IWETHEY v. 0.3.0 | TODO
1,095 registered users | 0 active users | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New No Can Do
For AD to work, you really need SOA on your DNS domain.

Your ISP's DNS servers will not suffice unless they do IXFR (Incremental Zone Transfer), Dynamic Updates, Secure Updates. I believe BIND 8.3.1 is the earliest version that supports all these.

Even if your ISP supports IXFR, I'm not sure they'll be happy with your client workstations adding themselves to the zone file :-)

Working DNS is not optional - you MUST have functional DNS for AD to exist. It won't install or operate without it.


Peter
[link|http://www.debian.org|Shill For Hire]
[link|http://www.kuro5hin.org|There is no K5 Cabal]
[link|http://guildenstern.dyndns.org|Blog]
New Re: No Can Do
Well I've got it installed with no zones, and everything is fine other than a bitch in the event log about adding records from %SystemRoot%\\system32\\config\\netlogon.dns.

Can you give a step-by-step minimalist procedure?
-drl
New Re: No Can Do
First, a few concepts.

Active Directory is built on two main protocols - LDAP, and DNS. It's also highly unwise to have only one DC - two DCs gives you an actual, functional AD forest. Only one has bits missing, which I can't remember off the top of my head. It bites you in the arse, I remember that much :-)

Without functional DNS (functional means that the DNS server can have A records added to it automatically via Dynamic/Secure Update and supports the other doin's mentioned in my first post), you will not be able to install Active Directory onto your chosen DC-to-be via the DCPROMO.EXE route.

One of the reasons you need your DNS sorted out is that in W2K, the domain is a security boundary. Without a domain, this vanishes, and so does your AD structure.

Installing AD is a commitment to a DNS structure. If you fully grok this and its implications, then you can plan and design your network. If you try and half-arse it or work around the DNS thing, you'll have a semi-broken network and you'll only end up reformatting the servers anyway.

As for step-by-step - unfortunately, I'm nowhere near a W2K server right now so can't help you out right this minute. If you can be a little patient, I'll dig out my old MCSE course notes and see if I can't whip up a "5 minute guide to installing AD" thing.


Peter
[link|http://www.debian.org|Shill For Hire]
[link|http://www.kuro5hin.org|There is no K5 Cabal]
[link|http://guildenstern.dyndns.org|Blog]
New Re: No Can Do
Fine, I'm reading a WP from MS about it now. Thanks.
-drl
     Win2K Server HowTo - (deSitter) - (4)
         No Can Do - (pwhysall) - (3)
             Re: No Can Do - (deSitter) - (2)
                 Re: No Can Do - (pwhysall) - (1)
                     Re: No Can Do - (deSitter)

A.A.P.B. certified.
47 ms