Microsoft Server windows 2000 DNS Manual do Utilizador

Consulte online ou descarregue Manual do Utilizador para Software Microsoft Server windows 2000 DNS. Microsoft Server windows 2000 DNS User's Manual [en] Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 70
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 0
Operating System
Windows 2000 DNS
White Paper
Abstract
This paper describes the Microsoft® Windows® 2000 operating system Domain Naming System
(DNS), including design, implementation, and migration issues. It discusses new features of the
Windows 2000 implementation of DNS, provides examples of DNS implementations, and describes
the architectural criteria that network architects and administrators should consider when designing a
DNS namespace for the Active Directory® service to provide reliable network naming services.
Vista de página 0
1 2 3 4 5 6 ... 69 70

Resumo do Conteúdo

Página 1 - Windows 2000 DNS

Operating SystemWindows 2000 DNSWhite Paper AbstractThis paper describes the Microsoft® Windows® 2000 operating system Domain Naming System(DNS), incl

Página 2

superceded by RFC 1034 (Domain Names–Concepts and Facilities), and RFC 1035(Domain Names–Implementation and Specification). RFCs that describe DNSsecu

Página 3 - CONTENTS

comedu gov mil microsoftmydomainmitManaged by NRegistration Authority Managed byMicrosoftwhitehousearmyint/net/orgMicrosoft DiDNS and InternetThe Int

Página 4

Description Class TTL Type DataStart of Authority Internet (IN) Default TTL is60 minutesSOA Owner Name,Primary Name ServerDNS Name, SerialNumber,Refre

Página 5

• A need to delegate management of a DNS domain to a number oforganizations or departments within an organization• A need to distribute the load of ma

Página 6

The changes made to the primary zone file are then replicated to the secondaryzone file. As mentioned above, a name server can host multiple zones. A

Página 7 - DNS FUNDAMENTALS

or a successful response. Resolvers typically make recursive queries. With arecursive query, the DNS server must contact any other DNS servers it need

Página 8 - Name Services in Windows 2000

www.whitehouse.gov:• Recursive query for www.whitehouse.gov (A RR)• Iterative query for www.whitehouse.gov (A RR)• Referral to the gov name server (NS

Página 9 - History of DNS

• Incremental Zone Transfer (IXFR)• Dynamic Update and Secure Dynamic Update• Unicode Character Support• Enhanced Domain Locator• Enhanced Caching Res

Página 10 - The Structure of DNS

Each Active Directory service object has attributes associated with it that defineparticular characteristics of the object.The classes of objects in t

Página 11 - Windows 2000 White Paper

Note: Only DNS servers running on domain controllers can load DS integratedzones.The Replication ModelSince DNS zone information is now stored in Acti

Página 12 - Windows 2000 White Paper 6

© 1999 Microsoft Corporation. All rights reserved.The information contained in this document represents the current view of MicrosoftCorporation on th

Página 13 - Replicating the DNS database

Note that only DNS server supports the Secure Dynamic Updates for the DS-integrated zones. Windows 2000 implementation provides even finer granularity

Página 14 - WINDOWS 2000 DNS

The following diagram details the incremental transfer mechanism.Master DNSServerSlave DNSServer 1Serial Number 11Serial Number 10Serial Number 8IXFRS

Página 15

protocols, rendered manual updating of DNS information insufficient and unusable.No human administrator can be expected to keep up with dynamic addres

Página 16 - Updating the DNS Database

The dynamic update algorithm differs depending on the type of client networkadapter engaging in the dynamic update process. The following three scenar

Página 17

client’s PTR RR. Also, the DHCP server will remove the corresponding A records ifconfigured to ”Discard forward lookups when leases expire.”Statically

Página 18 - Windows 2000 White Paper 12

algorithm defined in the Internet Draft “GSS Algorithm for TSIG (GSS-TSIG).” Thisalgorithm is based on the Generic Security Service Application Progra

Página 19 - Controlling Access to Zones

In step 1, the client queries the local name server to discover which server isauthoritative for the name it is attempting to update, and the local na

Página 20 - Incremental Zone Transfer

however, can be changed through the registry.Controlling Update Access to Zones and NamesActive Directory controls access to the secure DNS zones and

Página 21 - Dynamic Update

DNS Admins GroupBy default the DNS Admins group has full control of all zones and records in aWindows 2000 domain in which it is specified. In order f

Página 22 - Update Algorithm

• Which zones can be scavenged• Which records must be scavenged if they become staleThe DNS server uses an algorithm that ensures that it does not acc

Página 23 - DHCP Server Considerations

WHITE PAPER ...1CONTENTS...

