Once you have your first domain contoller in the forest setup, ensuring that the NIC's DNS points to itself, AD integrated zones match the AD name, and the svc directories are in DNS, what do you do for the other domain controllers in the same containter for the first forest domain contoller. Do you setup a DNS server with AD zones on those too and point the network DNS configuration for the NIC to itself as well? Or do you not install DNS and just point the NICs DNS entry to the first domain contoller. And if you do that, what if the first domain contollers goes down?
Then with child domains, do you setup DNS with AD integrated zones, and point the NIC's DNS to itself too with a helping forwarder to the first forest domain controller? Or do you just set the NICs DNS to the top forest domain contoller and do not install DNS.
Man, this gets confusing. I tried to set it up using Microsofts techweb pages and I found that the child domain could see all of the users in AD in both domains, but the top forest contoller could only manage itself. It could not find anything in the child domain. However, I could browse to it in explorer.exe from the forest DC.
Then with child domains, do you setup DNS with AD integrated zones, and point the NIC's DNS to itself too with a helping forwarder to the first forest domain controller? Or do you just set the NICs DNS to the top forest domain contoller and do not install DNS.
Man, this gets confusing. I tried to set it up using Microsofts techweb pages and I found that the child domain could see all of the users in AD in both domains, but the top forest contoller could only manage itself. It could not find anything in the child domain. However, I could browse to it in explorer.exe from the forest DC.
