There are times when you want to restrict a Domain Controller from registering certain resource records in the DNS. One of the scenario is when you have hub - spoke topology, it is preferable that if all domain controllers/global catalogs in a satellite site become unavailable, a client that is searching for a domain controller/global catalog in that site will fail over to a domain controller/global catalog in a central hub and not in another satellite site.
To achieve this behavior, the domain controllers/global catalogs in the satellite offices should not register generic (non-site-specific) domain controller locator DNS records
To restrict the DNS resource records that are updated by NetlLogon
Global Catalog-Specific Records
To achieve this behavior, the domain controllers/global catalogs in the satellite offices should not register generic (non-site-specific) domain controller locator DNS records
To restrict the DNS resource records that are updated by NetlLogon
- Open Registry Editor.
- In Registry Editor, navigate to the following registry key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters - Add the following multistring value (REG_MULTI_SZ) value:
DnsAvoidRegisterRecords - In this value, specify the list of data corresponding to the DNS resource records that should not be registered for this domain controller by the Net Logon service. The following table contains the list of data.
Mnemonic | <>>Type | <>DNS Record |
---|---|---|
LdapIpAddress | A | |
Ldap | SRV | _ldap._tcp. |
DcByGuid | SRV | _ldap._tcp. |
Kdc | SRV | _kerberos._tcp.dc._msdcs. |
Dc | SRV | _ldap._tcp.dc._msdcs. |
Rfc1510Kdc | SRV | _kerberos._tcp. |
Rfc1510UdpKdc | SRV | _kerberos._udp. |
Rfc1510Kpwd | SRV | _kpasswd._tcp. |
Rfc1510UdpKpwd | SRV | _kpasswd._udp. |
Global Catalog-Specific Records
Mnemonic | Type | DNS Record |
---|---|---|
Gc | SRV | _ldap._tcp.gc._msdcs. |
GcIpAddress | A | gc._msdcs. |
GenericGc | SRV | _gc._tcp. |
2 comments:
Thanks for sharing excellent informations. Your site is very cool. I’m impressed by the details that you have on this blog. It reveals how nicely you perceive this subject. Web Hosting India
Get Fully DMCA Ignored Hosting with 99.9% uptime Guarantee in Cheapest Prices. All offshore servers are hosted in multiple locations so you can run your websites very smoothly without worrying about DMCA complaints. We are offering offshore shared hosting, Offshore VPS & Offshore Dedicated Servers
Post a Comment