Site icon WinCert

Remove Root Hints in DNS server

<p><a href&equals;"http&colon;&sol;&sol;wincert&period;net&sol;wp-content&sol;uploads&sol;2015&sol;01&sol;windows-server&period;jpg"><img class&equals;"alignnone size-full wp-image-550" src&equals;"http&colon;&sol;&sol;wincert&period;net&sol;wp-content&sol;uploads&sol;2015&sol;01&sol;windows-server&period;jpg" alt&equals;"Windows Server" width&equals;"720" height&equals;"340" &sol;><&sol;a><&sol;p>&NewLine;<p>Our new domain is behind a firewall and once we setup the DNS server we got a lot of DNS domain-udp requests to Root servers that could not be contacted because of our corporate firewall policy&period;<&sol;p>&NewLine;<p>If you want to ensure that your DNS server does not use Root Hints&comma; you should do the following&colon;<&sol;p>&NewLine;<p>Open <strong>DNS Server Manager<&sol;strong> &vert; Expand <strong>DNS Server <&sol;strong>&vert; Expand <strong>Forward Lookup Zones<&sol;strong> &vert; Right Click on <strong>Forward Lookup Zones<&sol;strong> and select <strong>New Zone<&sol;strong> &vert; <strong>Primary Zone &vert; Zone Name&colon; &&num;8220&semi;&period;&&num;8221&semi;<&sol;strong> &lpar;only dot&comma; without quotation marks&rpar; <&excl;--more--><&sol;p>&NewLine;<p>One action that I have done in the past to ensure that the DNS server does not use the &&num;8220&semi;Root Hints&&num;8221&semi; is to create a foward lookup zone called &&num;8220&semi;&period;&&num;8221&semi;<&sol;p>&NewLine;<p>When you create such a zone&comma; you are configuring the DNS server to be the ultimate authority for the DNS namespace&period; The DNS server will no longer attempt to forward any DNS requests that it is not authoritative for&period;<&sol;p>&NewLine;<p>You can also remove <strong>Root Hints<&sol;strong> for a DNS Server but that is not recommended or supported by Microsoft&period;<&sol;p>&NewLine;<p>Note that once you remove the last root hint while you have the &period;root zone created&comma; you won&&num;8217&semi;t be able to add any additional root hints&period;<&sol;p>&NewLine;

Exit mobile version