Designing Advanced Name Resolution
Designing Advanced Name Resolution
Designing Advanced Name Resolution
Module Overview
Optimizing DNS Servers Designing DNS for High Availability and Security
Disabling Recursion
Disable recursion to limit name resolution to a specific server, or as a failover for another DNS server
Benefit: You will reduce the load on the DNS server Consequence: You will not be able to resolve names outside of your own zone
Delete root hints on servers that do not need to communicate with DNS servers that are authoritative for the root domain Modify root hints if the root domain is internal Update root hints when DNS servers that are authoritative for the root domain change
Arranges the query response, so that the records closest to the client subnet are first
Disable Round-robin rotation Used when multiple records match a request Rotates the order of responses for load balancing Install sufficient memory to cache all DNS zones
in memory
Have at least two DNS servers authoritative for each zone Place DNS servers in separate subnets or sites
Load Balancing:
Provides availability and scalability for DNS resolution Requires all DNS servers on the same subnet Does not protect against failed network links Is suitable for a centralized implementation of DNS
capturing data such as computer names and IP addresses it unavailable for normal use
Denial-of-service
Data modification
Redirection
Low
Use when there is no concern about DNS data Typically used when there is no external
connectivity
Medium
Available without running on domain controllers Internet resolution is performed through a proxy Includes medium level security measures
High
Must run on domain controllers to use ADintegrated zones and secure dynamic updates
LMHOSTS
Suitable for small environments Reduces broadcast traffic Requires static IP addresses
WINS
Suitable for organizations of all sizes
Reduces broadcast traffic Does not require static IP addresses
Pull replication:
Replicates after a specified period of time Ensures that all changes are replicated
Hub-and-Spoke Design
Do not use extended characters in NetBIOS names Consider using only DNS for name resolution Configure DNS for WINS Lookup and WINS Reverse Lookup
Resolution
Logon information
NYC-DC1, LON-DC1
Administrator Pa$$w0rd
Beta Feedback
Overall flow of module: Which topics did you think flowed smoothly, from topic to topic? Was something taught out of order? Pacing: Were you able to keep up? Are there any places where the pace felt too slow? Were you able to process what the instructor said before moving on to next topic? Did you have ample time to reflect on what you learned? Did you have time to formulate and ask questions? Learner activities: Which demos helped you learn the most? Why do you think that is? Did the lab help you synthesize the content in the module? Did it help you to understand how you can use this knowledge in your work environment? Were there any discussion questions or reflection questions that really made you think? Were there questions you thought werent helpful?