David,
Are both of your DCs Global Catalogs as well, if not which one is a GC.
When which one is off-line do you lose file share authentication?
As for what domain zone looks like, it's too difficult to explain in a
post, but if you email me I'll try to figure out a way to get the basic
content into an email for you. For what it's worth the _msdcs.yourdomain.com
zone file is discussed in some detail in chapter 3 of the Active Directory
for Microsoft Windows Server 2003 Technical Reference book from MS (ISBN
0-7356-1577-2). This reference has come in handy more than once for me.
Now for one possible sign of hope in all this when you promote a server
to a DC it writes all the the records needed by the Forest/Domain (as it
existed at that time) to a file called Netlogon.dns, it is located in the
%systemroot%\system32\config folder. If we're lucky you'll be able to find
this file on at least one of your DCs and use this file do build a correctly
populated _msdcs.yourdomain.com file on your UNIX system running BIND. If we
can get this working correctly then we'll move on to configuring BIND to
support dynamic updates from your DCs so hopefully you won't have problems in
the future.
It really drives me crazy when people ask me this, but are you really
dead set on integrating BIND with AD? Fear not I and others will stick with
you no matter what the answer, but I just felt compelled to ask.
--
James E. Price III
Fairway Consulting Group, Inc.
O: 954-727-5126
C: 305-970-4902
E:
(E-Mail Removed)
W:
www.fcgroup.us
"(E-Mail Removed)" wrote:
> Thanks for the help guys...
>
> Can someone direct me to some documentation on how the zone data file
> for a Windows domain (with more than one domain controller) should look
> like?
>
> I noticed more weird behavior... While access to network shares only
> seems to authenticate with the 2nd domain controller, it seems that
> Windows logon can authenticate with either domain controller. Does
> this indicate certain protocols are not being forwarded to EITHER
> domain controller? Is there a particular section of the domain zone
> data file I should be focusing on?
>
>