整合現有的 DNS 基礎結構 AD DSIntegrating AD DS into an Existing DNS Infrastructure

適用於:Windows Server 2016、Windows Server 2012 R2、Windows Server 2012Applies To: Windows Server 2016, Windows Server 2012 R2, Windows Server 2012

如果您的組織已經有現有的網域名稱系統 」 (DNS) 伺服器服務,Active Directory Domain Services (AD DS) 擁有者 DNS 必須使用 DNS 擁有者為您的組織 AD DS 整合現有的基礎結構。If your organization already has an existing Domain Name System (DNS) Server service, the DNS for Active Directory Domain Services (AD DS) owner must work with the DNS owner for your organization to integrate AD DS into the existing infrastructure. 這牽涉到建立 DNS client 設定和 DNS 伺服器。This involves creating a DNS server and DNS client configuration.

建立 DNS 伺服器設定Creating a DNS server configuration

當使用現有的 DNS 命名空間整合 AD DS,我們建議您下列動作:When integrating AD DS with an existing DNS namespace, we recommend that you do the following:

  • 森林中的每個網域控制站上安裝的 DNS 伺服器服務。Install the DNS Server service on every domain controller in the forest. 如果無法使用其中一個 DNS 伺服器,如此容錯。This provides fault tolerance if one of the DNS servers is unavailable. 如此一來,不需要網域控制站依賴的名稱解析其他 DNS 伺服器。In this way, domain controllers do not need to rely on other DNS servers for name resolution. 這也會簡化管理環境因為所有網域控制站統一設定。This also simplifies the management environment because all domain controllers have a uniform configuration.

  • 設定 Active Directory 森林根網域控制站管理 Active Directory 樹系 DNS 區域。Configure the Active Directory forest root domain controller to host the DNS zone for the Active Directory forest.

  • 設定為每個地區網域裝載對應至 Active Directory 網域 DNS 區域的網域控制站。Configure the domain controllers for each regional domain to host the DNS zones that correspond to their Active Directory domains.

  • 設定含有 Active Directory 樹系定位器記錄區域 (也就是 _msdcs。forestname區域) 來使用樹系 DNS 應用程式 directory 磁碟分割複寫森林中的每個 DNS 伺服器。Configure the zone containing the Active Directory forest-wide locator records (that is, the _msdcs.forestname zone) to replicate to every DNS server in the forest by using the forest-wide DNS application directory partition.

    注意

    DNS 伺服器服務的 Active Directory Domain Services 安裝精靈 (我們建議使用此選項) 安裝時,會自動執行所有先前的工作。When the DNS Server service is installed with the Active Directory Domain Services Installation Wizard (we recommend this option), all the previous tasks are performed automatically. 如需詳細資訊,請查看部署 Windows Server 2008 森林根網域For more information, see Deploying a Windows Server 2008 Forest Root Domain.

    注意

    AD DS 使用樹系定位記錄讓複寫合作夥伴尋找彼此以及讓戶端找不到通用伺服器。AD DS uses forest-wide locator records to enable replication partners to find each other and to enable clients to find global catalog servers. AD DS 儲存的樹系定位器記錄 _msdcs。forestname區域。AD DS stores the forest-wide locator records in the _msdcs.forestname zone. 必須廣泛提供區域中的資訊,因為此區域的樹系 DNS 應用程式 directory 磁碟分割透過會複寫森林中的所有 DNS 伺服器。Because the information in the zone must be widely available, this zone is replicated to all DNS servers in the forest by means of the forest-wide DNS application directory partition.

現有的 DNS 結構會保持不變。The existing DNS structure remains intact. 您不需要的任何伺服器或區域移動。You do not need to move any servers or zones. 您只需要從您現有的 DNS 階層 Active Directory 整合 DNS 區域建立委派。You simply need to create a delegation to your Active Directory-integrated DNS zones from your existing DNS hierarchy.

建立 DNS client 設定Creating the DNS client configuration

若要設定 DNS client 電腦上,AD DS 擁有者 DNS 必須指定命名配置和戶端如何找出 DNS 伺服器的電腦。To configure DNS on client computers, the DNS for AD DS owner must specify the computer naming scheme and how the clients will locate DNS servers. 下表列出我們建議的設定的設計的這些項目。The following table lists our recommended configurations for these design elements.

設計的項目Design element 設定Configuration
電腦命名Computer naming 使用預設命名。Use default naming. 當 Windows 2000、 Windows XP、 Windows Server 2003 時、 Windows Server 2008 或 Windows vista 的電腦加入網域,電腦指派本身組成主機名稱電腦的完整的網域名稱 (FQDN) 和 Active Directory 網域名稱。When a Windows 2000, Windows XP, Windows Server 2003, Windows Server 2008 , or Windows Vista-based computer joins a domain, the computer assigns itself a fully qualified domain name (FQDN) that comprises the host name of the computer and the name of the Active Directory domain.
Client 解析程式設定Client resolver configuration 設定 client 電腦指向任何網路上的 DNS 伺服器。Configure client computers to point to any DNS server on the network.

注意

Active Directory 戶端和網域控制站可以動態登記他們的 DNS 名稱即使您並未指向 DNS 伺服器其名稱的授權。Active Directory clients and domain controllers can dynamically register their DNS names even if they are not pointing to the DNS server that is authoritative for their names.

如果組織之前,靜態登記電腦 DNS 或組織是否先前部署整合動態主機設定通訊協定 」 (DHCP) 方案電腦可能有不同的現有 DNS 名稱。A computer might have a different existing DNS name if the organization previously, statically registered the computer in DNS or if the organization previously deployed an integrated Dynamic Host Configuration Protocol (DHCP) solution. 如果 client 電腦已經且已的 DNS 名稱,當他們加入的網域升級到 Windows Server 2008 AD DS,它們將會有兩個不同的名稱:If your client computers already have a registered DNS name, when the domain to which they are joined is upgraded to Windows Server 2008 AD DS, they will have two different names:

  • 現有的 DNS 名稱The existing DNS name

  • 新的完整的網域名稱 (FQDN)The new fully qualified domain name (FQDN)

仍然可以找到戶端由任一名稱。Clients can still be located by either name. 任何的現有 DNS、 DHCP 或整合的 DNS 日 DHCP 方案保留。Any existing DNS, DHCP, or integrated DNS/DHCP solution is left intact. 新的主要名稱會自動建立和更新透過動態更新。The new primary names are created automatically and updated by means of dynamic update. 他們會自動清除透過清除。They are cleaned up automatically by means of scavenging.

如果您想要利用 F:kerberos 驗證時連接到執行 Windows 2000、 Windows Server 2003 或 Windows Server 2008 的伺服器,您必須確定 client 連接到伺服器使用主要名稱。If you want to take advantage of Kerberos authentication when connecting to a server running Windows 2000, Windows Server 2003, or Windows Server 2008 , you must make sure that the client connects to the server by using the primary name.