PHWinfo banniere

Titres
PORTAIL ANNUAIRE ARTICLES COMPARATEUR HÉBERGEURS DEVIS FORUMS RÉDUCTEUR D'URL
Précédent   PHWinfo > Forums Hébergement > Forum Noms de domaine > ms.public.win.server.dns > Prevent DDNS update to a record or at least "lock" it?
S'inscrire FAQ Membres Recherche Messages du jour Marquer les forums comme lus
Prevent DDNS update to a record or at least "lock" it?

Réponse
 
LinkBack Outils de la discussion
Vieux 12/01/2007, 16h34   #1
Jay
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Prevent DDNS update to a record or at least "lock" it?

I have a situation where we have to use unauthenticated DDNS and from time
to time, someone will inadvertently name a device the same name as a server.
The short version of the story is that the server record ends up getting
deleted and I'd like to prevent that from happening.

If it s, the server record is manually created by an administrator.
DHCP is also being used to create DDNS records.

Seems to me the best solution would be to prevent any device from being able
to create the record with a matching name in the first place. I'm thinking
along the lines of the DNS server would reject the change/addition since
there is alrady a manually created record with the same name. That would
prevent round robin from kicking in and serving up both IP addresses. It
might even prevent the rename of said device from removing the manually
created record. Is this possible?

Failing the ability to do that, I'd at least like to prevent it (dynamic
part of DDNS) from deleting the manually created record. Can I do this with
the security settings on the DNS record? Or is there some other way to
"lock" a record so it can't be updated dynamically?

Using w2k3 for dns and w2k for dhcp.

Thanks!


  Réponse avec citation
Vieux 12/01/2007, 21h25   #2
Greg Lindsay
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Prevent DDNS update to a record or at least "lock" it?

I believe there is a way to deny the security privilege to update host
records, but I don't think it can be isolated to a single record. I don't
think this would in your situation.

However, there is a workaround that you can use. Create an A record with
the IP address of your server, but use a different name for the A record
that will not be duplicated by accident (something like server7341X).

Then, create a CNAME with the name that you want for your server and point
it to this new A record. Since you can't create an A record if a CNAME
already exists with the same name, then that record will not be overwritten.

I hope this s.

--
Greg Lindsay [MSFT]

Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.

"Jay" <nospam@no.where> wrote in message
news:eltfHemNHHA.2468@TK2MSFTNGP06.phx.gbl...
>I have a situation where we have to use unauthenticated DDNS and from time
>to time, someone will inadvertently name a device the same name as a
>server. The short version of the story is that the server record ends up
>getting deleted and I'd like to prevent that from happening.
>
> If it s, the server record is manually created by an administrator.
> DHCP is also being used to create DDNS records.
>
> Seems to me the best solution would be to prevent any device from being
> able to create the record with a matching name in the first place. I'm
> thinking along the lines of the DNS server would reject the
> change/addition since there is alrady a manually created record with the
> same name. That would prevent round robin from kicking in and serving up
> both IP addresses. It might even prevent the rename of said device from
> removing the manually created record. Is this possible?
>
> Failing the ability to do that, I'd at least like to prevent it (dynamic
> part of DDNS) from deleting the manually created record. Can I do this
> with the security settings on the DNS record? Or is there some other way
> to "lock" a record so it can't be updated dynamically?
>
> Using w2k3 for dns and w2k for dhcp.
>
> Thanks!
>


  Réponse avec citation
Vieux 12/01/2007, 22h04   #3
Greg Lindsay
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Prevent DDNS update to a record or at least "lock" it?

Actually, I found that you can expressly deny security on a single record.
View the properties of the record. On the security tab, remove write
permission from authenticated users and domain computers. Test it using
ipconfig /registerdns on a client computer.

--
Greg Lindsay [MSFT]

Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.

"Greg Lindsay" <greglin@microsoft.com> wrote in message
news:%23NM%230ApNHHA.4992@TK2MSFTNGP04.phx.gbl...
>I believe there is a way to deny the security privilege to update host
>records, but I don't think it can be isolated to a single record. I don't
>think this would in your situation.
>
> However, there is a workaround that you can use. Create an A record with
> the IP address of your server, but use a different name for the A record
> that will not be duplicated by accident (something like server7341X).
>
> Then, create a CNAME with the name that you want for your server and point
> it to this new A record. Since you can't create an A record if a CNAME
> already exists with the same name, then that record will not be
> overwritten.
>
> I hope this s.
>
> --
> Greg Lindsay [MSFT]
>
> Disclaimer: This posting is provided "AS IS" with no warranties, and
> confers
> no rights.
>
> "Jay" <nospam@no.where> wrote in message
> news:eltfHemNHHA.2468@TK2MSFTNGP06.phx.gbl...
>>I have a situation where we have to use unauthenticated DDNS and from time
>>to time, someone will inadvertently name a device the same name as a
>>server. The short version of the story is that the server record ends up
>>getting deleted and I'd like to prevent that from happening.
>>
>> If it s, the server record is manually created by an administrator.
>> DHCP is also being used to create DDNS records.
>>
>> Seems to me the best solution would be to prevent any device from being
>> able to create the record with a matching name in the first place. I'm
>> thinking along the lines of the DNS server would reject the
>> change/addition since there is alrady a manually created record with the
>> same name. That would prevent round robin from kicking in and serving up
>> both IP addresses. It might even prevent the rename of said device from
>> removing the manually created record. Is this possible?
>>
>> Failing the ability to do that, I'd at least like to prevent it (dynamic
>> part of DDNS) from deleting the manually created record. Can I do this
>> with the security settings on the DNS record? Or is there some other way
>> to "lock" a record so it can't be updated dynamically?
>>
>> Using w2k3 for dns and w2k for dhcp.
>>
>> Thanks!
>>

>


  Réponse avec citation
Réponse


Outils de la discussion

Règles de messages
Vous ne pouvez pas créer de nouvelles discussions
Vous ne pouvez pas envoyer des réponses
Vous ne pouvez pas envoyer des pièces jointes
Vous ne pouvez pas modifier vos messages

Les balises BB sont activées : oui
Les smileys sont activés : oui
La balise [IMG] est activée : oui
Le code HTML peut être employé : non
Trackbacks are oui
Pingbacks are oui
Refbacks are oui


Fuseau horaire GMT +1. Il est actuellement 21h28.


Édité par : vBulletin® version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC5 Tous droits réservés.
Version française #16 par l'association vBulletin francophone
PHWinfo est un site Éducation Sans Frontières
Ad Management by RedTyger
©Tous droits réservés par les parties respectives
Page generated in 0,11269 seconds with 11 queries