿ™t
>> >> have anything to access.
>> >>
>> >>
>> >>
>> >> I really feel like ÿÿ€™m missing an obvious underlying concept here and
>> that
>>  >> makes me nervous.
>> >
>> > VMWare gets quite unhappy when it can't talk to a DNS server. In most
>> > Windows environments, the DCs are also the DNS servers, therefore
>> > virtualizing *all* of your DCs, or rather, virtualizing them all on
>> > the *same* DC, puts that VMWare host at risk.
>> >
>> > That's reason enough for me to keep one DC (probably the one with the
>> > FSMO roles) on its own physical machine.
>> >
>> > Kurt
>> > ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
>> > ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~
>> >
>> >
>>
>> ~ Finally, powerful endpoint security that ISN'T a resource hog! ~
>> ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~
>>
>>
>
>
>
>
>
>
>
>
>
>

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

Reply via email to