Reply

Active Directory DNS Migration steps to Infoblox

Member
Posts: 2
2900     0

Any expert here can help me verify below steps and provide some advise? 

 

 

Background

Customer have multiple branches, some locations have Infoblox and some doesn’t. They also have multiple ADDC and RODC in different locations.

 

Objective

Migrate all the domains/zones in ADDC into Infoblox. After successful migration, all AD will convert into secondary zone.

 

Migration Steps

  1. create an authoritative zone
  2. configure ACL to allow updates from AD DNS
  3. configure AD DNS integration and underscore (_) zone will create automatically
  4. login into AD server
  5. configure DNS and point to Infoblox
  6. restart DNS service
  7. net stop netlogon
  8. net start netlogon
  9. ipconfig /registerdns
  10. Infoblox will sync all the SRV zone records (_ldap, _kerberos)
  11. Configure allow zone transfer from AD DNS to Infoblox
  12. Initiate import zone in Infoblox to import static A record and dynamic records
  13. Delete all dynamic records (because it will import as static into Infoblox)

 

**Since the project is big, we will let AD DNS running as normal but the AD DNS server DNS setting will point to Infoblox as prefer DNS

 

Migration for branches that have Infoblox

  1. Through DHCP server, dynamic client DNS setting will point to Infoblox
  2. User will update the dynamic record directly to Infoblox
  3. However, there is many servers are using static setting which we will migrate slowly.
  4. In this case, servers DNS are pointing to AD DNS however the AD DNS is pointing to Infoblox as prefer DNS. ** will this causing issue to the servers to operate as normal?

 

Migration for branches that do not have Infoblox

  1. The AD in the branches will convert to secondary zones
  2. Infoblox will zones transfer to AD DNS
  3. Client DNS will still be pointing to local AD DNS
  4. As our research, DHCP client will update their dynamic record to grid master directly. Therefore, we need to open UDP & TCP 53 from branches network to Grid master

 

Thanks

Chew

Re: Active Directory DNS Migration steps to Infoblox

Techie
Posts: 5
2901     0

Hi Chew,

 

I've migrated multiple ADs to Infoblox-DNS just recently.

Mostly I concure with your steps, but did it that way:

1.) Enabled Zone-Transfer on the Windows-DNS

2.) Created an ACL with the DCs in that are allowed to update the zone

3.) Created a new authoritive zone on Infoblox (NIOS)

4.) Imported the Zone to Infoblox and did the same for all subzones like _msdcs....

5.) Set the DC to use the infoblox as dns

6.) executed "net stop netlogon && net start netlogon" - that triggers the verification / registration of the SRV-Records, etc.

7.) Checked the syslog on the Infoblox-DNS to see possible errors

8.) If everything's good, set the Windows-DNS to forward all queries to the Infoblox

9.) Did the same on all DCS (Writeable and Readable).

10.) As soon as all the DCs have been migrated I deleted the AD-Integrated DNS-Zones transforming the Windows-DNS to be caching-only servers.

 

Cheers,

 Philipp

 

Re: Active Directory DNS Migration steps to Infoblox

Member
Posts: 2
2901     0

Hi Philipp,

 

Thank you so much for your sharing. I have 1 question regarding your migration:

 

1. For steps 9 and 10, do you do it one shot for all DCs or phase by phase, FYI, my customer got 60++ DC servers, we are thinking to do it phase by phase but we worry problem will occur in the period. 

 

Thanks

Chew

 

 

Showing results for 
Search instead for 
Did you mean: 

Recommended for You

Demo: Infoblox IPAM plug-in integration with OpenStack Newton