> For the complete documentation index, see [llms.txt](https://ghoulsec.gitbook.io/ghoulsec-vault/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ghoulsec.gitbook.io/ghoulsec-vault/server-are-fun/servers/windows-sever/ad-dns.md).

# AD DNS

Active Directory (AD) relies on **Domain Name System (DNS)** to function properly. DNS in an AD environment is responsible for translating domain names into IP addresses so that resources (like computers, servers, and services) can communicate with each other. Specifically, AD uses DNS to locate domain controllers, manage replication, and support various other critical directory services.

#### **Forward and Reverse Lookup Zones**:

* **Forward Lookup Zone**: This zone allows DNS to resolve domain names (like `server.example.com`) to their corresponding **IP addresses**. It's used when a client needs to find the IP address of a server or service by its name.
* **Reverse Lookup Zone**: This zone does the opposite. It maps an IP address back to a **domain name**. It's used when a client needs to find the domain name associated with an IP address (for example, reverse DNS lookup).

#### **Why It Is Compulsory to Configure Forward & Reverse Lookup Zones**:

1. **Correct Name Resolution**: AD heavily depends on DNS for proper name resolution. Without forward and reverse lookup zones configured, domain controllers and other network resources may fail to resolve names correctly, disrupting communication across the network.
2. **AD Functionality**: AD services, such as locating domain controllers and services like Global Catalog, depend on proper DNS configuration. Without DNS, clients won't be able to authenticate, or locate resources like printers or shared files.
3. **Replication**: In a multi-domain controller setup, **replication** between domain controllers relies on DNS for finding and communicating with each other. Misconfigured DNS can cause replication failures.
4. **Security and Troubleshooting**: Reverse lookup zones also enhance security (e.g., verifying client IP addresses) and troubleshooting (e.g., identifying the source of a connection) by allowing easy resolution from IP to domain name.

***

We will now be configuring windows AD DNS :&#x20;

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FUnaJsKg2ki8gaFXfiTrJ%2Fimage.png?alt=media&amp;token=f5246ca4-70ff-4c8b-a689-b0424c30999b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2Fy1RDj0oCiqOzOb8gKZCD%2Fimage.png?alt=media&amp;token=f42962da-d03c-479d-a34b-dab1d7f6df90" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FJ6A5weQwNhsx7s2nJucm%2Fimage.png?alt=media&amp;token=1b6a5764-6144-48e9-bf21-a277b5f580ac" alt=""><figcaption></figcaption></figure>

We will now create the Reverse lookup zones and configure Forward lookup zone to configure the FQDN resolution and functioning of AD DNS

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FH1wrdvFtyIGPkaJZ51CX%2Fimage.png?alt=media&amp;token=dabf6ca2-c2c7-49ee-849c-e00e20908f2e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2F1mOEmE7pKU43TbAd5GyF%2Fimage.png?alt=media&amp;token=dc56b0d9-edf9-4eb8-9cab-65c886bd8a11" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FfC2AkFG4Eo7XWwFB9DDe%2Fimage.png?alt=media&amp;token=a984e73a-0ba7-49ea-9669-4dca542be729" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FEd6tUoQiMCbbU8nmKNsg%2Fimage.png?alt=media&amp;token=7d5ff819-3944-462e-b7c8-ab3ace85e269" alt=""><figcaption></figcaption></figure>

We will keep the default selected values until here and now we have to enter the revers arpa IP address of the domain controller `First 3 Network Bytes`  of the AD servers IP address and continue

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2F798AeG4JeRHJZrzfR4gh%2Fimage.png?alt=media&amp;token=7a59b96b-0a7c-4a85-9c70-1c4527e86c65" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FrA6o69aOP061YhZkCzbG%2Fimage.png?alt=media&amp;token=af45cfcf-1103-4f93-acd4-2d9c8c5012cb" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FV7vbNJBx94yVwdZzyMcb%2Fimage.png?alt=media&amp;token=4693360d-3996-4e70-acce-5e1c9d16839d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FPWHiNDA1hFOVZdg0RJbz%2Fimage.png?alt=media&amp;token=bac843c8-33a9-44a2-af36-cae2fc3a45d0" alt=""><figcaption></figcaption></figure>

We have now configured the reverse lookup zone and now we will update the PTR record of the forward lookup zone to sucessfully configure the FQDN resolution

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FT1jAYUW3kODfgjfMSjwk%2Fimage.png?alt=media&amp;token=234a01b5-9eee-4829-99f6-5f524493514f" alt=""><figcaption></figcaption></figure>

Check the box to update the reverse PTR record and then apply and continue&#x20;

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FPOhcoxad5ay2YGHh8ehe%2Fimage.png?alt=media&amp;token=c6f764ad-4720-458c-83c0-f677a301bb6d" alt=""><figcaption></figcaption></figure>

Now we have configured the AD DNS and we will now check the resolution using nslookup utility built in under the DNS application&#x20;

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FctdWIBUwvHgpVj75heTC%2Fimage.png?alt=media&amp;token=54ed94cb-fddf-422f-a8a6-707a2d25e70f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2332860236-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fq6mjlFfyDOi3mV0lemKE%2Fuploads%2FmJMTisyKkZBTqxEiuQ7u%2Fimage.png?alt=media&amp;token=c1565d00-9dd8-4baf-aa10-de4b27cb0631" alt=""><figcaption></figcaption></figure>

If the forward & reverse lookup is sucessfull then we have sucessfully configured the AD DNS onto our sever. Now we will configure the DHCP server inside your domain to issue and lease the IP Addresses to our AD clients in the next section
