1
00:00:06,660 --> 00:00:11,660
- [Instructor] Servers Part
3: DHCP and DNS Servers.

2
00:00:12,300 --> 00:00:14,760
The DHCP server is in charge

3
00:00:14,760 --> 00:00:18,120
of handing out IP addresses to clients.

4
00:00:18,120 --> 00:00:22,380
It also gives out additional
TCP/IP information.

5
00:00:22,380 --> 00:00:23,820
So here in our illustration

6
00:00:23,820 --> 00:00:26,760
we have a DHCP server

7
00:00:26,760 --> 00:00:28,680
here on the LAN,

8
00:00:28,680 --> 00:00:32,550
and normally this would
hand out the IP address

9
00:00:32,550 --> 00:00:35,910
to all the clients automatically.

10
00:00:35,910 --> 00:00:39,000
It would also hand out the subnet mask,

11
00:00:39,000 --> 00:00:43,500
gateway address and the IP
address of the DNS server.

12
00:00:43,500 --> 00:00:44,820
So this is very common

13
00:00:44,820 --> 00:00:49,290
and this could be a SOHO router
that runs as a DHCP server

14
00:00:49,290 --> 00:00:53,700
or it could be a Windows server
that hands out IP addresses.

15
00:00:53,700 --> 00:00:57,540
You could also have DHCP
servers on the internet.

16
00:00:57,540 --> 00:01:00,090
And, for example, let's
say had a small office

17
00:01:00,090 --> 00:01:01,170
or a home office,

18
00:01:01,170 --> 00:01:05,790
and you had your SOHO
router/firewall device.

19
00:01:05,790 --> 00:01:08,460
Well, in order for computers
that are connected to this

20
00:01:08,460 --> 00:01:12,930
to get out to the internet
and access websites,

21
00:01:12,930 --> 00:01:17,460
this device that SOHO router
needs to get an IP address

22
00:01:17,460 --> 00:01:20,523
from the DHCP server at the ISP,

23
00:01:21,390 --> 00:01:23,880
a public IP address that'll allow it

24
00:01:23,880 --> 00:01:25,803
to communicate on the internet.

25
00:01:26,820 --> 00:01:28,710
So two different types there.

26
00:01:28,710 --> 00:01:32,310
Now, let's focus on the
DHCP server on the LAN

27
00:01:32,310 --> 00:01:36,450
and we'll show some IP config
information on a client,

28
00:01:36,450 --> 00:01:37,860
and then we'll show two examples

29
00:01:37,860 --> 00:01:40,713
of DHCP servers on the local area network.

30
00:01:42,150 --> 00:01:46,230
We'll start here, this is a
Windows 7 Virtual Machine.

31
00:01:46,230 --> 00:01:49,750
So we'll run an IP config command

32
00:01:50,850 --> 00:01:54,120
to see the TCP/IP information.

33
00:01:54,120 --> 00:01:57,360
And we need to do that
with the /all option

34
00:01:57,360 --> 00:01:59,160
so that we can see all
the information here.

35
00:01:59,160 --> 00:02:00,780
We'll press enter.

36
00:02:00,780 --> 00:02:04,380
and here's our local area
connection, our ethernet adapter.

37
00:02:04,380 --> 00:02:08,760
And it says here DHCP is enabled, yes.

38
00:02:08,760 --> 00:02:11,490
So we know we're getting this information

39
00:02:11,490 --> 00:02:13,250
from a DHCP server.

40
00:02:13,250 --> 00:02:16,770
In this case, it's a virtual DHCP server.

41
00:02:16,770 --> 00:02:19,203
It actually comes from within VMware.

42
00:02:20,040 --> 00:02:24,030
Here's the IP address that I've
been given at this computer.

43
00:02:24,030 --> 00:02:26,973
Here's the subnet mask, triple 255.

44
00:02:27,840 --> 00:02:29,310
Here's the gateway address,

45
00:02:29,310 --> 00:02:32,040
and that is the virtual switch,

46
00:02:32,040 --> 00:02:36,063
the virtual router, actually in VMware,

47
00:02:37,740 --> 00:02:38,573
that's .2

48
00:02:39,870 --> 00:02:43,500
And the DHCP server is
actually known as .254,

49
00:02:43,500 --> 00:02:46,563
but that's kind of all built
into the virtual system.

50
00:02:47,700 --> 00:02:50,700
And DNS servers .2 over here.

