My company has three business groups in three buildings, behind three firewalls, and each has its own Win2K3 forest. The company decided to deploy a shared forest across all three buildings for all three business units to use and established two-way trusts from this forest to the other three forests. The shared forest DCs replicate via IPSec over the Internet and it works well.
The first resource forest DC was deployed successfully in building one, but we started running into dns resolution issues after we deployed to buildings two and three. When we ping the FQDN of the shared forest, the local shared forest DNS server sometimes returns the local DNS/DC’s IP address and other times it returns the remote DCs IP address. The problem is that the remote DCs are behind the firewalls of buildings 2 and 3 and not accessible from building 1. This leads to our users not being able to download policies when they login to the shared forest.
Considering that all of our DCs are DNS servers also, we would like to find a way to configure each DNS server to return its own record instead of the remote DCs record when pinged. Is this at all possible?