Resolving external address when Active Directory Domain ends in .comWindows Active Directory naming best practices?Resolving DNS issues in an Active Directory Domain ending in .com instead of .localFind name of Active Directory domain controllerResolving DNS issues in an Active Directory Domain ending in .com instead of .localWhat is Active Directory Domain Services and how does it work?Active Directory DNS not resolving ANY queriesApex ANAME / ALIAS record in Windows Server 2012 R2 DNS ManagerSender address rejected: Domain not found - after Route 53 (Amazon AWS) changesIn windows server dns, how can I delegate example.com to an external name server?IP Address vs Name ServerWindows DNS with a pseudo secondary zonePublic DNS conflicts with Networks internal DNS
60s/70s science fiction novel where a man (after years of trying) finally succeeds to make a coin levitate by sheer concentration
Something that can be activated/enabled
My advisor talks about me to his colleague
I need a disease
What does this wavy downward arrow preceding a piano chord mean?
Should I decline this job offer that requires relocating to an area with high cost of living?
Pressure inside an infinite ocean?
Find the cheapest shipping option based on item weight
Where are the "shires" in the UK?
Can there be a single technologically advanced nation, in a continent full of non-technologically advanced nations?
Is there an idiom that support the idea that "inflation is bad"?
Why did the Apollo 13 crew extend the LM landing gear?
Why are UK Bank Holidays on Mondays?
Identifying characters
Does it make sense for a function to return an rvalue reference?
Appropriate certificate to ask for a fibre installation (ANSI/TIA-568.3-D?)
Proving n+1 th differential as zero given lower differentials are 0
Decoupling cap routing on a 4 layer PCB
Why aren't nationalizations in Russia described as socialist?
29er Road Tire?
Shutter speed -vs- effective image stabilisation
What is the solution to this metapuzzle from a university puzzling column?
Manager is threatening to grade me poorly if I don't complete the project
Nominativ or Akkusativ
Resolving external address when Active Directory Domain ends in .com
Windows Active Directory naming best practices?Resolving DNS issues in an Active Directory Domain ending in .com instead of .localFind name of Active Directory domain controllerResolving DNS issues in an Active Directory Domain ending in .com instead of .localWhat is Active Directory Domain Services and how does it work?Active Directory DNS not resolving ANY queriesApex ANAME / ALIAS record in Windows Server 2012 R2 DNS ManagerSender address rejected: Domain not found - after Route 53 (Amazon AWS) changesIn windows server dns, how can I delegate example.com to an external name server?IP Address vs Name ServerWindows DNS with a pseudo secondary zonePublic DNS conflicts with Networks internal DNS
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;
Prior IT support named a customer's Windows 2016 AD domain example.com instead of example.local, as I've always done it. The customer has an external Apache web server hosting www.example.com.
When a user browses to http://example.com or http://www.example.com it fails because that resolves to the server's LAN IP address.
How can I ensure that users can reach the external company web server?
(Different issue: Resolving DNS issues in an Active Directory Domain ending in .com instead of .local)
domain-name-system active-directory windows-server-2016
add a comment |
Prior IT support named a customer's Windows 2016 AD domain example.com instead of example.local, as I've always done it. The customer has an external Apache web server hosting www.example.com.
When a user browses to http://example.com or http://www.example.com it fails because that resolves to the server's LAN IP address.
How can I ensure that users can reach the external company web server?
(Different issue: Resolving DNS issues in an Active Directory Domain ending in .com instead of .local)
domain-name-system active-directory windows-server-2016
2
Please don't use .local - See serverfault.com/q/76715
– HBruijn
Apr 25 at 7:16
Perhaps Split-Brain DNS might apply to your situation. docs.microsoft.com/en-us/windows-server/networking/dns/deploy/…
– twconnell
Apr 25 at 18:15
add a comment |
Prior IT support named a customer's Windows 2016 AD domain example.com instead of example.local, as I've always done it. The customer has an external Apache web server hosting www.example.com.
When a user browses to http://example.com or http://www.example.com it fails because that resolves to the server's LAN IP address.
How can I ensure that users can reach the external company web server?
(Different issue: Resolving DNS issues in an Active Directory Domain ending in .com instead of .local)
domain-name-system active-directory windows-server-2016
Prior IT support named a customer's Windows 2016 AD domain example.com instead of example.local, as I've always done it. The customer has an external Apache web server hosting www.example.com.
