Professional Documents
Culture Documents
Active Directory Zone Replication
Active Directory Zone Replication
In this Video:
• Discuss the benefits of storing Zones in Active Directory
• Take a closer look at the Active Directory Zone Replication Scope
• Demonstrate Replication in a Domain, Forest Environment
• Use DNS Manager and ADSI edit to view Domain and Forest Zone Data
• Demonstrate how to remove Zone Data from Active Directory.
Prerequisites: You must have access to or have installed in your lab the following:
• Windows 2016 server with DNS and Active Directory installed and the server
promoted to a domain controller.
• Forward and Reverse lookup zone creation completed.
Adequate permissions will be needed.
1
• A simple domain structure – DE.DNS-ZONE.COM
• A Domain is a logical group of computers, users, and printers that share the
same database.
2
• In this example, Active Directory calls this structure a Forest, which in this
case is named DNS-ZONE.COM.
• Why, because in this example all the domains share the same schema.
A schema is an AD component that defines all the objects and attributes that
the directory service uses to store data.
• What we have is two domains and one Forest.
• We will now put this knowledge to work, to replicate DNS Zone data, first to
a domain then to a forest.
3
If we choose the second selection we will be replicating DNS data to every
Domain controller in the DE.DNS.COM domain. Even though in this case
there is only one Domain Controller.
4
We will now use DNS manager and ADSI edit to view Zone data at the Domain
level.
• From DNS manager, take a look at the records that are present in the
DE.DNS Zone.
ADSI Edit
Now we will dig a little deeper and use ADSI I edit to view and manage raw objects
and attributes from within Active Directory. I recommend extreme caution when
using this tool.
ADSI Demonstration
1. From Server Manager, tools click on ADSIEDIT.
2. Right click ADSIEDIT and click connect to.
• Type DC=DomainDNSZones,DC=DE,DC=DNS,DC=COM
5. Expand CN=MicrosoftDNS container and browse.
5
ADSI Displays Active Directory DNS Data at the Domain Level
• If you compare the DE.DNS.COM Zone data from the DNS manager with what is
displayed below from ADSI edit you will see much more detailed information.
6
Replicate to all Domain Controllers in this Forest
If the first choice is selected we will be replicating all DNS Data to all Domain
Controllers in the Forest. In our example that is two servers. The US server and the
DE server.
7
DNS Manager – Forest Data from the DE zone is displayed
Take a look at the data from _msdcs. The primary purpose of msdcs zones are:
• Forest and Domain Wide. (DNS Data is located in both Forest and Domain)
• Also this zone is used to locate Domain controllers SVR records and facilitate
their replication using CNAME records.
Notice the last four numbers at the end of that long string of alphanumeric
characters, 6575 represents the US server and the ad3f represents the
DE server. We will see those numbers again in ADSI edit.
Now let’s go back to ADSI edit type in the distinguished name for the Forest,
ForestDNSZones,DC=DNS,DC=COM
8
ADSI Edit Displays DNS Data from the Forest
• Notice 6575, which is the US server and ad3f which is the DE server.
Here is a slide of all the DNS Zone data relevant to this lecture
generated by DNS Manager and ADSIedit.
9
How does Replication Occur – Overview of the SOA tab
• Removing Zone data from Active Directory is not something that you would
normally do. But for the purposes of this lecture we need to explore what
happens to zone data if it is removed from Active Directory.
• Open Server Manager, tools, DNS.
10
• Double click on the Forward Lookup Zone, highlight in this case DNS.COM,
Right click then select Properties, select Change.
11
• Click yes, You receive this warning.
12
Active Directory Zone Replication
In this Video
Thanks for watching and we will see you in the next lecture.
13