Talk With an Expert

Security Considerations for Dynamic DNS Implementation in a Windows2000 Environment

Security Considerations for Dynamic DNS Implementation in a Windows2000 Environment (PDF, 1.57MB)Published: 09 Sep, 2001
Created by
Deborah Wade

Windows2000 name resolution is based on Dynamic DNS. Microsoft's implementation of Dynamic DNS is based on RFC 2136. This correlates to BIND v8 and v9. BIND v9 is covered in the 4th Edition of 'DNS and BIND' by Paul Albitz & Cricket Liu published by O'Reilly. In Windows2000 Dynamic DNS is integrated with and related to DHCP WINS and Active Directory. There are 3 ways to implement DNS in a Windows2000 domain: Active Directory Integrated Active Directory primary with non-Active Directory secondary(s) or non-Active Directory primary and non-Active Directory secondary(s). When DNS is fully integrated into Active Directory we can then utilize three important security benefits in a Windows2000 network: Secure dynamic updates Secure zone transfers and Access Control Lists for zones and resource records.