51
00:02:50,700 --> 00:02:52,890
So that's a bunch of
information that you get

52
00:02:52,890 --> 00:02:55,140
from the DHCP server.

53
00:02:55,140 --> 00:02:57,630
You get your IP address, the subnet masks,

54
00:02:57,630 --> 00:03:01,533
the default gateway, and
the DNS server information.

55
00:03:02,580 --> 00:03:07,413
So let's show two
examples of DHCP servers.

56
00:03:08,340 --> 00:03:10,320
First here, we have a basic router

57
00:03:10,320 --> 00:03:13,590
and I've gone to advanced,
and I've gone to network,

58
00:03:13,590 --> 00:03:15,240
and DHCP server.

59
00:03:15,240 --> 00:03:18,330
And you can see that the
DHCP server is on right now,

60
00:03:18,330 --> 00:03:19,800
it is enabled.

61
00:03:19,800 --> 00:03:22,350
And we have an IP address Pool,

62
00:03:22,350 --> 00:03:24,630
otherwise known as a scope.

63
00:03:24,630 --> 00:03:27,600
And this server will hand out IP addresses

64
00:03:27,600 --> 00:03:32,600
to clients automatically
between 10.252.0.2

65
00:03:32,670 --> 00:03:37,050
and 10.252.255.254.

66
00:03:37,050 --> 00:03:41,730
And so this device is considered
to be the gateway .101.

67
00:03:43,230 --> 00:03:46,560
We don't have DNS servers
placed in here, so by default

68
00:03:46,560 --> 00:03:50,460
this would forward DNS
requests out to the internet.

69
00:03:50,460 --> 00:03:54,243
So it would be 101 automatically
at the client side.

70
00:03:55,410 --> 00:03:57,840
Now let's take a look at
another type of server.

71
00:03:57,840 --> 00:04:01,710
This is server 2012 that I have running.

72
00:04:01,710 --> 00:04:05,370
And I've set this up as a DHCP server

73
00:04:05,370 --> 00:04:10,350
which you have to add as
a role to Windows Server.

74
00:04:10,350 --> 00:04:14,130
So I've added that and
I'm in the DHCP console.

75
00:04:14,130 --> 00:04:19,130
And then within IPv4 and IPv6
you would create a new scope,

76
00:04:19,860 --> 00:04:23,010
which is a Pool of IP addresses.

77
00:04:23,010 --> 00:04:24,813
And so I've created that here,

78
00:04:26,220 --> 00:04:31,220
and we have 10.1.1.1. through 10.1.200.254

79
00:04:31,770 --> 00:04:34,623
using a 255.255 subnet mask.

80
00:04:35,730 --> 00:04:39,840
This is where you'd go to
create this scope of information

81
00:04:39,840 --> 00:04:42,900
and we'd add additional info,
like the gateway address

82
00:04:42,900 --> 00:04:45,000
and who the DNS server is.

83
00:04:45,000 --> 00:04:49,320
We do all that here, create
that scope, activate the scope

84
00:04:49,320 --> 00:04:51,540
and then authorize the server.

85
00:04:51,540 --> 00:04:56,540
And you wanna see a green
arrow pointing up on the server

86
00:04:56,580 --> 00:05:00,150
and on the scope to make sure
then verify that you know

87
00:05:00,150 --> 00:05:02,343
that your server is running properly.

88
00:05:03,210 --> 00:05:08,210
So two examples of servers there for DHCP.

89
00:05:08,498 --> 00:05:11,520
Now DHCP uses a four step process

90
00:05:11,520 --> 00:05:14,040
that we discussed in other videos,

91
00:05:14,040 --> 00:05:18,420
and that's called Dora,
D-O-R-A, which stands for

92
00:05:18,420 --> 00:05:23,370
Discover, Offer, Request,
and Acknowledgement.

93
00:05:23,370 --> 00:05:24,630
And that's generally what happens

94
00:05:24,630 --> 00:05:27,390
between clients and the server.

95
00:05:27,390 --> 00:05:31,740
The client will not have an IP
address and you might plug it

96
00:05:31,740 --> 00:05:34,920
into the network or enable
the wireless adapter

97
00:05:34,920 --> 00:05:36,930
and it'll look out to the network

98
00:05:36,930 --> 00:05:41,100
if it's set to obtain IP
addresses automatically.

99
00:05:41,100 --> 00:05:45,570
It'll look out to the network
to find a DHCP server.

100
00:05:45,570 --> 00:05:49,863
And that's part of the discovery
phase, that D within Dora.

