DNS Advice on 140d/200d
Hello All,
I support 5 HA clusters across a few sites, most made up of 140D-POE's other than HQ where we have a pair of 200D-POE's and also our Main DC. Remote sites have no RODC or DC they are not currently on the domain
spoke and hub IPSec VPN setup between HQ and remote sites. I am trying to get our remote sites on the domain to help in the rollout of some company wide administration software, machines need to be on the domain to be visible to this remote management tool.
Heres the plan in all its half understood glory, please excuse my incorrect terminology use -
Each site has a VPN tunnel to HQ where our Primary DC sits
I will put in place a second VPN tunnel to a cloud based DC as a failover
This ensures remote offices dont go out of service if either link fails
I dont want the VPN link to be used for all DNS lookups, this seems like a lot of traffic going over a tunnel,
Heres where my terminology fails me. I want the local fortigates at each side to resolve internet DNS requests e.g. google.com, but any company domain based requests to be forwarded over the VPN to wither HQ or the secondary cloud DC.
All the guides/posts I've found seem to be showing how to do it vice versa, relying on the remote DC to resolve everything. Is this the norm? If an office of 30-40 users all have their DNS traffic going over a VPN tunnel would this be seen as unorthodox?
So I got as far as turning on advanced DNS controls on the fortigate and getting my head around creating zones but not the process for prioitizing what DNS requests go where.
Thanks for your help in advance, much appreciated by a humble IT administrator single handedly supporting 6 offices and in way over his head.
Shhhh dont tell the boss!