<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>DHCP, DNS and the DNSUpdateProxy-Group</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2004/11/15/19325.aspx</link><description>I had a discussion in the Newsgroups lately about DHCP and the DNSUpdateProxy-Group which is used to write unsecured DNS-Entries to a DNS-Zone which only allows secure updates. That's propably not the correct definition, but it describes pretty much what</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>re: Follow up discussion on the DNSUpdateProxy-Group</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2004/11/15/19325.aspx#60066</link><pubDate>Sun, 31 Jul 2005 13:58:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:60066</guid><dc:creator>TrackBack</dc:creator><description>&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=60066" width="1" height="1"&gt;</description></item><item><title>re: DHCP, DNS and the DNSUpdateProxy-Group</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2004/11/15/19325.aspx#39843</link><pubDate>Sun, 27 Mar 2005 04:35:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:39843</guid><dc:creator>Ulf B. Simon-Weidner</dc:creator><description>Hi Bob,&lt;br&gt;&lt;br&gt;I've answered your question in a new Blogentry:&lt;br&gt;&lt;a target="_new" href="http://msmvps.com/ulfbsimonweidner/archive/2005/03/26/39841.aspx"&gt;http://msmvps.com/ulfbsimonweidner/archive/2005/03/26/39841.aspx&lt;/a&gt;&lt;br&gt;&lt;br&gt;Thanks for the answer again, if you have comments they are always welcome and apprechiated.&lt;br&gt;&lt;br&gt;Ulf&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=39843" width="1" height="1"&gt;</description></item><item><title>Follow up discussion on the DNSUpdateProxy-Group</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2004/11/15/19325.aspx#39842</link><pubDate>Sat, 26 Mar 2005 19:29:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:39842</guid><dc:creator>TrackBack</dc:creator><description>&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=39842" width="1" height="1"&gt;</description></item><item><title>Training, Speaking at CeBit, and getting a boost on Testing</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2004/11/15/19325.aspx#39464</link><pubDate>Wed, 23 Mar 2005 21:18:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:39464</guid><dc:creator>TrackBack</dc:creator><description>&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=39464" width="1" height="1"&gt;</description></item><item><title>re: DHCP, DNS and the DNSUpdateProxy-Group</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2004/11/15/19325.aspx#38224</link><pubDate>Sat, 12 Mar 2005 04:31:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:38224</guid><dc:creator>Ulf B. Simon-Weidner</dc:creator><description>How does this solve the problem that the DNSUPDATEPROXY group was designed to fix, namely the prevention of stale records and the ability of upgrade clients (NT --&amp;gt; 2000) to refresh and update records created for them by the DHCP server?&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=38224" width="1" height="1"&gt;</description></item><item><title>re: DHCP, DNS and the DNSUpdateProxy-Group</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2004/11/15/19325.aspx#36009</link><pubDate>Wed, 16 Feb 2005 04:55:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:36009</guid><dc:creator>Ulf B. Simon-Weidner</dc:creator><description>Hi Max,&lt;br&gt;&lt;br&gt;sorry for answering so late - those Trainings and their preparation keep my busy right now.&lt;br&gt;&lt;br&gt;You have a Offline DC? Then you need to be very carefull that you replicate them once in a while - latest every 60 days. There are other solutions to provide DHCP redundancy. If you have different subnets, you can put the DHCP-Servers on different subnets and split the scopes (the router needs to support BootP Forwarding / DHCP-Relaying). You'd also be able to configure the subnet on both DHCP-Servers, but activate it on just one. Enable conflict detection. Or cluster the DHCP-Server. Or install and configure DHCP on both servers, configure the same scopes, but put the DHCP-Server Service on one machine to deactivated and stop it.&lt;br&gt;&lt;br&gt;Back to the reason of your question - do NOT use the DnsUpdateProxy-Group - configure both DHCP-Server Services to run under a specific Serviceaccount. As stated in the Blog DnsUpdateProxy is bad - it makes your dynamic updates as reliable as if they were &amp;quot;unsecure&amp;quot; - and this is paticulary bad if you are running DHCP on a DC. Create a Serviceaccount and configure the DHCP-Services to run under that account. That's much more secure.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=36009" width="1" height="1"&gt;</description></item><item><title>re: DHCP, DNS and the DNSUpdateProxy-Group</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2004/11/15/19325.aspx#34817</link><pubDate>Thu, 03 Feb 2005 23:35:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:34817</guid><dc:creator>Ulf B. Simon-Weidner</dc:creator><description>I have one dhcp online(DC) and one offline (DC) (backup)&lt;br&gt;The domain it's 2000 native mode one forest one domain&lt;br&gt;the dns zone is integrated in AD and allow only security update&lt;br&gt;i just wanna know if i need to start the backup dhcp server (stopping the another one) i need the dnsupdateproxy group and set with the netsh&lt;br&gt;command an account ?&lt;br&gt;&lt;br&gt;&lt;br&gt;thanks &lt;br&gt;Max&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=34817" width="1" height="1"&gt;</description></item></channel></rss>