ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Windows AD DNS Server Per NIC Responses with ZeroTier

    IT Discussion
    windows active directory dns windows dns zerotier
    5
    31
    5.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • dafyreD
      dafyre
      last edited by

      I actually was thinking about things like two separate NICs in a DNS server that sits on 2 networks that don't have access to one another.

      I don't want the DNS server giving out 192.168.50 addresses on the 192.168.30 subnet.

      scottalanmillerS 1 Reply Last reply Reply Quote 0
      • scottalanmillerS
        scottalanmiller @dafyre
        last edited by

        @dafyre said:

        I actually was thinking about things like two separate NICs in a DNS server that sits on 2 networks that don't have access to one another.

        I don't want the DNS server giving out 192.168.50 addresses on the 192.168.30 subnet.

        What is the underlying purpose of the dual homing?

        1 Reply Last reply Reply Quote 0
        • dafyreD
          dafyre
          last edited by

          To have one DNS server serving two separate, unrelated subnets to which it has a NIC in each.

          scottalanmillerS 1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller @dafyre
            last edited by

            @dafyre said:

            To have one DNS server serving two separate, unrelated subnets to which it has a NIC in each.

            Why are the subnets unrelated if single devices have to sit on both of them? They must be somehow related. Why isn't there a third, service network for the shared services? Once you multi-home you are tying the networks together, just in a poor way.

            dafyreD 1 Reply Last reply Reply Quote 0
            • dafyreD
              dafyre @scottalanmiller
              last edited by dafyre

              @scottalanmiller said:

              @dafyre said:

              To have one DNS server serving two separate, unrelated subnets to which it has a NIC in each.

              Why are the subnets unrelated if single devices have to sit on both of them? They must be somehow related. Why isn't there a third, service network for the shared services? Once you multi-home you are tying the networks together, just in a poor way.

              Only if you are using a device for routing. And that is not what I want done...

              What I want is Split-Brain DNS (coming Feature in Server 2016, http://blogs.technet.com/b/networking/archive/2015/05/12/split-brain-dns-deployment-using-windows-dns-server-policies.aspx)... Guess I gotta wait a few more weeks.

              My primary use case would be for something like with ZeroTier, but I could see it being useful under certain types of lab conditions as well.

              1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller
                last edited by

                But why don't you want that done? You are leading with your tech want, but what is the business need? What is the business factor pushing you to dual homing?

                1 Reply Last reply Reply Quote 0
                • dafyreD
                  dafyre
                  last edited by dafyre

                  Just to be clear, I've answered my question -- I didn't know what it was called, but it is called Split-Brain DNS. If you are a Windows shop, you get that feature in Server 2016.

                  ===

                  You know as well as I do that a Lab environment needs to be isolated from the network, and it some shops, the lab network doesn't even have internet access. I'd like to have my lab network connected to a multihomed DNS server simply because I can. I want to know if the tech can do what I want it to do. No other reason is necessary.

                  scottalanmillerS 2 Replies Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller @dafyre
                    last edited by

                    @dafyre said:

                    You know as well as I do that a Lab environment needs to be isolated from the network, and it some shops, the lab network doesn't even have internet access. I'd like to have my lab network connected to a multihomed DNS server simply because I can. I want to know if the tech can do what I want it to do. No other reason is necessary.

                    That's fine. If it is a lab you can obviously do whatever you want to do.

                    For isolation, though, just to be clear and for anyone who reads this and gets the wrong idea from the statement made above, dual homing has always been avoided for security reasons. So if the goal is to isolate a lab from product, or whatever, that is why you avoid dual homing and use a service network. Because the dual homing exposes the product to the lab more, rather than less, than a service network.

                    I just don't want others reading along and not realizing that this is a lab for a lab's sake and thinking that there is a standard product network design pattern here.

                    1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @dafyre
                      last edited by scottalanmiller

                      @dafyre said:

                      You know as well as I do that a Lab environment needs to be isolated from the network.... can. I want to know if the tech can do what I want it to do. No other reason is necessary.

                      This is the bit that I was concerned about. Lacking the lab isolation that I was suggesting. I realize not everyone needs their lab fully isolated, just seems simpler since it would be safer, easier and fix the issue that this thread was about all in one step. I'm saying that a fully isolated lab is easier.

                      1 Reply Last reply Reply Quote 0
                      • DashrenderD
                        Dashrender
                        last edited by

                        Also, wouldn't this lab still be fully part of the AD network since it's using the same DNS servers? If the answer is yes, then it's not really a lab, it's an extension of the production network.

                        scottalanmillerS 1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller @Dashrender
                          last edited by

                          @Dashrender said:

                          Also, wouldn't this lab still be fully part of the AD network since it's using the same DNS servers? If the answer is yes, then it's not really a lab, it's an extension of the production network.

                          No, not in that way. AD would be extended by LDAP and Kerberos. DNS is just a lookup service. Although this would theoretically expose information about AD, not very much. For full separation you would go with separate DNS in each place. But sharing DNS is pretty trivial as exposure goes.

                          DashrenderD 1 Reply Last reply Reply Quote 0
                          • DashrenderD
                            Dashrender @scottalanmiller
                            last edited by

                            @scottalanmiller said:

                            @Dashrender said:

                            Also, wouldn't this lab still be fully part of the AD network since it's using the same DNS servers? If the answer is yes, then it's not really a lab, it's an extension of the production network.

                            No, not in that way. AD would be extended by LDAP and Kerberos. DNS is just a lookup service. Although this would theoretically expose information about AD, not very much. For full separation you would go with separate DNS in each place. But sharing DNS is pretty trivial as exposure goes.

                            if the lab machines aren't part of AD, how are they adding entries to DNS? This is all assuming a Windows DNS.

                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller @Dashrender
                              last edited by

                              @Dashrender said:

                              if the lab machines aren't part of AD, how are they adding entries to DNS? This is all assuming a Windows DNS.

                              I think that I missed that they were adding their own entries. You can add things manually to DNS.

                              1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller
                                last edited by

                                If you use Windows for DHCP, Linux can update DNS records that way without being part of AD:

                                http://www.virtxpert.com/allow-linux-to-register-records-with-windows-dns-and-dhcp/

                                1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller
                                  last edited by

                                  I mention Linux here because it is the most extreme case. If Linux can do it, Windows can too.

                                  1 Reply Last reply Reply Quote 0
                                  • dafyreD
                                    dafyre
                                    last edited by

                                    Chances are if Linux can do it, it probably does it better than Windows, lol.

                                    scottalanmillerS Reid CooperR 2 Replies Last reply Reply Quote 2
                                    • scottalanmillerS
                                      scottalanmiller @dafyre
                                      last edited by

                                      @dafyre said:

                                      Chances are if Linux can do it, it probably does it better than Windows, lol.

                                      And even moreso when virtualized.

                                      1 Reply Last reply Reply Quote 1
                                      • Reid CooperR
                                        Reid Cooper @dafyre
                                        last edited by

                                        @dafyre said:

                                        Chances are if Linux can do it, it probably does it better than Windows, lol.

                                        I would second that.

                                        1 Reply Last reply Reply Quote 0
                                        • 1
                                        • 2
                                        • 2 / 2
                                        • First post
                                          Last post