0%

0/1 Lessons

Course Introduction

• 10min

0 / 2 lessons complete

DNS Basics

• 1hr 16min

0 / 8 lessons complete

DNS Resource Records

• 46min

0 / 5 lessons complete

DNS Zones

• 3hr 41min

0 / 12 lessons complete

DNS Delegation

• 50min

0 / 4 lessons complete

DNS Security Techniques

• 36min

0 / 5 lessons complete

Advanced DNS Topics

• 22min

0 / 5 lessons complete

DNS Security (DNSSEC)

• 1hr 16min

0 / 6 lessons complete

DNS Policies

• 54min

0 / 6 lessons complete

PowerShell for DNS

• 1hr 27min

0 / 6 lessons complete

Troubleshooting DNS Issues - Troubleshooting Tools

• 1hr 39min

0 / 8 lessons complete

Creating a Secondary Zones

Instructions

Q&A (0)

Notes (0)

Resources (0)

Saving Progress...

Resources

There are no resources for this lesson.

Notes can be saved and accessed anywhere in the course. They also double as bookmarks so you can quickly review important lesson material.

Create note

In this Video we will: 

  • Describe Secondary Zones
  • Explain why you would deploy a Secondary Zone
  • Then we will utilize what we have learned and create a Secondary Zone.
  • And finally, we will test the Zone
  • At the end of this lecture you will have a thorough understanding of Secondary Zones
  • You will know how to create, configure and test your Secondary Zone  

Prerequisites: You must have access to or have installed in your lab the following: 

  • One Windows 2016 Server with Active Directory installed and promoted to a domain controller (DNS installs automatically).
  • One member server with Windows 2016 server and DNS installed. This server must be joined to the domain. (Join this machine to the domain just like you would any other computer) 
  • Or two VM’s, one configured as a Domain Controller and one configured as a member server. 

AdequatePermissions will be needed.

  • To configure a DNS server that is not running as domain controller, you must be a member of the Administrators group for that computer.
  • To configure a DNS server that is running on a domain controller, you must be a member of the DNS Administrators, Domain Administrators, or Enterprise Administrators group

Describe a Secondary Zone 

  • It is a read only copy of a primary Zone
  • Changes cannot be made directly on the secondary server, only on the Master that holds the zone.
  • A secondary zone can be a copy of an Active Directory integrated zone.
  • Cannot be stored in Active Directory
  • In order for the secondary server to receive a copy of the zone, the master zone must be configured to allow zone transfers.
  • Secondary zones are supported on non-Microsoft DNS, will work with Linux and Unix.

Why would you Deploy Secondary Zones? 

  • Enhances redundancy
  • If the server hosting the Primary copy is unavailable, this server will be available for use by the clients in its place.

Creating a Secondary Zone 

Open Server Manager, then DNS Manager 

I am currently working from server SVR-US-DNS1.

I have created a brand new forward lookup zone called money.com.

Right now, SVR-US-DNS1 has the primary copy of those records from MONEY.COM in its data base.  

What if we want a secondary copy of that information on some other DNS server for backup purposes.

To accomplish this, we will need a second DNS server. I have a member server, that has been joined to the domain. The server has DNS installed but has not been promoted to a domain controller.  

Right click DNS, Connect to the DNS member server, type SVR-US-JD

Here we have SVR-US-DNS1 and the member server SVR-US-JD displayed.

Currently we do not have a copy of money.com on SVR-US-JD

The goal is to create a copy of money.com under SVR-US-JD.

To accomplish this: Right click on the forward lookup zone under SVR-US-JD click next, New Zone, the new zone wizard opens, click next, select Secondary Zone, next

Under Zone name - Type money.com (which will be a secondary for money.com)

Click next

Master DNS server â€“ To understand what server they are talking about here, you can ask yourself these questions. What is the server’s IP address that contains the zone money.com. Or where is the secondary getting the copy of its information? In this case, the master server is SVR-US-DNS1. I type 192.168.0.10. (Always verify the IP address on the VM, from TCPIP Properties) Click next, finish

Now we have a secondary zone called money.com on our second server.

When I click on money.com there is an error message that says the Zone has not been loaded.

Server Academy Members Only

Sorry, this lesson is only available to Server Academy Full Access members. Become a Full-Access Member now and you’ll get instant access to all of our courses.

0 0 votes
Lesson Rating
Subscribe
Notify of
profile avatar
2 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

profile avatar
ryanm3(@ryanm3)
Member
3 months ago

Hey, I’m having some issues when trying to create a secondary zone and transfer a master copy to it. It’s telling me that SVR-US-JD @ 192.168.0.11 is not authoritative in for the required zone.

-Ryan M

Secondary-Zone-Issue-Capture
profile avatar
Ricardo P(@ricardop)
Admin
Reply to  ryanm3
3 months ago

Hi profile avatar Ryan Monahan

Try with the server name since the red X it is because can’t do reverse lookup but should be OK. Also,check Zone Transfers Settings and ensure that “Allow zone transfers” is checked. Make sure “Only to servers listed on the Name Servers tab” or “Only to the following servers” is selected and the secondary DNS server (the one you are transferring to) is listed correctly.

Ricardo