Página 24 - Secure Dynamic Update

Aging and Scavenging Parameters for ZonesZone Parameter Description Configuration Tool NotesNo-refresh interval Time interval, after the lasttime a re

Página 25

The table below lists the server parameters that affect when records are scavenged.You set these parameters on the server.Aging and Scavenging Paramet

Página 26 - Windows 2000 White Paper 20

Record Life SpanThe Figure below shows the life span of a scavengeable record.When a record is created or refreshed on an Active Directory–integrated

Página 27 - DnsUpdateProxy Group

the record at that time. The time at which records are scavenged depends onseveral server parameters.Scavenging AlgorithmThe server can be configured

Página 28 - Reserving Names

Usually, the DHCP service requires the longest refresh interval of all services. If youare using the Windows 2000 DHCP service, you can use the defaul

Página 29

zone file. Administrators should exercise caution when transferring a zonecontaining UTF-8 names to a non-UTF–8-aware DNS server.The Domain LocatorThe

Página 30 - Windows 2000 White Paper 24

Collect the following info:DNS Domain Name,Domain GUID,Site Name.Did client find DNS DomainName or Domain GUID?FinishNoYesCallWindows NT 4compatibleLo

Página 31

The description of the Windows NT 4 Compatible Domain Locator has beenomitted, since it is irrelevant to the DNS and is described in “Windows 2000 Dom

Página 32 - Record Life Span

_ldap._tcp.<SiteName>._sites.<DnsDomainName>.Allows a client to find an LDAP server in the domain named by <DnsDomainName>and is in

Página 33 - Scavenging Algorithm

All DCs providing the Kerberos service will register this name. This service is atleast an RFC-1510 compliant Kerberos 5 KDC. The KDC is not necessari

Página 34 - Unicode Character Support

Dynamic Update...15Protocol Description...

Página 35 - The Domain Locator

IP/DNS DC Locator AlgorithmThe IP/DNS DC Locator algorithm is executed in the context of the NetLogonservice, (typically) running on the client. The a

Página 36 - Windows 2000 White Paper 30

Send a DNS queryspecifying one of thecriteria specific DNShost namesDoes the DNS queryresponse contain atleast one DC?Quit indicatingthe reasonNoAmong

Página 37 - IP/DNS Compatible Locator

A client might have multiple network adapters and thus might have multiple IPaddresses. That could theoretically put the client in multiple sites. The

Página 38 - Windows 2000 White Paper 32

computer, the same rule is applicable to every adapter separately. This featureis enabled by default. It can be disabled through the Registry. Name Re

Página 39

resolution. The following summarizes the name resolution algorithm:• The query is issued to the lead server on the preferred adapter's server lis

Página 40 - Windows 2000 White Paper 34

• The query is processed as a fully-qualified query.• If the result is a positive response, the response is returned to the caller.• If the result is

Página 41

• The response is returned to the client.Name Resolution ScenariosThis section provides name resolution scenarios for a multi-homed machine usingunqua

Página 42 - Caching Resolver

• negative response• query t1 for boguz.dns.microsoft.com.• negative response• query e1 for boguz.dns.ntlab.microsoft.com.• negative response• query t

Página 43 - Name Resolution

Registry key HKEY_Local_Machine\System\CurrentControlSet\Services\DNSCache\Parameters.Disabling the Caching ResolverThere are two ways to disable the

Página 44 - Windows 2000 White Paper 38

hardware components can provide information and notification of events. WMIsimplifies the instrumentation of various drivers and applications written

Página 45

Internet Access Considerations...46Characters in Names...

