DC and DNS method is not built on the same host (DNS do do first DC)

purpose:

① For DNS, you can understand SOA (Start of Authority) and NS (name server), respectively, what role
② For DC, understand the significance of SRV records exist

ready:

三台虚拟机,分别作为DNS服务器、DC服务器、客户端。
IP分配:
DNS服务器:192.168.22.1
DC服务器:192.168.22.2	首选DNS:192.168.22.1
客户端:192.168.22.3	首选DNS:192.168.22.1

DNS to build

1. Open the "Server Manager", click "Add Role"
Here Insert Picture Description
2. Click "Next"
Here Insert Picture Description3, check the "DNS Server" and click "Next"
Here Insert Picture Description4. Click "Next", click "Install"
Here Insert Picture DescriptionHere Insert Picture Description5. Installation success, click "Close"
Here Insert Picture Description6, open [start] - Administrative tools - DNS
Here Insert Picture Description7, right-click "forward lookup Zones", click on "New Zone", click "Next"
Here Insert Picture Description
8, select the "main area", click "Next"
Here Insert Picture Description
9, enter "zone name", click "Next" and click "Next"
Here Insert Picture DescriptionHere Insert Picture Description
10, be sure to select "Allow non-secure and secure dynamic updates"Click" Next ", click" Finish "
Here Insert Picture DescriptionHere Insert Picture Description
11, because he is the master server, so be designated as point man himself, so we have to build strip A (Host) record. Right-click the domain name, click on the" New Host A record " enter the "name" and "IP address", click "Add host"
Here Insert Picture Description
12, right-click the field to open the "properties"
Here Insert Picture Description
click "start of authority", the "main server" points to yourself, click on the "apply"
If you use the default DNS configuration, again with DC, the result will fail, so it is necessary to modify the DNS records SOA and NS records point to themselves.
SOA effect (start of authority): defines the region which name server is authoritative name server.
NS (name server) role: that the primary and secondary servers in the region authoritative server and SOA in the region specified.
Here Insert Picture Description
click on the "name server", click "Add"
Here Insert Picture Description
to add domain names and IP addresses that you create, click "OK" here, DNS-related modification is completed, you can install the DC.
Here Insert Picture Description

Creating DC server

1. Open the "Server Manager", click "Add role", click "Next"
Here Insert Picture Description2, check the "Domain Service", click on "Add Required Features"
Here Insert Picture Description3. Click "Next", click "Install"
Here Insert Picture DescriptionHere Insert Picture Description4, "Windows + R" to open the command line, enter "dcpromo", click "OK" open domain services installation Wizard
Here Insert Picture Description
click "Next"
Here Insert Picture Description
click "Next"
Here Insert Picture Descriptionselect "Create a new domain in a new forest", click "Next"
Here Insert Picture Descriptionenter DNS domain name was created, click Next
Here Insert Picture Description"forest functional level" and "domain functional level" must choose "Windows Server 2003", click "Next"
Here Insert Picture DescriptionHere Insert Picture Descriptionmust be hereRemove the DNS server option.Because the DNS has been created on another computer, and click Next, will pop up a warning box, click Yes to

Here Insert Picture DescriptionHere Insert Picture Description
Click Next, set a password for the service
Here Insert Picture DescriptionHere Insert Picture Descriptionclick "Next" until the installation is complete, restart the computer
Here Insert Picture DescriptionHere Insert Picture Description
after computer restart, refresh the DNS Manager, if you see a domain which added four new folder, installation is successful,
Here Insert Picture Description

Client Authentication

1, the client join the domain (Open Computer Properties, click Change settings, click Change, join the domain)
Here Insert Picture Descriptionto join the domain successfully and see the records in the DNS, the server creates success.

Note the question:

确定DC的IP地址,必须使用静态的IP
需要关闭防火墙
在DNS上创建的主域需要与DC上的域一样
DNS需要修改SOA记录和NS记录来指向自己
DC在搭建是一定不要勾选DNS服务

Guess you like

Origin blog.csdn.net/weixin_42569404/article/details/92799424