We have recently installed a Windows 2000 domain and have set up the DNS servers as root servers for a closed network. We have dedicated internet access with DNS servers outside the firewall to service internet requests. We don’t want to make the AD DNS servers forwarding servers because we have a limited list of users that are allowed internet access and due to the way DNS works, adding the external DNS servers as secondary servers does not work. Is there a way around this? Possibly a restricted user list?