Home
%3CLINGO-SUB%20id%3D%22lingo-sub-359726%22%20slang%3D%22en-US%22%3EWindows%20Server%20101%3A%20Configuring%20Split-Brain%20DNS%20on%20Windows%20Server%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-359726%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3EOrganizations%20that%20use%20a%20public%20DNS%20zone%20name%2C%20such%20as%20tailwindtraders.net%2C%20for%20their%20organization%E2%80%99s%20internal%20host%20names%2C%20perhaps%20even%20using%20it%20with%20their%20organization%E2%80%99s%20Active%20Directory%20instance%2C%20generally%20have%20to%20configure%20what%20is%20known%20as%20split-brain%20DNS.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3ESplit-Brain%20or%20Split-Horizon%20DNS%20provides%20different%20information%20about%20the%20contents%20of%20a%20DNS%20zone%20based%20on%20the%20location%20that%20the%20DNS%20query%20originates.%20For%20example%2C%20a%20DNS%20query%20for%20the%20host%20%3CA%20href%3D%22http%3A%2F%2Fwww.tailwindtraders.net%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ewww.tailwindtraders.net%3C%2FA%3E%20might%20return%20a%20public%20IP%20address%20result%20for%20a%20host%20on%20the%20internet%20and%20a%20private%20IP%20address%20for%20hosts%20on%20the%20organization%E2%80%99s%20internal%20network.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EIn%20the%20past%2C%20some%20organizations%20would%20deploy%20separate%20DNS%20servers%20hosting%20different%20copies%20of%20the%20same%20zone%20to%20achieve%20a%20split-brain%20configuration.%20A%20DNS%20server%20on%20an%20internal%20network%20would%20host%20a%20version%20of%20the%20zone%20that%20had%20all%20hostname%20mappings%20with%20the%20IP%20addresses%20that%20should%20be%20returned%20to%20internal%20clients.%20A%20DNS%20server%20on%20the%20perimeter%20network%2C%20or%20even%20hosted%20at%20the%20ISP%2C%20would%20host%20the%20version%20of%20the%20zone%20that%20returned%20hostnames%20with%20public%20IP%20addresses.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EYou%20can%20implement%20split%20brain%20DNS%20on%20Windows%20Server%202016%20and%20Windows%20Server%202019%20using%20two%20new%20features%20known%20as%20DNS%20policies%20and%20DNS%20Zone%20scopes.%20DNS%20policies%20allow%20you%20to%20customize%20DNS%20server%20responses%20based%20on%20the%20properties%20of%20the%20requestor.%20DNS%20Zone%20scopes%20allow%20you%20to%20create%20different%20subset%20collections%20of%20DNS%20zone%20records%2C%20with%20each%20zone%20supporting%20multiple%20zone%20scopes%20and%20DNS%20records%20being%20able%20to%20be%20members%20of%20multiple%20zone%20scopes.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EWhen%20creating%20a%20DNS%20policy%20to%20implement%20split%20brain%20DNS%2C%20you%20need%20to%20first%20configure%20DNS%20zone%20scopes%20with%20one%20zone%20scope%20containing%20the%20host%20records%20that%20should%20be%20returned%20to%20an%20external%20client%20and%20another%20DNS%20zone%20scope%20containing%20host%20records%20that%20should%20be%20returned%20to%20internal%20clients.%20Once%20you%20have%20these%20two%20zone%20scopes%2C%20you%20then%20need%20to%20configure%20DNS%20policies%2C%20one%20to%20return%20records%20from%20DNS%20zone%20scope%20to%20be%20used%20by%20external%20clients%2C%20the%20other%20to%20return%20records%20from%20the%20DNS%20zone%20scope%20to%20be%20used%20by%20internal%20clients.%20%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EWhen%20you%20create%20a%20DNS%20policy%2C%20you%20can%20specify%20how%20clients%20are%20identified%20as%20internal%20on%20the%20basis%20of%20client%20IP%20address%20or%20the%20network%20adapter%20that%20the%20request%20arrives%20on.%20If%20your%20DNS%20server%20has%20two%20network%20adapters%2C%20one%20of%20which%20is%20connected%20to%20a%20perimeter%20network%20and%20another%20which%20is%20connected%20to%20the%20internal%20network%2C%20network%20interface%20based%20policies%20are%20the%20best%20option.%20If%20the%20DNS%20server%20only%20has%20a%20single%20network%20adapter%2C%20you%E2%80%99ll%20need%20to%20use%20client%20subnets.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EUsual%20practice%20is%20to%20place%20all%20records%20that%20should%20be%20available%20to%20clients%20on%20the%20public%20internet%20into%20the%20default%20zone%20scope%20and%20all%20records%20that%20should%20be%20available%20to%20internal%20clients%20in%20the%20internal%20scope.%20Once%20this%20is%20done%2C%20create%20a%20policy%20that%20allows%20access%20to%20the%20internal%20scope%20only%20for%20queries%20originating%20on%20the%20internal%20network%20interface%20or%20client%20subnets.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EYou%20create%20query%20resolution%20policies%20with%20the%20Add-DNSServerQueryResolutionPolicy%20cmdlet.%20For%20example%2C%20to%20create%20a%20policy%20named%20SplitPolicy%20that%20directs%20clients%20that%20address%20the%20DNS%20server%20on%20the%20server%20interface%20172.16.10.10%20to%20the%20zone%20scope%20Internal%20for%20the%20zone%20tailwindtraders.net%2C%20run%20the%20command%3A%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3EAdd-DNSServerQueryResolutionPolicy%20-Name%20%E2%80%9CSplitPolicy%E2%80%9D%20-Action%20ALLOW%20-ServerInterface%20%E2%80%9Ceq%2C172.16.10.10%E2%80%9D%20-ZoneScope%20%E2%80%9CInternal%2C1%E2%80%9D%20-ZoneName%20%E2%80%9Ctailwindtraders.net%E2%80%9D%3C%2FPRE%3E%0A%3CP%3E%3CSPAN%3ETo%20get%20more%20detail%20on%20the%20process%20of%20creating%20split%20brain%20or%20split%20horizon%20zones%20on%20DNS%20servers%20running%20Windows%20Server%202016%20or%20Windows%20Server%202019%2C%20consult%20the%20following%20docs.microsoft.com%20article%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fnetworking%2Fdns%2Fdeploy%2Fsplit-brain-dns-deployment%3FWT.mc_id%3DITOPSTALK-blog-orthomas%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fnetworking%2Fdns%2Fdeploy%2Fsplit-brain-dns-deployment%3FWT.mc_id%3DITOPSTALK-blog-orthomas%3C%2FA%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-359726%22%20slang%3D%22en-US%22%3E%3CP%3ELearn%20why%20and%20how%20to%20configure%20split%20brain%20DNS%20on%20Windows%20Server%202016%20and%20Windows%20Server%202019%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F71983iC390E6702DB6E1CE%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22Windows_Server_101.jpg%22%20title%3D%22Windows_Server_101.jpg%22%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3EHow%20To%20Migrate%20Windows%20Server%202008%20R2%20FSMO%20roles%20to%20Windows%20Server%202019%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-359726%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EPowerShell%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

