Добрый день уважаемые!
Хочу реализовать полноценную систему Active Diurectory, с одним "но": Чтобы под Windows была лишь сама схема AD, а все остальное (DHCP,DNS,Proxy,Mail,Samba) крутилось на *NIX (В моем случае FreeBSD 6.2 x86) и было полностью игтегрировано с AD.
Начал с установки AD и поднятия DNS в BIND 9.3.3.
//******************************************************************************
/etc/namedb/named.conf
options {
directory "/etc/namedb";
pid-file "/var/run/named/named.pid";
dump-file "/var/dump/named_dump.db";
statistics-file "/var/stats/named.stats";
listen-on {192.168.0.1; 127.0.0.1; };
};
zone "." {
type hint;
file "named.root";
};
zone "0.0.127.IN-ADDR.ARPA" {
type master;
file "master/localhost.rev";
};
zone "test.loc" {
type master;
file "master/db.test.loc";
allow-update {192.168.0.1; 127.0.0.1; };
};
zone "1.0.0.0.0.0.0.........0.IP6.ARPA" {
type master;
file "master/localhost-v6.rev";
};
//******************************************************************************
/etc/namedb/master/db.test.loc
$TTL 3600
@ IN SOA TEST-FreeBSD.test.loc. dnsmaster.TEST-FreeBSD.test.loc. (
20030430
3600
900
3600000
3600)
@ IN NS TEST-FreeBSD.test.loc
localhost IN NS 127.0.0.1
@ IN NS 127.0.0.1
www IN CNAME @
//******************************************************************************
При запуске named никаких ошибок, в messages тоже.
На Win2003 указал в качестве DNS сервера 192.168.0.1 (TEST-FreeBSD). Адрес самого Win2003 192.168.0.100
Active Directory поднялась, но вот при загрузке в системном логе появляются 2 записи:
Event Type: Warning
Event Source: DnsApi
Event Category: None
Event ID: 11165
Date: 3/6/2007
Time: 4:11:21 AM
User: N/A
Computer: TEST-SERV
Description:
The system failed to register host (A) resource records (RRs) for network adapter
with settings:
Adapter Name : {8CC55A0D-FE32-43B2-BF93-AD60A0731EF9}
Host Name : test-serv
Primary Domain Suffix : test.loc
DNS server list :
192.168.0.1
Sent update to server : <?>
IP Address(es) :
192.168.0.100
The reason the system could not register these RRs was because the DNS server contacted refused the update request. The reasons for this might be (a) you are not allowed to update the specified DNS domain name, or (b) because the DNS server authoritative for this name does not support the DNS dynamic update protocol.
To register the DNS host (A) resource records using the specific DNS domain name and IP addresses for this adapter, contact your DNS server or network systems administrator.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 2a 23 00 00 *#..
Event Type: Warning
Event Source: NETLOGON
Event Category: None
Event ID: 5781
Date: 3/6/2007
Time: 4:16:15 AM
User: N/A
Computer: TEST-SERV
Description:
Dynamic registration or deletion of one or more DNS records associated with DNS domain 'test.loc.' failed. These records are used by other computers to locate this server as a domain controller (if the specified domain is an Active Directory domain) or as an LDAP server (if the specified domain is an application partition).
Possible causes of failure include:
- TCP/IP properties of the network connections of this computer contain wrong IP address(es) of the preferred and alternate DNS servers
- Specified preferred and alternate DNS servers are not running
- DNS server(s) primary for the records to be registered is not running
- Preferred or alternate DNS servers are configured with wrong root hints
- Parent DNS zone contains incorrect delegation to the child zone authoritative for the DNS records that failed registration
USER ACTION
Fix possible misconfiguration(s) specified above and initiate registration or deletion of the DNS records by running 'nltest.exe /dsregdns' from the command prompt or by restarting Net Logon service. Nltest.exe is available in the Microsoft Windows Server Resource Kit CD.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 2a 23 00 00 *#..
Я так из описания понял, что Win2003 не может занести запись свою в DNS. Как ему в этом помочь?