[Samba] Strange DNS issue...

Rowland penny rpenny at samba.org
Wed Jun 9 18:26:34 UTC 2021

On 09/06/2021 19:15, Adam Pribyl via samba wrote:
> It is not in the LDAP/AD, this "dig" is served by bind, and this is 
> what I think is out of sync. I am not sure how it exactly works, but 
> if clients are not registering to master DNS then secondary DNS 
> instances will not get the domain updates?
> Adam Pribyl

Exactly, the dns records need to be updated in AD because the DC's are 
authoritative for their dns domain, if you have the records on another 
dns server, you will break the AD domain. Not having a reverse zone has 
nothing to do with this problem, you do not have to have a reverse zone, 
but it is better if you do. If you want to take load of the DC dns 
servers, you can do this by pointing the clients at a dns server outside 
the AD dns domain, but this dns server MUST forward all requests for the 
AD dns domain to the AD DC's.


More information about the samba mailing list