Home

DHCP Server "Advanced" Dynamic DNS update

%3CLINGO-SUB%20id%3D%22lingo-sub-775662%22%20slang%3D%22en-US%22%3EDHCP%20Server%20%22Advanced%22%20Dynamic%20DNS%20update%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-775662%22%20slang%3D%22en-US%22%3E%3CP%3EAs%20I%20understand%20things%2C%20if%20you%20enable%20dynamic%20updating%20of%20DNS%20records%20on%20a%20DHCP%20scope%20on%20a%20windows%20DHCP%20server%2C%20the%20DHCP%20server%20will%20attempt%20to%20update%20the%20records%20of%20the%20FIRST%20DNS%20server%20on%20the%20scope's%20DNS%20server%20list.%26nbsp%3B%20Is%20there%20any%20way%20to%20change%20that%20behavior%20so%20that%20it%20uses%20an%20alternative%20DNS%20server%20for%20updates%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20reason%20I%20ask%20is%20because%20I%20want%20to%20use%20our%20firewall%20as%20the%20primary%20DNS%20server%20for%20our%20clients%2C%20but%20I%20also%20want%20to%20enable%20dynamic%20DNS%20registration%20as%20well%20and%20that%20is%20not%20possible%20through%20the%20firewall.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-775662%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ENetworking%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-775802%22%20slang%3D%22en-US%22%3ERe%3A%20DHCP%20Server%20%22Advanced%22%20Dynamic%20DNS%20update%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-775802%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CBLOCKQUOTE%3E%3CHR%20%2F%3EI%20want%20to%20use%20our%20firewall%20as%20the%20primary%20DNS%20server%20for%20our%20clients%2C%3C%2FBLOCKQUOTE%3E%0A%3CP%3EThis%20is%20going%20to%20be%20problematic.%20Domain%20controller%20and%20all%20members%20should%20have%20the%20static%20ip%20address%20of%20DC%20listed%20for%20DNS%20and%20no%20others%20such%20as%20router%20or%20public%20DNS.%20Your%20router%20%2F%20firewall%20knows%20nothing%20about%20your%20domain%20hence%20should%20not%20be%20used%20like%20that.%20More%20info%20here.%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fidentity%2Fad-ds%2Fplan%2Freviewing-dns-concepts%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fidentity%2Fad-ds%2Fplan%2Freviewing-dns-concepts%3C%2FFONT%3E%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%26nbsp%3B%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%26nbsp%3B%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-839480%22%20slang%3D%22en-US%22%3ERe%3A%20DHCP%20Server%20%22Advanced%22%20Dynamic%20DNS%20update%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-839480%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F51719%22%20target%3D%22_blank%22%3E%40Dave%20Patrick%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20fail%20to%20see%20how%20it%20would%20be%20problematic%20IF%20the%20dhcp%20clients%20could%20register%20their%20info%20in%20the%20secondary%20DNS%20server.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETO%20be%20clear%2C%20I%20want%20to%20setup%20the%20DHCP%20server%20to%20tell%20the%20clients%20to%20use%20the%20firewall%20as%20the%20primary%20DNS%20server%20and%20our%20DC%20as%20the%20secondary%20and%20make%20sure%20the%20DHCP%20server%20registers%20the%20client%20with%20the%20secondary%20DNS%20server.%26nbsp%3B%20The%20firewall%20IS%20NOT%20A%20delegated%20DNS%20server%20for%20the%20domain%20and%20it%20is%20actually%20not%20a%20DNS%20server%20at%20all%20and%20hosts%20no%20zone%20files.%26nbsp%3B%20It%20is%20a%20smart%20forwarder%20that%20will%20forward%20*.contoso.com%20lookups%20to%20the%20DNS%20servers%20designated%20for%20that%20domain%20and%20forward%20other%20DNS%20lookups%20out%20to%20our%20ISP's%20DNS%20servers%20for%20all%20other%20external%20domains.%26nbsp%3B%20I've%20tested%20it%20and%20it%20works%20perfectly%20well.%26nbsp%3B%20The%20ONLY%20problem%20with%20this%20setup%20is%20that%20the%20DHCP%20server%20and%20the%20clients%20will%20not%20register%20their%20names%20with%20the%20secondary%20DNS%20server%20and%20so%20any%20client%20that%20is%20configured%20to%20use%20the%20firewall%20as%20its%20primary%20DNS%20does%20not%20show%20up%20in%20the%20DNS%20system%20for%20forward%20or%20reverse%20lookups.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFrom%20what%20I've%20been%20able%20to%20find%2C%20there%20is%20no%20way%20to%20change%20this%20behavior%20and%20as%20such%20the%20only%20option%20is%20to%20use%20the%20DC%20as%20the%20primary%20DNS%20server%20if%20we%20want%20dynamic%20DNS%20registration%20to%20function.%26nbsp%3B%20The%20only%20place%20this%20is%20really%20much%20of%20an%20issue%20is%20on%20small%20remote%20sites%20connected%20through%20a%20VPN%20link%20without%20a%20local%20DC.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-839733%22%20slang%3D%22en-US%22%3ERe%3A%20DHCP%20Server%20%22Advanced%22%20Dynamic%20DNS%20update%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-839733%22%20slang%3D%22en-US%22%3E%3CP%3EYes%2C%20that's%20correct%2C%20the%20firewall%20router%20has%20no%20knowledge%20of%20the%20domain%20and%20active%20directory%20DNS.%20Domain%20controller%20and%20all%20members%20must%20use%20an%20integrated%20DNS%20%2F%20domain%20controller%20for%20DNS.%20If%20needed%20add%20forwarders%20to%20objects%20outside%20of%20scope%20of%20the%20domain.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EEven%20over%20VPN%20for%20route%20the%20members%20should%20have%20the%20domain%20controller%20listed%20for%20DNS%20and%20no%20others%20such%20as%20router%20or%20public%20DNS%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
oikjn
New Contributor

