Dynamic Updates The General tab also allows you to configure a zone with dynamic
updates in resource records. As shown in Figure 5-18, three dynamic update settings
are available for Active Directory–integrated DNS zones: None, Nonsecure And Secure,
and Secure Only. For standard zones, only two settings are available: None and Non-secure
And Secure.
When you select the None setting in the properties for a zone, you must manually perform
registrations and updates to zone records. However, when you enable either the
Nonsecure And Secure setting or the Secure Only setting, client computers can automatically
create or update their own resource records. This functionality greatly
reduces the need for manual administration of zone records, especially for DHCP clients
and roaming clients.
Secure Dynamic Updates and the DnsUpdateProxy group
When only secure dynamic updates are allowed in a zone, only the owner of a
record can update that record. (The owner of a record is the computer that originally
registers the record.) This restriction can cause problems in situations where
a DHCP server is being used to register host (A) resource records on behalf of client
computers that cannot perform dynamic updates. In such cases, the DHCP
server becomes the owner of the record, not the computers themselves. If the
downlevel client computer is later upgraded to Windows 2000 or some other
operating system that is capable of performing dynamic updates, the computer
will not be recognized as the owner and will consequently be unable to update its
own records. A similar problem might arise if a DHCP server fails that has registered
records on behalf of downlevel clients: none of the clients will be able to
have their records updated by a backup DHCP server.
To avoid such problems, add to the DnsUpdateProxy security group DHCP servers
that register records on behalf of other computers. Members of this group are prevented
from recording ownership on the resource records they update in DNS.
This procedure consequently loosens security for these records until they can be
registered by the real owner.