Página 46 - Name Resolution Scenarios

Receiving Non-RFC Compliant DataIf a Windows 2000 server supports a secondary zone and receives unknownresource records, then it drops such records an

Página 47 - Negative Caching

Hardware components SizingNumber of processors TwoProcessor Intel Pentium II 400 MHzAmount of RAM 256 MB (megabytes)Hard disk drive space 4 GB (gigaby

Página 48 - Administrative Tools

namespace and DNS architecture to support it, and then revising the ADS and DNSdesign if unforeseen, or undesirable consequences are uncovered.The Win

Página 49 - ACTIVE DIRECTORY

strongly discouraged, since it may lead to the ambiguity in name resolutionprocesses.In this section the focus is on the design of the private namespa

Página 50 - DNS Server Performance

The following DNS configuration and name resolution scenarios are considered indetail with overlapping internal and external namespaces, since it is t

Página 51 - Number of processors Two

zone, that is, zzz.com., must also contain the zones containing all (internal andexternal) names of the merged companies.Now take a look at a private

Página 52 - Choosing Names

External world / Global Nezzzrk YYY corporationZZZ corporationYYY corporationZZZ corporationVPNVPNProxy ServerFirewall A DNS Server, Firewall, VPN or

Página 53

forwards the query to the DNS server containing the zzz.com. zone (Step 2). Thisserver finds a delegation to the third.zzz.com. in the zzz.com. zone.

Página 54 - Windows 2000 White Paper 48

(Step 8). The DNS server returns the response to the proxy server (Step 9). Finally,the proxy server uses the obtained IP address of www.someother.com

Página 55

Now consider an interesting case of a corporate computer that needs to resolve anexternal name of a computer from its own company.A computer in the YY

Página 57

A computer in the ZZZ Corporation needs to resolve a DNS query for www.zzz.com.It submits the query to the assigned DNS server (Step 1). If its cache

Página 58 - Windows 2000 White Paper 52

First it finds that the name myname.zzz.com. is internal, based on the PAC file.Therefore, it submits a query to the assigned DNS server (Step 1). If

Página 59

a full DNS computer name, which is a concatenation of Host name and primaryDNS suffix. The primary DNS suffix is part of the base machine configuratio

Página 60 - Windows 2000 White Paper 54

Active Directory Domain: MyCompany.com Host name: MyComputerPrimary DNS suffix –MyCompany.com Full computer name : MyComputer.MyCompany.com Public

Página 61 - Computer Names

If existing DNS tree is implemented by Windows NT 4.0 DNS, the solution is toupgrade the Windows NT 4.0 DNS servers to the Windows 2000 implementation

Página 62 - Windows 2000 White Paper 56

Do you have DNS Design/DeployWindows 2000DNS TopologyYesNo OverlapFinishWhat is your DNS Naming platform & topology? Windows NT 4 DNS in PlaceUpg

Página 63

secondary zones can be upgraded to DS integrated zones. At this point non-Microsoft DNS servers can be safely retired and removed from the network.Dep

Página 64 - Active Directory

Using Automatic ConfigurationThe Windows 2000 implementation of DNS offers a DNS Server Configurationwizard, which greatly simplifies the DNS server i

Página 65

In the picture above, a WINS referral zone called wins.mydomain.microsoft.com.has been created and pointed to the WINS database. Assume that a Windows

Página 66 - Windows 2000 White Paper 60

• Enhanced Caching Resolver Service • Enhanced DNS ManagerTo properly deploy DNS in the Windows 2000-based environment, it isrecommended to start with

Página 67 - GLOSSARY

The designers of the Microsoft ® Windows® 2000 operating system chose theDomain Name System (DNS) as the name service for the operating system.Windows

Página 68 - Windows 2000 White Paper 62

UCS-2–Also known as Unicode is a character encoding protocol.UTF-8–A character encoding protocol, specified in RFC 2044WINS–Windows Name System (WINS)

Página 69 - For More Information

Name Services in Windows 2000DNS is the name service of Windows 2000. It is by design a highly reliable,hierarchical, distributed, and scalable databa

Página 70 - Windows 2000 White Paper 64

• Draft-skwan-gss-tsig-04.txt (GSS Algorithm for TSIG (GSS-TSIG) )For more information on these documents, go to http://www.ietf.org/.In addition to t

Comentários a estes Manuais

Sem comentários