DNS dynamic updates for non domain computers


hello!

i use secure dynamic updates ad-integrated zones still can't understand following: according ms's documentation dns servers should check whether client has  permission register or ptr record:

"the server checks ensure updates permitted client request. standard primary zones, dynamic updates not secured; therefore, client attempt update succeeds. for ad ds-integrated zones, updates secured , performed using directory-based security settings."

q1) these "security settings" located?

suppose  there dc , 4-5 domain-joined computers on same network other ~100-200 computers standalone workstations. default both forward , reverse dns zones configured secure updates , expect see records domain-joined pcs in both zones, see following:

1) forward zone: - expect (only domain-joined pcs registed there):

2) reverse zone - there many other non domain-joined pcs have ptr records registed in zone:


q2) why same setting (secure update) leads different results (there no records non domain-joined pcs while there plenty of records in reverse zone)?

thank in advance,

michael



hi michael,

>> q1) these "security settings" located?

you reference article below understanding:

checklist: secure dns server

https://technet.microsoft.com/en-us/library/cc770432(v=ws.11).aspx

>> q2) why same setting (secure update) leads different results (there no records non domain-joined pcs while there plenty of records in reverse zone)?

have tried delete ptr records non-domain-joined , checked if still exist?

please view dns events check process of ptr record integration non-domain-joined pcs.

best regards

john


please remember mark replies answers if , unmark them if provide no help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Windows Server 2012 General



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file