In this thread today I got clarification on the meaning of the various DNS actions. Very helpful. Now to the real question. We have a Windows DNS secondary zone that maintains a copy of our parent company's DNS. When I open the zone in DNS mmc, "all" the entries show up yet the Status for the zone is listed as "zone never loaded".
This seems odd since we can apparently resolve the hosts we need to access in this dns. What is this status trying to tell us about this zone?
By default, AD Integrated zones do not have zone transfers allowed. Regarding transfer status, are both TCP 53 and UDP 53 allowed between the two?
Ace Fekay
As I understand it with Windows DNS, zone transfers are not enabled by default. You have to enable them explicitly in the 'zone transfer' section in the properties of the primary zone.
Can you confirm if you have enabled this?
You're right that there is a conflicting message. A warning, plus valid data. Some things to try:
Use NS lookup to confirm that your zone is responding correctly. Here's a video walkthrough on how to do that. Make sure to use
server secondary_dns_server
to test directly from your secondary server.We experienced the same problem on our secondary server, when the primary AD was restored from a backup.
In fact the
serial number
value on the secondary server was ahead of the serial number on the primary server. On the secondary server, the zones showed the statuszone never loaded
.I solved the problem by deleting and re-creating the lookup zones.
The primary was a 2003, the secondary a 2012R2.