101
00:05:52,260 --> 00:05:56,850
Once it finds one, the
server will have an offering.

102
00:05:56,850 --> 00:06:01,260
It'll do an offering to
the client of IP addresses.

103
00:06:01,260 --> 00:06:03,630
The client will request
one, quote/unquote,

104
00:06:03,630 --> 00:06:05,160
it'll request an IP address,

105
00:06:05,160 --> 00:06:09,180
which is really one that the
DHCP server decides for it.

106
00:06:09,180 --> 00:06:13,110
And if that's available and
the client meets the criteria

107
00:06:13,110 --> 00:06:16,770
the DHCP server will acknowledge that

108
00:06:16,770 --> 00:06:20,040
and the client can start
using that IP address.

109
00:06:20,040 --> 00:06:23,430
So that's the four step
process known as Dora.

110
00:06:23,430 --> 00:06:25,920
And that's a little
bit about DHCP servers.

111
00:06:25,920 --> 00:06:28,170
Remember they could be on the LAN

112
00:06:28,170 --> 00:06:30,300
handing out IPS to all the clients,

113
00:06:30,300 --> 00:06:33,240
or they could be out on the internet,

114
00:06:33,240 --> 00:06:37,320
handing out an IP address
that's publicly used to say

115
00:06:37,320 --> 00:06:40,920
your router or whatever
device that publicly

116
00:06:40,920 --> 00:06:44,343
faces the internet and allows
access out to the internet.

117
00:06:47,310 --> 00:06:52,310
Now, the domain name
system, or DNS server,

118
00:06:52,500 --> 00:06:57,150
resolves domain names to IP addresses.

119
00:06:57,150 --> 00:07:00,330
DNS is a system that
could be run on your LAN

120
00:07:00,330 --> 00:07:04,080
as part of your Windows
domain, but it is also

121
00:07:04,080 --> 00:07:08,430
a worldwide system that
translates all website

122
00:07:08,430 --> 00:07:13,080
domain names into their
corresponding IP addresses.

123
00:07:13,080 --> 00:07:15,600
So DNS servers could be on the LAN.

124
00:07:15,600 --> 00:07:19,230
They could be on the DMZ and
they're all over the internet.

125
00:07:19,230 --> 00:07:24,090
There's a whole hierarchy of
DNS servers around the world.

126
00:07:24,090 --> 00:07:28,110
Where your organization
places a DNS server

127
00:07:28,110 --> 00:07:30,930
will depend on several factors,

128
00:07:30,930 --> 00:07:35,400
namely what kind of other servers you have

129
00:07:35,400 --> 00:07:38,763
and who needs to access
them and from where.

130
00:07:39,900 --> 00:07:43,860
So for example, here, we have a DNS server

131
00:07:43,860 --> 00:07:48,860
in our local area network,
and that's possible.

132
00:07:49,380 --> 00:07:50,460
You might have this,

133
00:07:50,460 --> 00:07:53,400
especially if you have
an authentication server,

134
00:07:53,400 --> 00:07:55,950
if you're running say a Windows domain

135
00:07:55,950 --> 00:07:59,340
which we'll talk about
in a following video.

136
00:07:59,340 --> 00:08:02,160
And that would take care
of the name resolution

137
00:08:02,160 --> 00:08:06,723
for all the domain
information on your LAN.

138
00:08:07,680 --> 00:08:10,440
So that runs in conjunction, in concert,

139
00:08:10,440 --> 00:08:15,390
with the domain server, with
that authentication server.

140
00:08:15,390 --> 00:08:19,440
But they can also exist,
as say part of the DMZ,

141
00:08:19,440 --> 00:08:20,670
or on the internet.

142
00:08:20,670 --> 00:08:23,010
And they do the same thing.

143
00:08:23,010 --> 00:08:26,880
They're gonna resolve domain
names to IP addresses.

144
00:08:26,880 --> 00:08:31,080
So if a client wants to say, a
client that's on the internet

145
00:08:31,080 --> 00:08:33,033
wants to go to this web server here,

146
00:08:34,770 --> 00:08:37,260
that client might know the domain name,

147
00:08:37,260 --> 00:08:39,810
but they're probably not
gonna know the IP address,

148
00:08:39,810 --> 00:08:42,720
and that's how computers
communicate with each other.

