[Samba] Speed of Samba internal DNS for AD

Andrew Bartlett abartlet at samba.org
Tue Dec 14 02:01:37 UTC 2021

On Mon, 2021-12-13 at 17:48 -0800, Gregory Sloop via samba wrote:
> 2) Delegate my 3rd level domain (e.g. ad.somedomain.com) in my main
> BIND (not samba) servers to the AD servers for lookups and handle
> everything else on (non-samba) BIND.
> If the volume of lookups that Samba internal dns can handle is
> perhaps an issue, the second approach would be far better, since it
> will place the least load on the AD/Samba servers  - they'll only
> handle lookups they are actually responsible for. (not doing any
> forwarding)

Do 2).

Our forwarding code can fall over if the lists get too long due to
outstanding queries.  Also real DNS servers know about DNSSEC etc.

Andrew Bartlett

Andrew Bartlett (he/him)       https://samba.org/~abartlet/
Samba Team Member (since 2001) https://samba.org
Samba Team Lead, Catalyst IT   https://catalyst.net.nz/services/samba

Samba Development and Support, Catalyst IT - Expert Open Source

More information about the samba mailing list