A
A
alovanton2015-11-16 14:36:06
Domain Name System
alovanton, 2015-11-16 14:36:06

No direct zone _msdcs.my.domain, how to add?

Purpose: Adding a second Win2012r2 domain controller.
Situation: Before adding a backup DC to the network, you need to run dcdiag tests . There were no problems, that is, in all tests there was a pass check.
But in Win2012r2 there is a Best Practices Analyzer, and in it I found this entry.
906590a9b75f4f0881ae4634fba98622.PNG
I immediately went to dns to confirm this fact.
As it turned out, there really is no such zone.
4631607d1d274fff9635c400e630cf3f.PNG
But there is no-ip.biz for ddns. Used for rdp connection by name.
My next steps:On the test bench, I set up a domain network on the same Win2012r2 distribution and specifically deleted the _msdcs.my.domain zone, rebooted a couple of times and ran dcdiag, and surprisingly I got errors.
b8ffd55d97b8469fa2d770eeff5d74b2.PNG
The question immediately arises. Why doesn't the same thing happen on a DC in a production network? What I missed
Steps to restore the zone:
1. Stop the dns service, net stop dns.
2. I rename the netlogon.dnb and netlogon.dns files.
3. Creation of a direct zone. Main -> _msdcs.my.domain
4. Restart services: net stop netlogon & net start netlogon.
On the test bench, it started up and worked.
Noticed some differences in the structures.
In the working domain in the my.domain direct zone, there are different containers and entries in the (roughly) _msdcs folder.
147f1a4df4b64939b60db53b7deeaf69.PNG
I also decided to compare on the test bench and was again surprised.
5f3cd0afc8394503adbb1fb550dbc456.PNG
In the direct entry m.local
Just a top-level entry _msdcs
Since there were many questions and unclear situations, I decided not to implement a new DC so far, so that there would be no problems with dns and ad replication.
I would be very grateful for any advice! Thank you!

Answer the question

In order to leave comments, you need to log in

1 answer(s)
N
Nadz Goldman, 2015-11-17
@nadz

I did not catch the essence of the question, but:
create a direct zone entry of the form: _msdcs.MY.DOMAIN
and create another direct zone entry: MY.DOMAIN
After that, run netdiag / fix
and then:
ipconfig / registerdns

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question