Re: Private separate DNS domains

2014-04-09 Thread Joseph S D Yao
On 2014-04-08 07:35, Jason Brandt wrote: ... All of our Windows clients resolve through our Bind servers, and have no problems with any AD resources.  The only MSW machines that point to our AD DNS servers, are our DC's.  All clients will resolve just fine through BIND, so long as your zones are

Private separate DNS domains

2014-04-08 Thread Bryan Harris
Hello all, We have a sort of private DNS such that servers can lookup zones that don’t actually exist in the real, public DNS, they just exist within our private NOCs. In addition, we have always had both Windows AD handling the Windows side of things and we have had BIND handling Linux.

Re: Private separate DNS domains

2014-04-08 Thread Jason Brandt
I have ours setup with AD as a stub, and then point all our clients to our bind servers as resolvers. Works well. On Tue, Apr 8, 2014 at 5:08 AM, Bryan Harris bryanlhar...@me.com wrote: Hello all, We have a sort of private DNS such that servers can lookup zones that don't actually exist in

Re: Private separate DNS domains

2014-04-08 Thread Joseph S D Yao
On 2014-04-08 06:08, Bryan Harris wrote: Hello all, We have a sort of private DNS such that servers can lookup zones that don’t actually exist in the real, public DNS, they just exist within our private NOCs. In addition, we have always had both Windows AD handling the Windows side of things

Re: Private separate DNS domains

2014-04-08 Thread Jason Brandt
On Tue, Apr 8, 2014 at 6:15 AM, Joseph S D Yao j...@tux.org wrote: The MSW workstations and servers do only look up from the MSW AD servers, for some MSW reason that nobody can explain except MS says they have to. The MSW AD servers forward all DNS queries that they cannot resolve to the

Re: Private separate DNS domains

2014-04-08 Thread Sam Wilson
In article mailman.2610.1396955773.20661.bind-us...@lists.isc.org, Joseph S D Yao j...@tux.org wrote: On 2014-04-08 06:08, Bryan Harris wrote: ... The current mechanism is to put the Windows AD server into the resolv.conf BEFORE the BIND servers, since, as has been explained to me a

Re: Private separate DNS domains

2014-04-08 Thread Kevin Darcy
Regardless of what you've been told, the resolvers (nameservers) in /etc/resolv.conf are tried *in*sequence*, and if a valid response (where NXDOMAIN _is_ a valid response) is received from one resolver, none of the others are tried. So, I'm surprised that your mix-and-match-resolvers hack