149
00:08:42,720 --> 00:08:46,800
So the DNS server is
gonna be needed to resolve

150
00:08:46,800 --> 00:08:50,250
that domain name to IP,
to allow that connectivity

151
00:08:50,250 --> 00:08:51,960
between the web server and the client,

152
00:08:51,960 --> 00:08:53,960
wherever that client is on the internet.

153
00:08:55,980 --> 00:08:59,700
So you might have these DNS
servers just about anywhere.

154
00:08:59,700 --> 00:09:02,310
And again, there's a
whole hierarchy of these

155
00:09:02,310 --> 00:09:04,050
around the world.

156
00:09:04,050 --> 00:09:09,050
When you go to the internet
and try to connect to a domain

157
00:09:09,060 --> 00:09:12,210
it's gonna go to the initial DNS server.

158
00:09:12,210 --> 00:09:14,910
Let's show another example here.

159
00:09:14,910 --> 00:09:17,700
Okay, this is my Windows 10 system here.

160
00:09:17,700 --> 00:09:22,223
And so here we'll do another ipconfig/all.

161
00:09:24,360 --> 00:09:26,910
We get lots of information here

162
00:09:26,910 --> 00:09:29,460
and let's take a look at this,

163
00:09:29,460 --> 00:09:32,220
the main network ethernet adapter.

164
00:09:32,220 --> 00:09:34,170
This one's not using DHCP.

165
00:09:34,170 --> 00:09:37,320
I've statically configured the IP address.

166
00:09:37,320 --> 00:09:39,660
And when that's the case,

167
00:09:39,660 --> 00:09:41,760
we have to statically
configure everything else,

168
00:09:41,760 --> 00:09:44,100
the subnet mask, the gateway we're using

169
00:09:44,100 --> 00:09:45,660
and the DNS server.

170
00:09:45,660 --> 00:09:47,400
Now the DNS server is the gateway,

171
00:09:47,400 --> 00:09:50,100
it's the SOHO router that I'm using.

172
00:09:50,100 --> 00:09:54,580
But that gateway is gonna have
to look out to the internet

173
00:09:55,680 --> 00:10:00,660
to another DNS server when I
try to connect to domain names.

174
00:10:00,660 --> 00:10:03,660
So for example, if we were to do a ping

175
00:10:03,660 --> 00:10:07,710
to something like
example.com, my SOHO router

176
00:10:07,710 --> 00:10:10,650
is not gonna know the IP
address of example.com.

177
00:10:10,650 --> 00:10:13,560
It's gonna have to look
out to the DNS server.

178
00:10:13,560 --> 00:10:16,200
And the first place
it'll go to look for that

179
00:10:16,200 --> 00:10:19,650
is at my ISP, at my
internet service provider,

180
00:10:19,650 --> 00:10:23,733
their in-house DNS server or DNS servers.

181
00:10:24,750 --> 00:10:28,200
Hopefully they'll come back
with the IP address for that.

182
00:10:28,200 --> 00:10:30,810
And I just did a quick ping to show this.

183
00:10:30,810 --> 00:10:34,740
So example.com is using
this IP address right now.

184
00:10:34,740 --> 00:10:38,460
But it could be that they
don't know that server

185
00:10:38,460 --> 00:10:40,260
or maybe they know this server

186
00:10:40,260 --> 00:10:44,220
but the DNS servers at my
ISP don't know other servers.

187
00:10:44,220 --> 00:10:48,000
So for example, I could
do ping davidlprouse.com,

188
00:10:48,000 --> 00:10:50,970
maybe they don't know
that domain right now.

189
00:10:50,970 --> 00:10:54,030
They should by now, but
let's say they don't.

190
00:10:54,030 --> 00:10:57,390
Then that DNS server at
my IP would have to go out

191
00:10:57,390 --> 00:11:01,440
to another higher level DNS server

192
00:11:01,440 --> 00:11:03,750
somewhere else in the country.

193
00:11:03,750 --> 00:11:06,093
And if you want to connect
to other countries,

194
00:11:06,990 --> 00:11:10,920
your local DNS server would
forward the DNS requests

195
00:11:10,920 --> 00:11:14,100
to those other countries' DNS servers,

196
00:11:14,100 --> 00:11:19,100
and ultimately get the
IP address that you need.

197
00:11:20,160 --> 00:11:22,080
And whenever you're connecting
with your web browser

198
00:11:22,080 --> 00:11:23,430
that's actually what's happening.

