DNS dynamic updates for non domain computers


hello!

i use secure dynamic updates ad-integrated zones still can't understand following: according ms's documentation dns servers should check whether client has  permission register or ptr record:

"the server checks ensure updates permitted client request. standard primary zones, dynamic updates not secured; therefore, client attempt update succeeds. for ad ds-integrated zones, updates secured , performed using directory-based security settings."

q1) these "security settings" located?

suppose  there dc , 4-5 domain-joined computers on same network other ~100-200 computers standalone workstations. default both forward , reverse dns zones configured secure updates , expect see records domain-joined pcs in both zones, see following:

1) forward zone: - expect (only domain-joined pcs registed there):

2) reverse zone - there many other non domain-joined pcs have ptr records registed in zone:


q2) why same setting (secure update) leads different results (there no records non domain-joined pcs while there plenty of records in reverse zone)?

thank in advance,

michael



hi michael,

>> q1) these "security settings" located?

you reference article below understanding:

checklist: secure dns server

https://technet.microsoft.com/en-us/library/cc770432(v=ws.11).aspx

>> q2) why same setting (secure update) leads different results (there no records non domain-joined pcs while there plenty of records in reverse zone)?

have tried delete ptr records non-domain-joined , checked if still exist?

please view dns events check process of ptr record integration non-domain-joined pcs.

best regards

john


please remember mark replies answers if , unmark them if provide no help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Windows Server 2012 General



Comments

Popular posts from this blog

directory stack

After enabling Windows Server 2012 R2 DHCP Failover Getting Packet dropped because of Client ID hash mismatch

WMI Repository 4GB limit - Win 2003 Ent Question