As I understand things, if you enable dynamic updating of DNS records on a DHCP scope on a windows DHCP server, the DHCP server will attempt to update the records of the FIRST DNS server on the scope's DNS server list.  Is there any way to change that behavior so that it uses an alternative DNS server for updates?

 

The reason I ask is because I want to use our firewall as the primary DNS server for our clients, but I also want to enable dynamic DNS registration as well and that is not possible through the firewall.

3 Replies

 


I want to use our firewall as the primary DNS server for our clients,

This is going to be problematic. Domain controller and all members should have the static ip address of DC listed for DNS and no others such as router or public DNS. Your router / firewall knows nothing about your domain hence should not be used like that. More info here.

https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/reviewing-dns-concepts

 

 

 

 

@Dave Patrick 

 

I fail to see how it would be problematic IF the dhcp clients could register their info in the secondary DNS server.

 

 

TO be clear, I want to setup the DHCP server to tell the clients to use the firewall as the primary DNS server and our DC as the secondary and make sure the DHCP server registers the client with the secondary DNS server.  The firewall IS NOT A delegated DNS server for the domain and it is actually not a DNS server at all and hosts no zone files.  It is a smart forwarder that will forward *.contoso.com lookups to the DNS servers designated for that domain and forward other DNS lookups out to our ISP's DNS servers for all other external domains.  I've tested it and it works perfectly well.  The ONLY problem with this setup is that the DHCP server and the clients will not register their names with the secondary DNS server and so any client that is configured to use the firewall as its primary DNS does not show up in the DNS system for forward or reverse lookups. 

 

From what I've been able to find, there is no way to change this behavior and as such the only option is to use the DC as the primary DNS server if we want dynamic DNS registration to function.  The only place this is really much of an issue is on small remote sites connected through a VPN link without a local DC.

Yes, that's correct, the firewall router has no knowledge of the domain and active directory DNS. Domain controller and all members must use an integrated DNS / domain controller for DNS. If needed add forwarders to objects outside of scope of the domain.

 

Even over VPN for route the members should have the domain controller listed for DNS and no others such as router or public DNS

 

 

 

Related Conversations
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
30 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies