F
F
Fiasco2014-07-15 20:53:31
Domain Name System
Fiasco, 2014-07-15 20:53:31

How to configure the addresses of the domain controller, dns server and mail server behind the router?

Hello!
Please help with the settings of the domain controller with the role of the DNS server and the mail server, which are located behind the router.
Available:
white ip allocated by the provider - 213.150.x.x;
internal network - 192.168.0.0/24;
mikrotik router - 192.168.0.2;
domain controller on windows 2012 R2 - 192.168.0.3;
DNS server - 192.168.0.3;
web server - 192.168.0.3;
mail server - 192.168.0.17;
The router is configured, there is Internet, there is an internal network, ports are forwarded:
tcp and udp 53, tcp 80 to the address 192.168.0.3;
tcp 25 to 192.168.0.17;
Confused with the DNS server settings, what should I write in NS, MX and A records? Do I need to write in the NS record the internal address of the interface 192.168.0.3 or the external 213.150.х.х? similarly with the MX record - write external or internal, or both? And in general, how to configure network interfaces in this situation of equipment? Should I write the DNS servers of the provider or my server 192.168.0.3?
Now the domain does not resolve from other networks at all - neither ping nor nslookup pass. From the local network, all tests are successful. Online verification services say that there is no NS record.
Thank you in advance!

Answer the question

In order to leave comments, you need to log in

3 answer(s)
G
Gem, 2014-07-16
@Fiasco

there is a wild suspicion of a typical (gross) error of ms admins, the use of a public domain name in AD
depends on the dns structure and the settings depend on
if I understood your config correctly, with the words "everything worked" then nothing needs to be changed, you need to do
a return dnat on Mikrotik
do port forwarding in Mikrotik when accessing from LAN?
you need to configure points 2 and 3 for both addresses (those three ports) - and everything will become as it was,
but in general, re-read the documentation from ms and do it right,
but you don’t need to make the remaining two typical mistakes
1. using a monosyllabic (single-level) domain name is unacceptable, causes the dns server to check its registration on the Internet root servers.
Example incorrect - corp, correct - msk.corp
2. use of the .local domain or public second-level domains .ru .com .org etc.
is not allowed according to RFC

F
F1RST, 2014-07-16
@F1RST

Are you sure that your domain is supported by your DNS server. Usually this is done either by the domain name registrar, or by the provider, or by free resources. As soon as you figure out where your registrar refers, you will immediately understand where the zone should spin. And most likely it will not be your internal DNS.

F
Fiasco, 2014-07-16
@Fiasco

this is all of course interesting, but please tell me what addresses to write on the dns server - internal gray or external white? Everything was working before Mikrotik was installed.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question