When a user browses to http://example.com or http://www.example.com it fails because that resolves to the server's LAN IP address.
How can I ensure that users can reach the external company web server?
(Different issue: Resolving DNS issues in an Active Directory Domain ending in .com instead of .local)
domain-name-system active-directory windows-server-2016
domain-name-system active-directory windows-server-2016
asked Apr 25 at 6:11
jbbarnesjbbarnes
162
162
2
Please don't use .local - See serverfault.com/q/76715
– HBruijn
Apr 25 at 7:16
Perhaps Split-Brain DNS might apply to your situation. docs.microsoft.com/en-us/windows-server/networking/dns/deploy/…
– twconnell
Apr 25 at 18:15
add a comment |
2
Please don't use .local - See serverfault.com/q/76715
– HBruijn
Apr 25 at 7:16
Perhaps Split-Brain DNS might apply to your situation. docs.microsoft.com/en-us/windows-server/networking/dns/deploy/…
– twconnell
Apr 25 at 18:15
2
2
Please don't use .local - See serverfault.com/q/76715
– HBruijn
Apr 25 at 7:16
Please don't use .local - See serverfault.com/q/76715
– HBruijn
Apr 25 at 7:16
Perhaps Split-Brain DNS might apply to your situation. docs.microsoft.com/en-us/windows-server/networking/dns/deploy/…
– twconnell
Apr 25 at 18:15
Perhaps Split-Brain DNS might apply to your situation. docs.microsoft.com/en-us/windows-server/networking/dns/deploy/…
– twconnell
Apr 25 at 18:15
add a comment |
1 Answer
1
active
oldest
votes
So using .com instead of .local is perfectly fine, preferable even. I would be running AD from a namespace like ad.company.com instead of the root to avoid issues like this, but overall, using a real TLD that you own is best practice for AD.
The only issue here is that the internal and external namespace are shared. You can get around the website issue by having iis on the DCs acting as a forward/reverse proxy to the external website. Suggesting putting that role onto a DC actually makes me feel queasy but it should work.
add a comment |
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f964517%2fresolving-external-address-when-active-directory-domain-ends-in-com%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
So using .com instead of .local is perfectly fine, preferable even. I would be running AD from a namespace like ad.company.com instead of the root to avoid issues like this, but overall, using a real TLD that you own is best practice for AD.
The only issue here is that the internal and external namespace are shared. You can get around the website issue by having iis on the DCs acting as a forward/reverse proxy to the external website. Suggesting putting that role onto a DC actually makes me feel queasy but it should work.
add a comment |
So using .com instead of .local is perfectly fine, preferable even. I would be running AD from a namespace like ad.company.com instead of the root to avoid issues like this, but overall, using a real TLD that you own is best practice for AD.
The only issue here is that the internal and external namespace are shared. You can get around the website issue by having iis on the DCs acting as a forward/reverse proxy to the external website. Suggesting putting that role onto a DC actually makes me feel queasy but it should work.
add a comment |
So using .com instead of .local is perfectly fine, preferable even. I would be running AD from a namespace like ad.company.com instead of the root to avoid issues like this, but overall, using a real TLD that you own is best practice for AD.
The only issue here is that the internal and external namespace are shared. You can get around the website issue by having iis on the DCs acting as a forward/reverse proxy to the external website. Suggesting putting that role onto a DC actually makes me feel queasy but it should work.
So using .com instead of .local is perfectly fine, preferable even. I would be running AD from a namespace like ad.company.com instead of the root to avoid issues like this, but overall, using a real TLD that you own is best practice for AD.
The only issue here is that the internal and external namespace are shared. You can get around the website issue by having iis on the DCs acting as a forward/reverse proxy to the external website. Suggesting putting that role onto a DC actually makes me feel queasy but it should work.
edited Apr 25 at 13:55
answered Apr 25 at 6:49
Rob MoirRob Moir
29.7k45183
29.7k45183
add a comment |
add a comment |
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f964517%2fresolving-external-address-when-active-directory-domain-ends-in-com%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
2
Please don't use .local - See serverfault.com/q/76715
– HBruijn
Apr 25 at 7:16
Perhaps Split-Brain DNS might apply to your situation. docs.microsoft.com/en-us/windows-server/networking/dns/deploy/…
– twconnell
Apr 25 at 18:15