Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


April 2008

Tried-and-True DNS Wisdom

Systems administrator Apostolos Fotakelis reveals his DNS best practices and troubleshooting insights
RSS
Subscribe to Windows IT Pro | See More Domain Name System (DNS) Articles Here | Reprints
SideBar    A Sysadmin’s DNS Best Practices
Main Article    Conquer 2 New DNS Exploits

Executive Summary:

Apostolos Fotakelis shares best practices for running a secure DNS environment, which he’s compiled in his experience as a Microsoft Windows systems administrator.


DNS wasn’t exactly designed with security in mind, and no one is more aware of this than Apostolos Fotakelis, a systems administrator with NATO in Albania. Apostolos, a regular contributor to Windows IT Pro’s Reader to Reader section, compiled a set of DNS best practices based on his DNS experiences over the past 11 years he’s been in IT, including a stint as systems administrator at Aristotle University of Thessaloniki, Greece. Recently Apostolos and I discussed the techniques he uses for making DNS more secure and some examples from his experiences troubleshooting problems related to name resolution.

Q: What sort of environment are you supporting?

A: For security reasons, I can’t describe our infrastructure [at NATO], so I’ll talk about my previous environment at the university instead.

We had eight servers. Initially they ran Linux, IRIX, Solaris, and Windows NT 4.0, but gradually we moved mainly to Windows Server 2003 R2, while preserving two servers running Linux. One of the Linux servers was virtualized. Also we had a ninth Windows 2003 server that was used for some short-term research needs and became live only when needed. In July 2007, we installed a Windows Server 2008 Beta 3 server at one of our sites for testing purposes. The number of end users and workstations varied over time from 50 to 100, depending on our research projects in progress. The clients were running 32- and 64-bit Windows XP. Our main site was on [the university’s] campus, and there were two other sites with research labs. The main applications included both Microsoft Office tools (Word, Excel) and our own software and tools for digital watermarking, digital video processing, and artificial intelligence projects.

Q: DNS is a perennial topic of interest for many of our readers, since it’s an essential part of their jobs. What are some DNS best practices you’ve developed over the years?

A: Generally, I always pay special attention to name resolution (mainly DNS, not so often WINS), since it’s something that every infrastructure relies on. When name resolution doesn't work perfectly, it causes numerous problems that sometimes don’t even point to name-resolution problems. So you need to make sure DNS/WINS is set up correctly before you can deal with other Windows IT issues, such as Active Directory and security.

Over time, I’ve developed a DNS best practices list that I always check when setting up a network (see the sidebar “A Sysadmin’s DNS Best Practices List”). Initially I followed Microsoft’s DNS recommendations, then tried some other approaches as well. My DNS resources have been Microsoft TechNet, various forums, and personal experimentation. Also, as a Microsoft Certified Trainer (MCT), I’ve been lucky enough to have taught some smart students who asked me questions that required me to dig even further into DNS, and I also learned from troubleshooting the DNS problems that they faced in their environments. I’ve found these DNS best practices to be applicable for the vast majority of the companies and organizations I’ve worked with.

Q: What are some examples of unusual network behavior you’ve seen that have turned out to be name-resolution problems?

A: Well, usually big delays when opening shared folders on the network indicate such problems, but unfortunately there are also cases where the problem remains well hidden. For example, once I had a client whose Microsoft Exchange server logged numerous errors in the event log without giving any clue that would point to name resolution. It turned out to be a Global Catalog server wrongly registered in DNS; however, we lost many hours trying to troubleshoot the problem.

Testing name resolution is easy but usually isn’t the first thing that comes to mind when you’re troubleshooting problems. My experience so far has shown that unexplainable delays in a LAN usually are either name resolution or RPC (remote procedure call)–related, so I try to test these things first before moving to higher-level troubleshooting.

Q: What are some other challenges your IT department faces in supporting your end users, especially with networking and security?

