DNS dynamic updates for non domain computers
hello!
i use secure dynamic updates ad-integrated zones still can't understand following: according ms's documentation dns servers should check whether client has permission register or ptr record:
"the server checks ensure updates permitted client request. standard primary zones, dynamic updates not secured; therefore, client attempt update succeeds. for ad ds-integrated zones, updates secured , performed using directory-based security settings."
q1) these "security settings" located?suppose there dc , 4-5 domain-joined computers on same network other ~100-200 computers standalone workstations. default both forward , reverse dns zones configured secure updates , expect see records domain-joined pcs in both zones, see following:
1) forward zone: - expect (only domain-joined pcs registed there):
2) reverse zone - there many other non domain-joined pcs have ptr records registed in zone:
q2) why same setting (secure update) leads different results (there no records non domain-joined pcs while there plenty of records in reverse zone)?
thank in advance,
michael
hi michael,
>> q1) these "security settings" located?
you reference article below understanding:
checklist: secure dns server
https://technet.microsoft.com/en-us/library/cc770432(v=ws.11).aspx
>> q2) why same setting (secure update) leads different results (there no records non domain-joined pcs while there plenty of records in reverse zone)?
have tried delete ptr records non-domain-joined , checked if still exist?
please view dns events check process of ptr record integration non-domain-joined pcs.
best regards
john
please remember mark replies answers if , unmark them if provide no help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.
Windows Server > Windows Server 2012 General
Comments
Post a Comment