How to setup multiple DNS zones in a single domain

We have a small charter school running a Mac Open Directory network on a single subnet with a single registered FQDN for its internal domain. We are about to open a second school within a wing of the same building which will also be on a Mac Open Directory domain, but since it is legally a separate school (just administered by the same staff) it needs to be on it's own subnet and have its own LDAP directory.
Is there a way to program DNS between the two schools so that DNS traffic can be routed between them without breaking the DNS and Open Directory/Kerberos realms of either? Both schools will share the same internal domain name. Is it as simple as creating two primary DNS zones on each other's nameservers, both using the same domain name but each having its own designated nameserver for that particular subnet?
For instance, the existing school is running DNS on server1.example.com within the 10.39.54.0/23 subnet. The second school will be running DNS on server2.example.com within the 10.39.56.0/23 subnet. Would I then simply create two primary zones within each subnet, one referring to its own with itself as the nameserver and one within the neighbor subnet referencing that subnet's server as the designated nameserver.
Or would I do this with each schools DNS servers searching through its own subnet as its primary zone with the neighbor zone being added as a secondary zone?
Thanks!

You have two options.
Use a DNS server with a single internal domain example.com and have (as you said) server1.example.com
If the two subnets are on separate networks either via a router or VLAN, then you could run a separate DHCP server on each and advertise the appropriate DNS server for that subnet.
Otherwise you could have a single DNS server and either single DHCP advertising that single DNS server and have both server1 and server2 in the single DNS zone, or a DHCP server in each subnet but still pointing to the same single DNS server.
Each of these two servers would be an Open Directory Master
Note: in DNS terminology a DNS 'zone' is the same thing as a Domain Name.
The second option which if you want to keep the two 'schools' completely separate is to do the following
Use a DNS server per subnet
Use a DHCP server per subnet
Use a different domain name per school e.g. school1.com and school2.com
Create a server record on each as appropriate e.g. server1.school1.com and server2.school2.com
You cannot have a single DNS server have two identical zones e.g. example.com and example.com as they are of course the same thing.
If the two schools will merge officially at some point it might be better to use the same domain name, if they are going to fully split then definiately it is going to be better to use two different domain names.

Similar Messages

  • How to setup multiple base station under one network?

    How to setup multiple base station under one network? I have 6 rooms but one airport base station makes really difficult to get good signal from every rooms. I wonder if I can setup multiple airport base stations talking to each other under the same network to build up the signal strength will help solve this problem. But, is it possible? How?

    One route would be to utilize a "roaming" network. In a roaming network, you would connect multiple AirPort Extreme Base Stations (AEBS) to the same Ethernet. Of course, this would require that your home is already wired for Ethernet.

  • How to setup multi DNS server resolution

    I have a peculiar situation which I think may be applicable to others. I take my Macbook Pro to work. At work I have a Ethernet based LAN connection and a wireless connection.
    The ethernet connection gets me access to company servers, but uses some crude proxies and limits what I can access on the net.
    The wireless was setup by a tech to get around this and has a direct connection to the net, but no access to the company servers.
    The best situation I have currently is to put the wireless connection first in the network setting sand use that unless I need a company server. Then I have to turn wireless off before accessing the server and turn it back on to access anything I cannot get through the company LAN.
    I've been looking into configuring the Mac to enable me to have both on all the time. I've found that if I execute
    route add 161.117.0.0/16 -inteface en0
    Then any company server name I have already resolved will correctly route out through the eithernet rather than the wireless which solves the first part of the puzzle.
    I've also tried to setup multiple DNS resolution by adding a /etc/resolvers/company.com.au file with the contents:
    nameserver 161.117.219.153
    nameserver 161.117.248.113
    search company.com.au
    search_order 1
    I've then checked this with scutil --dns which shows
    DNS configuration
    resolver #1
      search domain[0] : Wireless
      nameserver[0] : 10.0.0.138
    resolver #9
      domain   : company.com.au
      search domain[0] : company.com.au
      nameserver[0] : 161.117.219.153
      nameserver[1] : 161.117.248.113
      order    : 1
    DNS configuration (for scoped queries)
    resolver #1
      search domain[0] : Wireless
      nameserver[0] : 10.0.0.138
      if_index : 5 (en1)
      flags    : Scoped
    resolver #2
      search domain[0] : company.com.au
      nameserver[0] : 161.117.219.153
      nameserver[1] : 161.117.248.113
      if_index : 4 (en0)
      flags    : Scoped
    But I still cannot get DNS resolution working for the company servers. Dig is no help because it's doco says that it only uses the /etc/resolv.conf file. Unfortunately documentation on setting up multi DNS resolution is practically nil and I've not been able to find any examples on the net. Just a few postings saying to use /etc/resolvers and very little doco in man pages.
    Has anyone else managed to get this working?

    Following blogposts will get you started:
    Automatic Provisioning of a Virtual BizTalk Environment
    http://blog.codit.eu/post/2013/06/07/Windows-Azure-IaaS-%E2%80%93-Automatic-provisioning-of-a-virtual-BizTalk-environment.aspx
    One Click BizTalk Multi Server Environment Azure Provisioning
    http://blog.brauwers.nl/2013/07/23/one-click-biztalk-multi-server-environment-azure-provisioning-and-full-configuration/
    Build an Azure IAAS Biztalk Single Server or Domain
    http://www.biztalkgurus.com/biztalk_server/biztalk_blogs/b/biztalk/archive/2014/06/12/build-an-azure-iaas-biztalk-single-server-or-domain-win-100-or-other-great-prizes.aspx
    Glenn Colpaert - MCTS BizTalk Server - Blog : http://blog.codit.eu

  • How to combine multiple Unmanaged Solution to one single Managed solution

    Hi,
    How to combine multiple Unmanaged Solution to one single Managed solution.?
    There were some other third party developer have kept things lik ein UAT there are 2 release solution and both are Managed Solution.
    And in Production the changes are only deployed for release 1 and for the release 2 changes deployment needs to be done.
    But when i import that second release Managed Solution from UAT to Production then i got number of elements missing but i have checked they are already there in Soolution.
    I did some R&D on this but not much helpful.
    I thought i require to convert Unmanaged Solution of Production environment to Managed first for first release and then needs to import Managed solution of UAT to Production for second release.
    Is this the right way to overcome form this situation?
    Any help and response would be really appreciated.
    Thanks.
    If this post answers your question, please click "Mark As Answer" on the post and "Mark as Helpful"

    Hi, 
    You can prepare unmanaged solution by adding all the components from the default solution,which are there in the managed solution, If Customizatiable entity is true in  the managed solution.

  • How to include multiple image components into a single custom component???

    How to include multiple image components into a single custom component???

    Hi Marcel,
    an ABAP transaction can only run or at least be started on one single system. A portal transaction can be assigned using a URL. This doesn't need any logical component.
    Regards
    Andreas

  • Multiple SOA clusters within a Single Domain

    Hi All,
    We're looking at a scenario where there would be multiple SOA clusters within a single domain. Would that be possible to do? I mean I can create multiple SOA clusters but it seems that applications deployed to one of the 2 SOA clusters seem to go into an inconsistent state. Please advise. Thank you.

    This is just because all SOA servers in a domain will refer to one(same) SOAINFRA schema for SOA deployments info and hence belong to same logical group (cluster) and that's the reason why you cann't even have two separate SOA managed servers without a cluster.
    Regards,
    Anuj

  • Create multiple SOA Clusters in a single domain?

    Is it allowed to create multiple SOA Clusters in a single domain with both SOA Clusters sharing the same soa-infra schema but deploying different composites?
    Create a domain with
    - Admin server (AdminServer)
    - SOA_Cluster1
    -soa_server1
    -soa_server2
    - SOA_Cluster2
    -soa_server3
    -soa_server4
    SOA_Cluster1 will need to deploy servcies A, B and C and SOA_Cluster2 will have services A, D and E. Is there any documentation which can help us with this?

    Thanks for the document link but it seems that the document was created only yesterday. Can you elaborate on "only one set of SOA schemas is allowed per SOA domain/cluster". I was able to build another SOA cluster_2 to my existing domain with SOA_cluster1 pretty successfully. The only problem was the internal JMS queues were configured as Uniform Distributed. hence i was not able to point them to 2 clusters.

  • Hosting Multiple DNS Zones on different servers How To?

    Hello, I have an issue that I would like one of the experts to help out with.
    I am currently facing an issue with DNS. I currently need to be able to ping certain machines on my internal domain by their external IP address.
    Example: machineA.domain.local has IP address 192.168.1.10 but from the inside of my network I would need to be able to ping machineA.domain.local and have it resolve to my EXTERNAL IP ADDRESS.
    Now as far as I know using a split DNS would solve this issue. Herein lies my issue.
    My DNS works half the time. Sometimes I will ping machineA.domain.local and it will resolve the internal address and sometimes it would resolve the public IP address (which I set manually in my split DNS)
    Now, my reasoning for this is because there are multiple entries with the same machine name on the same domain controller that resolve to different IP addresses. So when I ping machineA.domain.local the reply will be a "confused" reply.
    Here is what I tried to do to correct the issue. I created another Windows Server 2008 R2 machine with only the DNS role installed. I then removed the split DNS from my domain controller and added the zone "zone.domain.com" with the A record "machineA.domain.com"
    I did not join the domain with the new machine as I did not believe it to be necessary.
    The machines on the inside still cannot ping "machineA.domain.com", nor can my new server successfully ping "machineA.domain.local". It can resolve "machineA.domain.com" but I am fairly certain this is because I added it in
    the DNS zone.
    I tried to go a little further and tried to connect to the domain controller DNS via the MMC snap in on my new server. I get an error telling me that the access is denied.
    In order to attempt to fix that I added the computer in the properties of the DNS in the security tab. I also added the newly created server to the DNS admins group.
    Nothing works I am not sure what I am doing incorrect but I would need to know how I can do the following
    A) Successfully (if possible) have 2 different zones on the same domain
    example: internal.domain.local and external.domain.com
    I would need to know how to be able to successfully ping the machines I need to ping that resolves to  the external IP address from the inside without having the internal A record in the DNS zone interfere.
    I would also need to know how I could connect to the domain controllers DNS via another computer (the new server) without having the access is denied error.
    Once again, I tried to use a split DNS on the same server which yielded mixed results. I cannot have the machines replying randomly or go down because 2 DNS zones are on the same machine.
    Thank you hope to get an answer ASAP!

    Anyone have any ideas on this?

  • How do setup multiple send and receive domain on single virtual ironport?

    HI all
    how do i setup multiple send and receive domain on single virtual ironport?
    Daemien

    Please use the admin guide to assist you for setup/configuration:
    http://www.cisco.com/c/dam/en/us/td/docs/security/esa/esa8-0/user_guide/ESA_8-0-1_User_Guide.pdf
    On the VESA - the Recipient Access Table (RAT) will control which domains your appliance accepts for.  
    AsyncOS uses a Recipient Access Table (RAT) for each public listener to manage accept and reject actions for recipient addresses. Recipent addresses include these:
    •Domains
    •Email addresses
    •Groups of email addresses
    This is covered in detail in the "Overview of Accepting or Rejecting Connections Based on the Recipient’s Address" section.
    Please see the "Configuring the Gateway to Receive Email" section for configuration of appliance for domains.
    Please see the "Defining Which Hosts Are Allowed to Connect Using the Host Access Table (HAT)" section for configuration of appliance for sending.
    I hope this helps!
    -Robert
    (*If you have received the answer to your original question, and found this helpful/correct - please mark the question as answered, and be sure to leave a rating to reflect!)

  • How to setup multiple Apple ID's on Apple TV home sharing?

    I have an Apple TV and a Mac with mavericks.. My roommate also has a Mac. We both want to be able to access our home sharing videos on the Apple TV. I figured out how to have multiple accounts for iTunes (rentals etc) but can't seem to do it with home sharing? Anyone out there know if it is possible? I don't like to use mirroring because it can be slow when watching movies.
    Thanks!

    Thanks for your help! I don't mind switching between them.. How do I authorize both on the home sharing ID? When my roommate goes to "computers" it tells her to turn on home sharing on my computer (with my ID).. Even if I changed the iTunes account over to hers..
    Thanks again!

  • How to setup multiple Exchange accounts in Mail with the same username/password

    Okay didn't see a place to ask a Mail question so I am placing this here.
    I work for a helpdesk that requires me to monitor 4 different email accounts throughout the day. They are all Exchange accounts. The first one setups just fine but when I go to setup the others I get a message that states that the username and password are in use for the other account. Is there any way to setup multiple Exchange account when using the same LDAP creds for all the accounts?

    Csound1,
    I need to add a second Exchange account to my MBP using Mail.  Both accounts are with Rackspace, but each email address is unique (i.e., two different domain names).  When I use Preferences to attempt to add the second account, it recognizes the new credentials, finds the server and autopopulates the necessary address information.  But, as soon as I click "Done" after setting which functions are active on the account (mail, cal, contacts, etc.), the screen shows only my original Exchange account.  The new one is not added, yet there is no error message saying that it can't be added.  Any idea what is going on?  Shouldn't Mail be able to have multiple Exchange accounts, even if they are hosted via the same Rackspace server (in this case: connect.emailsrvr.com)?
    Many thanks,
    Wally
    MBPR with Mavericks, Exchange 2012, Mac Mail

  • How to add multiple passbooks cards to a single mail

    im trying to add multiple passbook cards to a single mail on iphone
    how can i do that....
    the upload or share tab in passbook card only allows one card at a time on my iphone...
    pls help...

    its still not happening
    i did that way and pasted all multiple passbook cards in a single message
    then i copied all and pasted it in mail...
    its coming as attachment .pk in mail body but no attachment is there ...
    so the receiver of the mail is not able to get the picture of the passbook card...
    its not working...

  • How to provision multiple AD Accounts to a single User Profile in OIM

    Hi,
    We are using OIM 11g R2. We have implemented AD Provisioning/Reconciliation using Active Directory 11g Connector.
    The correlation rule for linking AD accounts with OIM during target recon is set as “Email ID”
    We have some business requirement where we want to provision multiple AD Accounts to a single User Profile in OIM.
    Issue we are facing:
    Suppose we have USERID1 in OIM which has email id as USERID1@ XYZ.COM .
    After that we have provisioned sAMAccountName=USERID1 (Email ID as USERID1@ XYZ.COM )& sAMAccountName=USERID2 (Email ID as [email protected]) to the user User Login = USERID1 in OIM.
    Both the AD User accounts can be seen as provisioned.
    After we run the AD Target Recon, the target recon is failing because of “Multiple Process Matches Found” issue.
    Question here is:
    Is it possible to maintain/manage multiple AD Accounts (Same AD is used for all the multiple AD Accounts) to a single OIM profile user ?
    Regards,
    J

    Hi,
    We have seen its working and linking multiple accounts when we have Key field as "User ID" in the Process Defn & RO and the recon matching rule has email ID as the matching rule.
    Please suggest, if we are having the above kind of rule/config...will it not cause any issue?
    Regards,
    J

  • How to view multiple files' info in a single window

    I remember I can view multiple files' info in a single window before, but now I have to viewed multiple files' info in each their own window. It's very inconvenient to me, I want to get a solution to resolve it. Please do me favor, Many Thanks!
    Message was edited by: 5imacintosh

    Select them and press the Option, Command, and I keys at once. The resulting window will change its content based on the selection.
    (45010)

  • Multiple EAR files in one single domain ?

    can i deploy multiple EAR files in single domain
    thanks,
    KM

    I'm not sure what a "domain" is in this context. I suppose it depends on the J2EE server you're using. Weblogic has something called a "domain", and sure in that server you can deploy multiple EARs in one domain, and there can be multiple domains.

Maybe you are looking for

  • To import photos from Iphone to mac is a strange thing.

    There are different ways to import the Iphone pictures to the mac but the result is a strange thing. 1. way over the osx tool digital pictures. result with osx Lion 1.1 GB (with the osx Lion it is 3.8 GB with the same Iphone and pictures) 2. way with

  • The Artists in my Itunes are ordered incorrectly, Completely!

    Hi, My itunes library has gone slightly strange. The artists order has changed, it seems that they are now being ordered by artist surname for some of them, but there are some that are completley out of order. Patrick Wolf for instance, comes at the

  • Error using Interop

    Hi, I need to use an Interop DLL in my C# web application. I have successfully registered the managed DLL using regsvr32 and the generated COM Interop DLL using regasm. The CLSID is available under WOW6432 in the registry. But when I run the applicat

  • Toshiba SM30-604, Windows XP Service Pack 2 problems

    I installed Service Pack 2 on my Toshiba SM30-604. But after that it can't startup whitout a electrical cable connected to it, so whenever I want to startup I need to sit close to a wall connector. I've already search for a update on the site but I c

  • BC4J with other API using JClient

    hi i like to know whether new APIs can be binded with BC4J componets or not. now i am using JClient and its API to bind with BC4j components. but i like to use new API in jclient to bind with BC4j componets. or bindind the new APIS directly in to BC4