Managing Name Resolution

Slides:



Advertisements
Similar presentations
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 6 Managing and Administering DNS in Windows Server 2008.
Advertisements

Web Server Administration
2.1 Installing the DNS Server Role Overview of the Domain Name System Role Overview of the DNS Namespace DNS Improvements for Windows Server 2008 Considerations.
Implementing Domain Name System
Domain Name System. DNS is a client/server protocol which provides Name to IP Address Resolution.
Chapter 9: Configuring DNS for Active Directory
4.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Hands-On Microsoft Windows Server 2003 Networking Chapter 6 Domain Name System.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 8: Managing and Troubleshooting DNS.
11.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 11: Introducing WINS, DNS,
Hands-On Microsoft Windows Server 2003 Networking Chapter 7 Windows Internet Naming Service.
Hands-On Microsoft Windows Server 2003 Administration Chapter 9 Administering DNS.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 5 Introduction to DNS in Windows Server 2008.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 7: Planning a DNS Strategy.
Domain Name Server © N. Ganesan, Ph.D.. Reference.
Network Protocols Transmission Control Protocol/Internet Protocol (TCP/IP) Asynchronous Transfer Mode (ATM) NWLink NetBIOS Enhanced User Interface (NetBEUI)
Chapter 10 Configuring DNS
Changes to DNS in Windows Server 2003 By David Pracht.
Domain Name Services Oakton Community College CIS 238.
1 Chapter Overview Understanding Windows Name Resolution Using WINS.
Windows Server 2008 Chapter 8 Last Update
Copyright line. Configuring DNS EXAM OBJECTIVES  An Introduction to Domain Name System (DNS)  Configuring a DNS Server  Creating DNS Zones  Configuring.
Hands-On Microsoft Windows Server 2008 Chapter 8 Managing Windows Server 2008 Network Services.
Configuring and Managing the DNS Server Role Lesson 4.
Host Name Resolution. Overview Name resolution Name resolution Addressing a host Addressing a host Host names Host names Host name resolution Host name.
11.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 11: Introducing WINS, DNS,
DNS and Active Directory Integration
Chapter Overview Understanding DNS Creating Zones
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
Module 7: Configuring TCP/IP Addressing and Name Resolution.
Name Resolution Domain Name System.
Implementing DNS Module D 7: Implementing DNS
Module 3: Configuring Basic TCP/IPv4 Settings. Overview of the TCP/IP Protocol Suite Overview of TCP/IP Addressing Name Resolution Dynamic IP Addressing.
1 Objectives Discuss the basics of the Domain Name System (DNS) and its terminology Configure DNS clients Install a standard DNS server on Server 2008.
CN2140 Server II Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+
Windows Server 2008 R2 Domain Name System Chapter 5.
Module 2: Implementing DNS to Support Active Directory
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 7: Domain Name System.
Zone Properties. Zone Properties Continued Aging allows zone to remove “stale” or “old” records for clients who have not updated within a certain period.
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network Chapter 6: Name Resolution.
70-291: MCSE Guide to Managing a Microsoft Windows Server 2003 Network, Enhanced Chapter 6: Name Resolution.
DNS Zones. DNS records kept in zones DNS server is authoritative for a domain if it hosts the zone for that domain Sub-domains can be kept in same zone.
Windows routing and resolution. Basic concepts  Host name: machine.sub-domain.domain example: mail.ubalt.edu same machine name in Windows in NetBIOS.
1 Week 7 – DNS and ADDS Integration Review of DNS Concepts, Components, and Processes Install and Configure DNS in an AD DS Domain AD DS, DNS, and Windows.
Implementing Active Directory Lesson 2. Skills Matrix Technology SkillObjective DomainObjective # Installing a New Active Directory Forest Configure a.
How to configure DNS for a Windows 2000 domain? 1.Start the Install/Remove Programs Control Panel Applet (Start - Settings - Control Panel - Add/Remove.
Objectives Discuss the basics of the Domain Name System (DNS) and its terminology Configure DNS clients Install a standard DNS server on Server 2008 Create.
Module 6: Managing and Monitoring Domain Name System (DNS)
Configuring and Troubleshooting Domain Name System
Configuring Name Resolution and Additional Services Lesson 12.
Windows Server 2003 DNS 安裝設定與管理維護 林寶森
Windows Server 2003 La migrazione da Windows NT 4.0 a Windows Server 2003 Relatore: MCSE - MCT.
DNS DNS overview DNS operation DNS zones. DNS Overview Name to IP address lookup service based on Domain Names Some DNS servers hold name and address.
Linux Operations and Administration
NT1330 Client Server Networking 2
Configuring and Managing the DNS Server Role Lesson 4.
KAPLAN SCHOOL OF INFORMATION SYSTEMS AND TECHNOLOGY IT375 Window Enterprise Administration Course Name – IT Introduction to Network Security Instructor.
Module 2: Implementing an Active Directory Forest and Domain Structure.
Ip addressing: dhcp & dns
Chapter Overview Understanding Windows Name Resolution Using WINS.
Understand Names Resolution
Network Protocols Transmission Control Protocol/Internet Protocol (TCP/IP) Asynchronous Transfer Mode (ATM) NWLink NetBIOS Enhanced User Interface (NetBEUI)
Module 5: Resolving Host Names by Using Domain Name System (DNS)
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 6: Planning, Configuring, And Troubleshooting WINS.
IMPLEMENTING NAME RESOLUTION USING DNS
Configuring and Troubleshooting DNS
Configuring and Managing the DNS Server Role
IIS.
Overview Multimedia: The Role of WINS in the Network Infrastructure
Windows Name Resolution
Presentation transcript:

Managing Name Resolution Network Services Managing Name Resolution

Nội dung Moving from Workgroups to Domain Environments TCP/IP for AD Transport, Access, and Support Using Group Policy to Manage Network Protocols

Introduction to NetBIOS Name Resolution 16-character name first 15 characters identify a unique host 16th character identifies a service or application running on host such as Workstation or Server service.

Introduction to WINS Installing WINS Configuring a WINS Server WINS Replication Configuring WINS Replication Forcing Replication

Install WINS

Install WINS

Exploring WINS & DNS Integration

Exploring WINS & DNS Integration

Examining WINS Replication

Examining WINS Replication

Examining WINS Replication

WINS replication partners

Upgrading a WINS Environment

Upgrading a WINS Environment

Active Directory Global Catalog

Configuring WINS Clients configure DHCP server to assign IP Address of WINS server to DHCP clients Open DHCP management console highlight Server Options in left pane select Action/ Configure 044 WINS/NBNS Servers Specifies IP address of WINS servers available to clients. 046 WINS/NBT Node Type Specifies name resolution type. available options include 1 = B-node (broadcast), 2 = P-node (peer), 4 = M-node (mixed), 8 = H-node (hybrid).

Configuring WINS Clients Windows XP client for WINS Open Local Area Connection/ Properties. select Internet Protocol (TCP/IP), click Properties. select Advanced tab and WINS tab. Click Add, type IP address for WINS server. Repeat process for additional WINS servers other configurable options Enable LMHOSTS Lookup enables client to use LMHOSTS file Enable NetBIOS over TCP/IP uses NetBIOS over TCP/IP and WINS Disable NetBIOS over TCP/IP disables NetBIOS over TCP/IP and WINS for LAN Use NetBIOS Setting from DHCP Server client obtain WINS information from a DHCP server.

Configuring Static Mappings Case clients are unable to dynamically update NetBIOS name with a WINS server  use static mapping Open WINS management console, Rclick Active Registrations, select New Static Mapping. type in computer name (NetBIOS name) for host. If required, type in NetBIOS scope. select type of entry created. Type in IP address of host.

DNS on a Windows Server 2008 R2

configure role Expand DNS Server, select DNS server Select Action/Config DNS Server Select Create Forward and Reverse Lookup Zones Select Create a Forward Lookup Zone Select type of zone Primary Zone Type FQDN in Zone Name

select Create a Reverse Lookup Zone Select Primary Zone Type in network ID of reverse lookup zone

Creating Resource Records list of common resource records Host Address (A) Maps a DNS name to IP address Start of Authority (SOA) Identifies primary DNS server for zone first resource record in a zone file Mail Exchanger (MX) Routes messages to a specified mail exchanger Pointer (PTR) map an IP address to a DNS name (reverse lookups). Alias (CNAME) another name for name referenced in another record. Service Locator (SRV) used to locate domain controllers in Active Directory domain

sample SOA record

Host (A) Records

Service (SRV) Records

Service (SRV) Records

Other DNS Record Types

DNS Zones a portion of a DNS namespace that is controlled by a particular DNS server or group of servers. establish boundaries over which a particular server can resolve requests.

Top level domain

Zone Types Forward Lookup Zones Reverse Lookup Zones resolves names to IP addresses and resource information Reverse Lookup Zones exact opposite operation as a forward lookup zone.

Zone Types primary zone secondary zone Active Directoryintegrated zone maintains master writable copy of zone in a text file secondary zone stores a copy of existing zone in read-only text file. To create a secondary zone, primary zone must already exist, must specify a master name server Active Directoryintegrated zone stores zone information within Active Directory configured on WS 2008 domain controllers run DNS Stub zone only a list of authoritative name servers for a particular zone. Ensure: DNS servers hosting a parent zone are aware of authoritative DNS servers for its child zones

Stub zone

Create stub zone

Entering stub master servers

Performing Zone Transfers Copying DNS database from server to another pulled by secondary servers from primary servers Primary DNS servers can be configured to notify secondary DNS servers of changes to a zone

Config secondary server to pull zone transfers from a forward lookup zone

create secondary zone & begin zone transfers

Initiating Incremental Zone Transfers asynchronous zone transfer

Recursive and iterative queries

Other DNS Componentss Time to Live time (in seconds) that a resolver or name server will keep a cached DNS request before requesting it again from original name server. modified via SOA record.

Changing TTL

Aging and Scavenging for DNS scavenging those records removes them from a database after their original owners do not update them not turned on, by default

Scavenging

Scavenging

forwarder

forwarder

Active Directory-Integrated Zones zones were stored in Active Directory, as opposed to a text file as in standard DNS. Windows Server 2008, utilizes AD-integrated zones,

DNS in Windows Server 2008 R2 Application Partition Active Directory-integrated zones are stored in application partition of AD Automatic Creation of Zones Forest Root Zone for _msdcs In AD, all client logons and lookups are directed to local DC and global catalog servers through references to SRV records in DNS.

Forest Root Zone for _msdcs

Troubleshooting DNS DNS Event Viewer to Diagnose Client-Side Cache and HOST Resolution Problems NSLOOKUP Command IPCONFIG Command TRACERT Command DNSCMD Command

DNS Event Viewer to Diagnose - enable Debug logging

log file dns.log in c:\windows\system32\dns\

Client-Side Cache and HOST Resolution Problems When requesting lookups, client resolver First parses this cache Then contact name server Items remain in cache until TTL expires, machine is rebooted, cache is flushed.  flush cache ipconfig /flushdns

NSLOOKUP view MX and SOA records associated with a specific domain

IPCONFIG ipconfig /flushdns ipconfig /registerdns ipconfig /displaydns forces client to dynamically reregister itself in DNS ipconfig /displaydns displays contents of client-side cache

TRACERT gives you an idea of path that a DNS query takes when being sent over a network.

DNSCMD

Secure DNS with DNSSEC

DNSSEC Components DNSSEC relies on signed zones records are signed as defined by RFC 4035 signed zone contains new DNSEC record types DNSKEY, NSEC, RRSIG, DS records Use Zone Signing Key (ZSK) Key Signing Key (KSK) is key used to sign ZSK

DNSEC record DNSKEY NSEC used to store a public key prove non-existence of a DNS name DNS clients to be sure that if a record is not retrieved in a DNS lookup, record does not exist in DNSSEC zone

DNSEC record RRSIG Delegation Signer (DS) hold signature for a DNS record Map: A record - RRSIG record Delegation Signer (DS) secure delegations to other DNS servers and confirm their validity

Config a DNSSEC Zone using dnscmd Scenario zone secure.companyabc.com will be encrypted generate signing certificates ZSK and KSK certificates. sign zone file and records reload zone file into DNS server.

generate signing certificates

KSK and ZSK certificates

sign zone file and records

reload zone file into DNS server

Encrypted zone records

config to request secure DNS entries Allow clients use DNSSEC properties of DNS zone  config a Name Resolution Policy Table (NRPT) policy for clients NRPT policy can be configured through group policy

create NRPT group policy for secure.companyabc.com zone