programming4us
programming4us
DESKTOP

Windows Server 2003 : Configuring Zone Properties and Transfers (part 2)

12/25/2013 6:48:44 PM
Zone File Name

For standard zones not stored in Active Directory, the default zone filename is created by adding a .dns extension to the zone name. The Zone File Name text box on the General tab allows you to change the default name of this file.

Dynamic Updates

The General tab also allows you to configure the dynamic updates settings for a zone. Three dynamic update settings are available for Active Directory-integrated DNS zones: None, Nonsecure And Secure, and Secure Only. For standard zones, only two settings are available: None and Nonsecure And Secure.

When you select the None setting in the properties for a zone, you must manually perform registrations and updates to zone records. However, when you enable either the Nonsecure And Secure setting or the Secure Only setting, client computers can automatically create or update their own resource records. This functionality greatly reduces the need for manual administration of zone records, especially for DHCP clients and roaming clients.

Figure 3 illustrates a typical dynamic update process.

Figure 3. Dynamic update process


Whenever a triggering event occurs on a DNS client computer, the DHCP Client service, not the DNS Client service, attempts to perform a dynamic update of the A resource record with the DNS server. This update process is designed so that if a change to the IP address information occurs because of DHCP, this update is immediately sent to the DNS server. The DHCP Client service attempts to perform this dynamic update function for all network connections used on the system, including those not configured to use DHCP. Whether this attempt at a dynamic update is successful depends first and foremost on whether the zone has been configured to allow dynamic updates.

Dynamic Update Triggers

The following events trigger the DHCP Client service to send a dynamic update to the DNS server:

  • The DNS client computer is turned on.

  • An IP address lease changes or renews with the DHCP server for any one of the local computer’s installed network connections—for example, when the computer is started or if the Ipconfig /renew command is used.

  • An IP address is added, removed, or modified in the Transmission Control Protocol/Internet Protocol (TCP/IP) properties configuration for any one of the local computer’s installed network connections.

  • A member server within the zone is promoted to a domain controller.

  • The Ipconfig /registerdns command is used on a DNS client computer to manually force a refresh of the client name registration in DNS.

Secure Dynamic Updates

Secure dynamic updates can be performed only in Active Directory-integrated zones. For standard zones, the Secure Only option does not appear in the Dynamic Updates drop-down list box. These updates use the secure Kerberos authentication protocol to create a secure context and ensure that the client updating the resource record is the owner of that record.

Note

Only clients running a version of Windows 2000, Microsoft Windows XP, or Windows Server 2003 can attempt to send dynamic updates to a DNS server. Dynamic updates are not available for any version of Windows NT, Windows 95, Microsoft Windows 98, or Microsoft Windows Millenium Edition (Me). However, a DNS client computer (such as a DHCP server) can perform dynamic updates on behalf of other clients if the server is configured to do so.


  • Secure Dynamic Updates and the DnsUpdateProxy group

    When only secure dynamic updates are allowed in a zone, only the owner of a record can update that record. (The owner of a record is the computer that originally registers the record.) This restriction can cause problems in situations where a DHCP server is being used to register host (A) resource records on behalf of client computers that cannot perform dynamic updates. In such cases, the DHCP server becomes the owner of the record, not the computers themselves. If the down-level client computer is later upgraded to Windows 2000 or some other operating system that is capable of performing dynamic updates, the computer will not be recognized as the owner and will consequently be unable to update its own records. A similar problem might arise if a DHCP server fails that has registered records on behalf of down-level clients: none of the clients will be able to have their records updated by a backup DHCP server.

    To avoid such problems, add to the DnsUpdateProxy security group DHCP servers that register records on behalf of other computers. Members of this group are prevented from recording ownership on the resource records they update in DNS. This caveat consequently loosens security for these records until they can be registered by the real owner.

Tip

Expect to be tested on DnsUpdateProxy on the exam.


Aging

By clicking Aging on the General tab, you can open the Zone Aging/Scavenging Properties dialog box, as shown in Figure 4. These properties provide a means of finding and clearing outdated records from the zone database.

Figure 4. Zone Aging/Scavenging Properties dialog box

Other  
  •  Windows 7 : Managing Pictures with Windows Live Photo Gallery (part 14) - Sharing with E-mail, Sharing on the Web: Services Integration
  •  Windows 7 : Managing Pictures with Windows Live Photo Gallery (part 13) - Printing Pictures and Ordering Prints, Adding Photos to Movies, DVDs, and Data Discs
  •  Windows 7 : Managing Pictures with Windows Live Photo Gallery (part 12) - Using Photos as Slide Shows
  •  Windows 7 : Managing Pictures with Windows Live Photo Gallery (part 11) - Enjoying Photos on Your Own PC
  •  Windows 7 : Managing Pictures with Windows Live Photo Gallery (part 10) - Resizing Photos,Creating Panoramic Photos , Editing with Other Applications
  •  Windows 7 : Managing Pictures with Windows Live Photo Gallery (part 9) - Editing Pictures
  •  Windows 7 : Managing Pictures with Windows Live Photo Gallery (part 8) - Importing Images from a Digital Camera or Memory Card
  •  Windows 7 : Managing Pictures with Windows Live Photo Gallery (part 7) - Importing Images with a Scanner
  •  Windows 7 : Managing Pictures with Windows Live Photo Gallery (part 6) - Using People Tags, Searching for Pictures in Photo Gallery
  •  Windows 7 : Managing Pictures with Windows Live Photo Gallery (part 5) - Using Captions, Using Ratings
  •  
    Video
    PS4 game trailer XBox One game trailer
    WiiU game trailer 3ds game trailer
    Top 10 Video Game
    -   Minecraft Mods - MAD PACK #10 'NETHER DOOM!' with Vikkstar & Pete (Minecraft Mod - Mad Pack 2)
    -   Minecraft Mods - MAD PACK #9 'KING SLIME!' with Vikkstar & Pete (Minecraft Mod - Mad Pack 2)
    -   Minecraft Mods - MAD PACK #2 'LAVA LOBBERS!' with Vikkstar & Pete (Minecraft Mod - Mad Pack 2)
    -   Minecraft Mods - MAD PACK #3 'OBSIDIAN LONGSWORD!' with Vikkstar & Pete (Minecraft Mod - Mad Pack 2)
    -   Total War: Warhammer [PC] Demigryph Trailer
    -   Minecraft | MINIONS MOVIE MOD! (Despicable Me, Minions Movie)
    -   Minecraft | Crazy Craft 3.0 - Ep 3! "TITANS ATTACK"
    -   Minecraft | Crazy Craft 3.0 - Ep 2! "THIEVING FROM THE CRAZIES"
    -   Minecraft | MORPH HIDE AND SEEK - Minions Despicable Me Mod
    -   Minecraft | Dream Craft - Star Wars Modded Survival Ep 92 "IS JOE DEAD?!"
    -   Minecraft | Dream Craft - Star Wars Modded Survival Ep 93 "JEDI STRIKE BACK"
    -   Minecraft | Dream Craft - Star Wars Modded Survival Ep 94 "TATOOINE PLANET DESTRUCTION"
    -   Minecraft | Dream Craft - Star Wars Modded Survival Ep 95 "TATOOINE CAPTIVES"
    -   Hitman [PS4/XOne/PC] Alpha Gameplay Trailer
    -   Satellite Reign [PC] Release Date Trailer
    Game of War | Kate Upton Commercial
    programming4us
     
     
    programming4us