A: Our needs at Aristotle University of Thessaloniki generally were not vastly different from those of a business environment. From an IT point of view, we faced the same demands for availability, reliability, and security. However, there were also some special needs. For example, when we needed an ERP program, we couldn’t find one on the market that met our needs, so we had to develop our own. Also, many of our applications were for research purposes. That is, they were still under development and usually not well documented, so when you had a problem with an application, you couldn’t expect to find any help on the Internet. All these special needs had a direct effect on security: Since there was no official provider to release patches and updates, you had to act proactively and do in-depth searches when dealing with software security issues.

Another challenge was that sometimes users needed a program that was developed for another platform and didn’t run on Windows XP. In that case, Microsoft Virtual PC was a godsend. Formerly we had dedicated computers for such programs, but with Virtual PC, we just stored the Virtual PC images on DVDs and deployed them to the users that needed the programs.

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Managing Virtual Sprawl

As some wise person once said, nothing is ever truly free. Such is the case with VMs, which can quickly mutate from a cost-reducing Dr. Jekyll into a time-consuming, profligate nightmare that would do Mr. Hyde proud. ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...


Networking Whitepapers Measure the Real ROI of Enterprise Monitoring Software

How to Evaluate and Choose a Messaging Archiving Solution

An IT Investment That Pays Real Dividends: Building ROI with your Email System

Related Events Check out our list of Free Email Newsletters!

Networking eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

SQL Server Administration for Oracle DBAs

Related Networking Resources Order Windows IT Pro VIP and SAVE!!
Get it all with Windows IT Pro VIP A $500+ value foir only $279!

Monthly Online Pass - Only $5.95!
Get instant access to 9,000+ articles from Windows IT Pro Magazine!!

Buy One Get One!
Order Windows IT Pro & Get SQL Server Magazine FREE!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.




ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

EXCHANGE 2007 Mastery Series – May 29, 2008
3 Info-packed eLearning seminars for only $99! Learn the pros and cons of your mailbox high availability options, see real-world examples of Transport Rules, and get started with basic PowerShell commands with Mark Arnold, MCSE+M and Microsoft MVP.

Windows IT Pro Master CD: Take the Experts with You!
Find the solutions you need in thousands of searchable articles, helpful bonus content, and loads of expert advice with the Windows IT Pro Master CD. Order comes with a 1-year subscription to the new, online articles posted every day!

Making the Case for Oracle Database on Windows
One of the best-kept secrets in the IT industry is the depth of support Oracle offers to customers deploying its databases on Microsoft Windows platforms.

SQL Server Magazine Master CD: Take the Experts with You!
Find the solutions you need in thousands of searchable articles, helpful bonus content, and loads of expert advice with the SQL Server Magazine Master CD. Order comes with a 1-year subscription to the new, online articles posted every day!

Attention User Group Leaders...
Announcing the eNews Generator—a FREE HTML e-newsletter builder for user group leaders. Build your HTML and text e-newsletters in minutes. And add Windows IT Pro & SQL Server Mag articles alongside your own message!.

Become a fan of Windows IT Pro on Facebook
Join the Windows IT Pro fan club on Facebook. Chat with other IT Pros, upload your pictures, check out what's up n' coming in the next issue and more!



Solve the 12 Toughest Active Directory Management Tasks Today
No matter which management tasks you’re dealing with, you’ll discover a new set of ideas about how to best manage your Active Directory environment.

Get Started with Oracle on Windows DVD
Learn how Oracle gives you the power to grow by providing a scalable, easy-to-use platform for running your business at a price you can afford.

Virtualization Essentials – Free Online Conference :: June 24th
Learn virtualization basics - Discover how to reduce IT costs while increasing the efficiency, utilization, and flexibility of your existing computer hardware. Register Today!

Gain enhanced insight into and control over your IT systems.
View this web seminar to learn about the latest and greatest features and product enhancements in the Systems Center Configuration Manager SP1 and R2.

11 Myths About Microsoft Exchange Backup & Recovery
This white paper will guide you in overcoming Exchange Backup and Recovery myths with careful planning and the right toolset.
Windows IT Pro Home Register About Us Affiliates / Licensing Press Room Media Kit Contact Us/Customer Service  
SQL Connected Home IT Library SuperSite FAQ Wininfo News
Europe Edition Office & SharePoint Pro Windows Dev Pro Windows Excavator 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing