Configure and Verify DNS Records on Windows Server

ravell
9 min read

Overview#

This lab configures and verifies forward and reverse DNS records for the company.local environment. It adds an A record for ise121, creates a reverse lookup zone and PTR records, adds a CNAME alias, and checks the Active Directory LDAP and Kerberos SRV records.

The lab also confirms that the DNS zone is configured to allow secure dynamic updates. Automatic DNS registration from a separate Windows client was not tested because a separate client is not available in this lab.

Lab Environment#

  • Operating system: Windows Server 2025 Standard, version 24H2
  • OS build: 26100.32690
  • Domain: company.local
  • DNS server / Domain Controller: company-ad.company.local — 198.18.134.50
  • ISE host record: ise121.company.local — 198.18.134.121
  • Subnet: 198.18.128.0/18 (255.255.192.0)
  • Default gateway: 198.18.128.1
  • DNS client settings shown in the lab: ::1 and 127.0.0.1

The Windows Server adapter has DHCP disabled. The DNS Manager screenshots show the existing company.local forward lookup zone and the DNS server named COMPANY-AD.company.local.

Prerequisites#

  • An existing Windows Server DNS role and the company.local forward lookup zone.
  • Access to DNS Manager with permission to create or update DNS records and zones.
  • The intended hostnames and IP addresses for the A and PTR records.

This guide starts from the existing DNS and Active Directory environment; it does not cover installing the DNS Server or AD DS roles.

Configure the Forward Lookup Record#

Open Server Manager > Tools > DNS. Expand the DNS server, expand Forward Lookup Zones, and select company.local.

DNS Manager showing the COMPANY-AD.company.local DNS server and its forward lookup zones
DNS Manager showing the COMPANY-AD.company.local DNS server and its forward lookup zones

Figure 1. DNS Manager with the existing company.local forward lookup zone.

Forward lookup zone company.local showing the existing company-ad host record
Forward lookup zone company.local showing the existing company-ad host record

Figure 2. The selected company.local zone shows the existing company-ad A record at 198.18.134.50.

Select the company.local zone and choose New Host (A or AAAA). In this lab, the host record was created with these values:

  • Name: ise121
  • IP address: 198.18.134.121
  • Resulting FQDN: ise121.company.local

The Create associated pointer (PTR) record option was not selected at this stage. The PTR records were added manually after the reverse lookup zone was created.

New Host dialog with ise121 and 198.18.134.121
New Host dialog with ise121 and 198.18.134.121

Figure 3. Values entered for the ise121 host record.

Confirm that ise121 appears in the company.local zone with address 198.18.134.121.

Forward lookup zone showing the ise121 host record
Forward lookup zone showing the ise121 host record

Figure 4. The ise121 A record in the forward lookup zone.

Verify Forward Name Resolution#

From the command prompt on the server, ping the FQDN:

Copy code to clipboard
Open code in new window
Disable hover highlighting
1C:\Users\Administrator>ping ise121.company.local 2 3Pinging ise121.company.local [198.18.134.121] with 32 bytes of data: 4Reply from 198.18.134.121: bytes=32 time<1ms TTL=64 5Reply from 198.18.134.121: bytes=32 time=1ms TTL=64 6Reply from 198.18.134.121: bytes=32 time=1ms TTL=64 7Reply from 198.18.134.121: bytes=32 time=1ms TTL=64 8 9Ping statistics for 198.18.134.121: 10 Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), 11Approximate round trip times in milli-seconds: 12 Minimum = 0ms, Maximum = 1ms, Average = 0ms 13 14C:\Users\Administrator>

The hostname resolved to 198.18.134.121, and the ping received four replies with no packet loss. This verifies name resolution and ICMP reachability from the server; it does not test an application service on the ISE host.

Command prompt showing a successful ping to ise121.company.local
Command prompt showing a successful ping to ise121.company.local

Figure 5. The FQDN resolves to 198.18.134.121 and replies to ping.

Create the Reverse Lookup Zone#

In DNS Manager, right-click Reverse Lookup Zones and select New Zone. The recorded wizard selections were:

  1. Zone type: Primary zone, with Store the zone in Active Directory selected.
  2. Active Directory replication scope: All DNS servers running on domain controllers in the company.local domain.
  3. Reverse lookup zone type: IPv4 Reverse Lookup Zone.
  4. Network ID: 198.18.134.
  5. Dynamic updates: Allow only secure dynamic updates.
Reverse Lookup Zones in DNS Manager before opening the wizard
Reverse Lookup Zones in DNS Manager before opening the wizard

Figure 6. Starting the New Zone wizard from Reverse Lookup Zones.

New Zone wizard with Primary zone and Active Directory integration selected
New Zone wizard with Primary zone and Active Directory integration selected

Figure 7. The zone is configured as a Primary zone stored in Active Directory.

New Zone wizard showing replication to DNS servers in the company.local domain
New Zone wizard showing replication to DNS servers in the company.local domain

Figure 8. The selected replication scope is DNS servers on domain controllers in company.local.

New Zone wizard with IPv4 Reverse Lookup Zone selected
New Zone wizard with IPv4 Reverse Lookup Zone selected

Figure 9. IPv4 is selected for the reverse lookup zone.

New Zone wizard with the Network ID 198.18.134
New Zone wizard with the Network ID 198.18.134

Figure 10. The Network ID entered for the zone is 198.18.134.

New Zone wizard with Allow only secure dynamic updates selected
New Zone wizard with Allow only secure dynamic updates selected

Figure 11. The reverse zone is set to allow only secure dynamic updates.

The wizard created the zone 134.18.198.in-addr.arpa.

New Zone wizard completion page showing 134.18.198.in-addr.arpa
New Zone wizard completion page showing 134.18.198.in-addr.arpa

Figure 12. The resulting reverse lookup zone name is 134.18.198.in-addr.arpa.

DNS Manager showing the reverse lookup zones
DNS Manager showing the reverse lookup zones

Figure 13. DNS Manager shows the reverse lookup zones, including 134.18.198.in-addr.arpa.

Add PTR Records#

Add a PTR record for each host in the reverse lookup zone. The lab added these mappings:

IP addressPTR target
198.18.134.121ise121.company.local
198.18.134.50company-ad.company.local
New PTR record form for 198.18.134.121 and ise121.company.local
New PTR record form for 198.18.134.121 and ise121.company.local

Figure 14. PTR record values for the ISE host.

New PTR record form for 198.18.134.50 and company-ad.company.local
New PTR record form for 198.18.134.50 and company-ad.company.local

Figure 15. PTR record values for the DNS server / Domain Controller.

Reverse lookup zone showing PTR records for company-ad and ise121
Reverse lookup zone showing PTR records for company-ad and ise121

Figure 16. Both PTR records are visible in the reverse lookup zone.

Verify A and PTR Records#

Query the DNS server at 198.18.134.50 for both forward and reverse records:

Copy code to clipboard
Open code in new window
Disable hover highlighting
1C:\Users\Administrator>nslookup company-ad.company.local 198.18.134.50 2Server: company-ad.company.local 3Address: 198.18.134.50 4 5Name: company-ad.company.local 6Address: 198.18.134.50 7 8 9C:\Users\Administrator>nslookup 198.18.134.50 198.18.134.50 10Server: company-ad.company.local 11Address: 198.18.134.50 12 13Name: company-ad.company.local 14Address: 198.18.134.50 15 16 17C:\Users\Administrator>nslookup ise121.company.local 198.18.134.50 18Server: company-ad.company.local 19Address: 198.18.134.50 20 21Name: ise121.company.local 22Address: 198.18.134.121 23 24 25C:\Users\Administrator>nslookup 198.18.134.121 198.18.134.50 26Server: company-ad.company.local 27Address: 198.18.134.50 28 29Name: ise121.company.local 30Address: 198.18.134.121

The forward queries return the expected IP addresses, and the reverse queries return the corresponding hostnames. In the earlier attempt, reverse queries returned Non-existent domain; after the PTR records were added, the queries above returned the hostnames.

Add and Verify a CNAME Alias#

In the company.local forward lookup zone, add a CNAME with:

  • Alias name: ise
  • Fully qualified alias: ise.company.local
  • Target FQDN: ise121.company.local
New CNAME resource record for ise pointing to ise121.company.local
New CNAME resource record for ise pointing to ise121.company.local

Figure 17. The ise alias points to ise121.company.local.

Verify the CNAME and then resolve the alias:

Copy code to clipboard
Open code in new window
Disable hover highlighting
1C:\Users\Administrator>nslookup -type=CNAME ise.company.local 198.18.134.50 2Server: company-ad.company.local 3Address: 198.18.134.50 4 5ise.company.local canonical name = ise121.company.local 6 7C:\Users\Administrator>nslookup ise.company.local 198.18.134.50 8Server: company-ad.company.local 9Address: 198.18.134.50 10 11Name: ise121.company.local 12Address: 198.18.134.121 13Aliases: ise.company.local

The output confirms that ise.company.local is an alias for ise121.company.local and resolves to 198.18.134.121. This verifies DNS resolution only; it does not test access to a service through the alias.

Verify Active Directory SRV Records#

Query the LDAP and Kerberos SRV records for the domain controller:

Copy code to clipboard
Open code in new window
Disable hover highlighting
1C:\Users\Administrator>nslookup -type=SRV _ldap._tcp.dc._msdcs.company.local 198.18.134.50 2Server: company-ad.company.local 3Address: 198.18.134.50 4 5_ldap._tcp.dc._msdcs.company.local SRV service location: 6 priority = 0 7 weight = 100 8 port = 389 9 svr hostname = company-ad.company.local 10company-ad.company.local internet address = 198.18.134.50 11 12C:\Users\Administrator>nslookup -type=SRV _kerberos._tcp.dc._msdcs.company.local 198.18.134.50 13Server: company-ad.company.local 14Address: 198.18.134.50 15 16_kerberos._tcp.dc._msdcs.company.local SRV service location: 17 priority = 0 18 weight = 100 19 port = 88 20 svr hostname = company-ad.company.local 21company-ad.company.local internet address = 198.18.134.50

Both queries return company-ad.company.local at 198.18.134.50. The LDAP SRV response advertises port 389, and the Kerberos SRV response advertises port 88. These queries verify that the SRV records resolve; they do not test whether the corresponding services accept connections.

Secure Dynamic Updates#

The company.local zone properties show that the zone is Active Directory-integrated and that Dynamic updates is set to Secure only. The reverse-zone wizard also selected Allow only secure dynamic updates.

company.local zone properties showing Active Directory integration and Secure only dynamic updates
company.local zone properties showing Active Directory integration and Secure only dynamic updates

Figure 18. The company.local zone is Active Directory-integrated and configured for secure-only dynamic updates.

This confirms the zone setting. Automatic registration by a separate Windows client has not been verified in this lab because no separate Windows client was installed. Mark client-side registration as [PERLU VERIFIKASI] until it is tested from an appropriate domain-joined client.

Issues and Scope Notes#

  • Initial reverse queries returned Non-existent domain. The A records resolved, but the PTR lookups did not. PTR records were then created for 198.18.134.50 and 198.18.134.121; the later nslookup output shows both reverse lookups resolving.
  • Reverse-zone coverage is narrower than the documented subnet. The lab subnet is 198.18.128.0/18, while the wizard input 198.18.134 created 134.18.198.in-addr.arpa, which covers the 198.18.134.x /24 range. The screenshots also show 128.18.198.in-addr.arpa. The successful PTR tests prove resolution for the two 198.18.134.x addresses only; they do not prove complete reverse DNS coverage for the entire /18. [PERLU VERIFIKASI] Determine and test the intended reverse-zone design if all addresses in 198.18.128.0/18 must have reverse resolution.
  • Client-side secure dynamic update is untested. The zone is configured as secure-only, but no separate Windows client was available to test automatic record registration.

Security and Limitations#

  • The DNS zones shown are configured for secure-only dynamic updates; do not change them to allow nonsecure updates as part of this lab.
  • The A, PTR, CNAME, and SRV checks verify DNS answers. They do not prove that an application, LDAP, or Kerberos connection succeeds.
  • The client-side dynamic update behavior and full /18 reverse-zone coverage remain unverified.

Conclusion#

The lab successfully verifies forward and reverse resolution for company-ad.company.local and ise121.company.local, resolves the ise.company.local CNAME, and returns the LDAP and Kerberos SRV records for company-ad.company.local. The zone is configured for secure-only dynamic updates. A separate Windows client test and a decision about reverse lookup coverage for the complete /18 remain outstanding.

References#