Professional Documents
Culture Documents
DNS 安裝設定與管理維護
林寶森
jeffl@ms11.hinet.net
What Is a Domain Namespace?
Root Domain
The
TheDNS
DNSserver
serverreturns
returnsaacomplete
completeanswer
answertotothe
the
Recursive
RecursiveQuery
Query query,
query,not
notaapointer
pointertotoanother
anotherDNS
DNSserver
server
Lookup
LookupTypes
Types
Forward
ForwardLookup
Lookup Requires
Requiresname-to-address
name-to-addressresolution
resolution
Reverse
ReverseLookup
Lookup Requires
Requiresaddress-to-name
address-to-nameresolution
resolution
How Recursive Queries Work
A recursive query is a query made to a DNS server, in which the DNS client
asks the DNS server to provide a complete answer to the query
172.16.64.11 Database
Ask nw
wtra query f
traders .com
.com
mai ursive
Itera
1
64.1
tive
Auth Que
l1.n
orita ry
.16.
Rec
tive R
espo
172
nse
Computer1 nwtraders.com
How Root Hint Works
Root hints are DNS resource records stored on a DNS server that list the
IP addresses for the DNS root servers
Root Hints
Local com
DNS Server
Computer1 microsoft
How Forwarders Work
A forwarder is a DNS server designated by other internal DNS servers to forward
queries for resolving external or offsite DNS domain names
Iterative Query
Forwarder Root Hint (.)
Ask .com
Iterative
Q uery
ry
ue
Ask nw .com
eQ
traders
.11
.com
siv
.64
cur
Itera
.16
tive
Re
Que
172
Auth ry
orita
172.1 tive R
6.
64.11 espo
Recu nse
r
mail1 sive query
.nwtr
aders for nwtraders.com
Local .com
Computer1
DNS Server
What Is a DNS Zone?
Nwtraders
Read-Only
Read-only copy of a DNS database
Secondary
Copy of
limited Copy of a zone containing limited records
records
Stub
Selecting Zone Data Location
Standard Zones
Change
Zone Transfer
Zone
Information
DNS Server B DNS Server C
DNS DNS
Server Server
(Master)
support training
Zone 1
Configuring Zone Transfers
• Zone Transfer Types
– Full zone transfer (AXFR)
– Incremental zone transfer (IXFR)
• Configuring Zone Transfer Properties
Serial number:
2 Increment
Refresh interval: 15 minutes
Retry interval: 10 minutes
Expires after: 1 days
Minimum (default) TTL: 0 :1 :0 :0
Notify…
OK Cancel Apply
OK Cancel A
Apply
pply
How DNS Notify Works
A DNS notify is an update to the original DNS protocol specification that
permits notification to secondary servers when zone changes occur
Resource record is
Destination Server 1 updated Source Server
SOA serial number is
2 updated
3 DNS notify
4 Zone transfer
Active
Active Directory
Directory
contoso.com
DNS Server
What Are Directory Partitions?
Contains:
Definitions and rules for creating
and manipulating objects and
attributes
Forest Schema
Information about the Active
Directory structure
Configuration
Information about domain-specific
Domain objects
<Domain>
Configurable
replication Information about applications
<Application>
Forest Application
Domain
Application
Domain Partition
Configuring Dynamic Updates
• DNS Dynamic Update Protocol
– Allows clients to automatically update DNS servers
– Can be used in conjunction with DHCP
1 Request
Requestfor
forIPIPaddress
address
DHCP
Server
Assign 2
AssignIPIPaddress
address
ofof192.168.120.133
192.168.120.133 DHCP
DHCPupdates
updatesreverse
reverse
Windows
Windowsclient
client resource
resourcerecord
recordfor
for
updates
updatesforward
forward Windows
Windows2000,
2000,XP
XPandand
resource
resourcerecord
record 2003
2003clients
clientsand
andboth
both
on
onDNS
DNSserver
server resource
resourcerecords
recordsfor
for
Computer1
other
otherclients
clients
192.168.120.133
OK Cancel Apply
Creating a Subdomain
• Create a Subdomain to Better Organize Your Namespace
• Delegate Authority of a Subdomain To
– Delegate management of portions of the namespace
– Delegate administrative tasks of maintaining one large DNS
database
“.”
org. com.
com. edu. tw.
microsoft.com.
training.microsoft.com.
Non-recursive You have Internet-facing DNS that are authoritative for one or
servers more zones
You want to manage the DNS traffic between your network and
Forward-only servers
the Internet
The records in the zone are sent to other DNS servers and clients in
1 response to queries
DNS servers and DNS clients that store the record in their cache hold
2 the record for the TTL period supplied in the record
3 When the TTL expires, the record is removed from the cache
Reducing Network Traffic by Using
Caching-Only Servers
Caching-Only Servers
– Perform name resolution on behalf of client computers and
cache the results
– Can be used to reduce DNS-related traffic across a WAN
Remote Office
Corporate Headquarters
Client
How Aging and Scavenging Works
7-days 7-days
Aging
What Is DNS Debug Logging?
DNS debug logging is an optional logging tool for DNS that stores the
DNS information that you select
Primary DNS Server1
Internal External
DNS Server Firewall
DNS Server
Internet
Screened
Subnet
Firewall
Firewall
Internet
Private
Network Screened
Firewall Subnet