简体   繁体   English

Azure <> 本地 DNS 转发器分辨率

[英]Azure <> on premise DNS forwarder resolution

We have an Azure infrastructure that is connected to an on premise datacenter via a VPN gateway, and are trying to configure DNS resolution between both.我们有一个 Azure 基础设施,它通过 VPN 网关连接到本地数据中心,并试图在两者之间配置 DNS 分辨率。

We have an ADDS configured with forwarders(for app.internal) to the on premise DNS servers and on premise DNS server forwards to our ADDS that forwards to Azure DNS 168.63.129.16. We have an ADDS configured with forwarders(for app.internal) to the on premise DNS servers and on premise DNS server forwards to our ADDS that forwards to Azure DNS 168.63.129.16.

In a VNET configured with the two IP of the ADDS, we have an app service configured with vnet integration, and when we try to resolve an app.internal the resolution is not stable at all.在配置了 ADDS 的两个 IP 的 VNET 中,我们有一个配置了 vnet 集成的应用服务,当我们尝试解析 app.internal 时,分辨率根本不稳定。

At the end of the TTL the A record disappear only to reappear randomly.在 TTL 结束时,A 记录消失,只是随机重新出现。 The only way we found to force him to resolve the A record is to clear cache on the ADDS.我们发现迫使他解析 A 记录的唯一方法是清除 ADDS 上的缓存。

Resolution from on premise to Azure works fine.从本地到 Azure 的分辨率工作正常。

In Azure ADDS when you added the conditional forwarding, did you check "store this conditional forwarder in ad and replicate it to": make sure you did NOT select all dns server in this Forest,在 Azure ADDS 中,当您添加条件转发时,您是否选中“将此条件转发器存储在广告中并将其复制到”:确保您没有 select 在此森林服务器中的所有 ZB3BF60B851EBAEB2768B01A32E2

Important重要的

If the conditional forwarder is stored in the forest instead of the domain, the conditional forwarder fails.如果条件转发器存储在林而不是域中,则条件转发器将失败。

If this is not the issue, then I'm not sure what the problem is here, but as a workaround, you could create a secondary zone of your on-prem app.internal zone on the ad ds dns server, and have it replicate records from on-prem primary, that would probably increase reliability because it would probably do a better job of caching the zone.如果这不是问题,那么我不确定问题出在哪里,但作为一种解决方法,您可以在 ad ds dns 服务器上创建本地 app.internal 区域的辅助区域,并让它复制来自本地主数据库的记录,这可能会提高可靠性,因为它可能会更好地缓存区域。

If others have comments about this, feel free.如果其他人对此有意见,请随意。

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM