You need to sign up to get access!

Sign up to get full access to this course.

Sign up to access this lesson

Click here to sign up and get access to this lesson!

Saving Progress...

In this Video: 

  • We will describe Stub Zones
  • We will consider the differences between a conditional forwarder, a delegation and a stub zone.
  • We will describe a scenario in which stub zones could be used in your organization.
  • At the completion of this lecture, you will know how to use stub zones in your lab or your organization.

What is a Stub Zone? How are stub zones different from conditional forwarders or delegations?

Describe a Stub Zone

  • A stub zone is a pointer, that points to another DNS server (we will call this server the target server).
  • A stub zone is unique in that it can dynamically update itself.
  • If things change (at the target domain) if DNS servers are added removed. Stub Zones know about those changes where delegations or conditional forwarders would have to be manually changed.
  • A stub zone is a forward lookup zone. A stub zone only requires the SOA and the NS records from the other DNS server (or the target), which are normally publicly available.
  • Stub zones are useful in that they are dynamically configured and basically can take care of themselves.

Describe Conditional Forwarders and Delegations

  • Delegations and conditional forwarder are configured to point to other servers as well.  
  • When a conditional forwarder or a delegation is configured, a single server is used to resolve names. If that server (the target) goes down the clients won’t be able to get to the data that they require.
  • Delegations and conditional forwarders are useful if there are no future changes made at the target domain.

LAB Prerequisites: 

  • Setup Three Windows 2016 Servers
  • Two of those servers should be “stand alone” domains (completely separated) I used and
  • For the domain install Active Directory on SVR-US, On SVR-DNS1 install DNS. This server could be a member server.  
  • Setup one server in the domain, this server has Active Directory installed.


Your company, Computer Associates has just purchased United Security Services.

Both companies have completely separate Domains. The Managers at HQ need access to servers in the domain. You are the DNS administrator.

How will you configure DNS to satisfy the following requirements from management?

  • Management will need access to certain files in the domain
  • Management request fault tolerance, so that if one DNS server goes down they will not lose access to the files that they require.

Step 1

From the server SVR-CA, open a command prompt and type ping  Ping cannot find the server. This proves that there is no access to SVR-US.

Step 2 Stub Zone Creation

From SVR-CA (we will call this the source), open server manager, tools, DNS. Double click the forward lookup zone, the current zones are displayed.  

Right click forward lookup, select new zone, click next, Select Stub Zone, check store in Active Directory, click next.  

Select how you want zone data replicated, in this case I select to all DNS servers running on Domain Controllers in this domain, click next.  

For zone name type, click next. Type the IP address of the server that the stub zone will point too (or the target) in this case type the IP address for SVR-US which is Click in the box. SVR-US is validated, click next, click finish Double click on the zone – Why would you receive this error Zone Not Loaded by DNS Server?

It is because Zone transfers have not been enabled on the zone.

Step 3 – Enable zone transfers  

From SVR-US server (we will call this the target), open server manager, tools, DNS. Double click forward lookup zone, right click, select properties, click zone transfers, check allow zone transfers, select only to the following servers, click edit, type in the IP address of the server that you wish to send zone data too.

Sign up to access the rest of this lesson

You must either log in or sign up to access this lesson.


Course Introduction

• 10min

0 / 2 lessons complete

DNS Basics

• 56min

0 / 8 lessons complete

DNS Resource Records

• 45min

0 / 5 lessons complete

DNS Zones

• 4hr 11min

0 / 12 lessons complete

DNS Delegation

• 50min

0 / 4 lessons complete

DNS Security Techniques

• 36min

0 / 5 lessons complete

Advanced DNS Topics

• 22min

0 / 5 lessons complete

DNS Security (DNSSEC)

• 1hr 16min

0 / 6 lessons complete

DNS Policies

• 55min

0 / 6 lessons complete

PowerShell for DNS

• 1hr 27min

0 / 6 lessons complete

Troubleshooting DNS Issues - Troubleshooting Tools

• 1hr 39min

0 / 8 lessons complete