Organizations that use a public DNS zone name, such as tailwindtraders.net, for their organization’s internal host names, perhaps even using it with their organization’s Active Directory instance, generally have to configure what is known as split-brain DNS.

 

Split-Brain or Split-Horizon DNS provides different information about the contents of a DNS zone based on the location that the DNS query originates. For example, a DNS query for the host www.tailwindtraders.net might return a public IP address result for a host on the internet and a private IP address for hosts on the organization’s internal network.

 

In the past, some organizations would deploy separate DNS servers hosting different copies of the same zone to achieve a split-brain configuration. A DNS server on an internal network would host a version of the zone that had all hostname mappings with the IP addresses that should be returned to internal clients. A DNS server on the perimeter network, or even hosted at the ISP, would host the version of the zone that returned hostnames with public IP addresses.

 

You can implement split brain DNS on Windows Server 2016 and Windows Server 2019 using two new features known as DNS policies and DNS Zone scopes. DNS policies allow you to customize DNS server responses based on the properties of the requestor. DNS Zone scopes allow you to create different subset collections of DNS zone records, with each zone supporting multiple zone scopes and DNS records being able to be members of multiple zone scopes.

 

When creating a DNS policy to implement split brain DNS, you need to first configure DNS zone scopes with one zone scope containing the host records that should be returned to an external client and another DNS zone scope containing host records that should be returned to internal clients. Once you have these two zone scopes, you then need to configure DNS policies, one to return records from DNS zone scope to be used by external clients, the other to return records from the DNS zone scope to be used by internal clients.

 

When you create a DNS policy, you can specify how clients are identified as internal on the basis of client IP address or the network adapter that the request arrives on. If your DNS server has two network adapters, one of which is connected to a perimeter network and another which is connected to the internal network, network interface based policies are the best option. If the DNS server only has a single network adapter, you’ll need to use client subnets.

 

Usual practice is to place all records that should be available to clients on the public internet into the default zone scope and all records that should be available to internal clients in the internal scope. Once this is done, create a policy that allows access to the internal scope only for queries originating on the internal network interface or client subnets.

 

You create query resolution policies with the Add-DNSServerQueryResolutionPolicy cmdlet. For example, to create a policy named SplitPolicy that directs clients that address the DNS server on the server interface 172.16.10.10 to the zone scope Internal for the zone tailwindtraders.net, run the command:

 

Add-DNSServerQueryResolutionPolicy -Name “SplitPolicy” -Action ALLOW -ServerInterface “eq,172.16.10.10” -ZoneScope “Internal,1” -ZoneName “tailwindtraders.net”

To get more detail on the process of creating split brain or split horizon zones on DNS servers running Windows Server 2016 or Windows Server 2019, consult the following docs.microsoft.com article: https://docs.microsoft.com/en-us/windows-server/networking/dns/deploy/split-brain-dns-deployment?WT....