199
00:11:23,430 --> 00:11:25,590
The IP address of your local computer

200
00:11:25,590 --> 00:11:29,520
or your SOHO router will
connect out to that IP address

201
00:11:29,520 --> 00:11:32,493
and they communicate directly via IP.

202
00:11:33,600 --> 00:11:37,500
Let's go back to our Server 2012 here

203
00:11:37,500 --> 00:11:41,340
and I'm going to go to the DNS manager.

204
00:11:41,340 --> 00:11:45,720
Now, well, first we'll go to
the Server Manager Dashboard.

205
00:11:45,720 --> 00:11:49,050
Now this particular server started

206
00:11:49,050 --> 00:11:53,730
as a basic file and
storage services server,

207
00:11:53,730 --> 00:11:56,670
but then I wanted to promote
it to a domain controller

208
00:11:56,670 --> 00:11:58,950
to become an authentication server.

209
00:11:58,950 --> 00:12:03,630
So we installed active
directory domain services.

210
00:12:03,630 --> 00:12:08,520
And to do that, we have to
point to some DNS server

211
00:12:08,520 --> 00:12:11,730
either a separate box,
or you could install it

212
00:12:11,730 --> 00:12:13,830
at this same server, which is what I did.

213
00:12:13,830 --> 00:12:15,930
I installed DNS here
and it's up and running.

214
00:12:15,930 --> 00:12:17,703
We got the green arrow pointing up.

215
00:12:18,600 --> 00:12:22,470
So that is running and to work with that,

216
00:12:22,470 --> 00:12:26,013
you can work within the
DNS manager console.

217
00:12:27,150 --> 00:12:31,080
And you can see here, we have
DNS and we have this computer.

218
00:12:31,080 --> 00:12:34,950
This is the fully qualified
domain name for this server.

219
00:12:34,950 --> 00:12:38,280
It's dc1, that's the name of the computer.

220
00:12:38,280 --> 00:12:41,100
The domain is dpro 42.com,

221
00:12:41,100 --> 00:12:44,913
which I selected when I installed DNS.

222
00:12:47,070 --> 00:12:50,550
And if we look here, we'll
see the forward lookup zones,

223
00:12:50,550 --> 00:12:55,230
and we have dpro42.com, and
you can see the resolutions

224
00:12:55,230 --> 00:12:57,450
that can be made from this computer,

225
00:12:57,450 --> 00:13:02,450
dc1 is also known as 10.252.0.103 and .105

226
00:13:03,635 --> 00:13:06,240
'cause it's a multi-homed server.

227
00:13:06,240 --> 00:13:09,120
And then other computers that connect,

228
00:13:09,120 --> 00:13:11,490
like say the Windows 10 laptop 1

229
00:13:11,490 --> 00:13:14,100
that we've connected to before

230
00:13:14,100 --> 00:13:17,250
that name will also
resolve to its IP address

231
00:13:17,250 --> 00:13:19,320
and that'll be added to the DNS manager.

232
00:13:19,320 --> 00:13:22,470
So anything that deals with this domain

233
00:13:22,470 --> 00:13:25,950
and all the post names within the domain

234
00:13:25,950 --> 00:13:28,983
will get added to this
forward lookup zone.

235
00:13:29,910 --> 00:13:33,270
And DNS can work in reverse as well.

236
00:13:33,270 --> 00:13:38,270
It can resolve from IP
address to domain name, right.

237
00:13:39,120 --> 00:13:42,480
So you have both of those
functions within DNS.

238
00:13:42,480 --> 00:13:45,150
And this is running within Server 2012.

239
00:13:45,150 --> 00:13:47,730
And this is one example of a DNS server

240
00:13:47,730 --> 00:13:51,060
that does this name resolution.

241
00:13:51,060 --> 00:13:54,210
Okay, so we have the DNS
servers here on the LAN

242
00:13:54,210 --> 00:13:56,760
and that's common if you have a domain

243
00:13:56,760 --> 00:13:59,730
and we'll talk more about that
with authentication servers.

244
00:13:59,730 --> 00:14:02,730
But more often what you're
looking at is the DNS server

245
00:14:02,730 --> 00:14:05,550
out on the internet, or on your DMZ,

246
00:14:05,550 --> 00:14:09,210
which takes care of the
resolutions between domain names

247
00:14:09,210 --> 00:14:11,640
and IP addresses,
especially for web servers

248
00:14:11,640 --> 00:14:14,790
but just about any
other servers out there.

249
00:14:14,790 --> 00:14:18,540
So you wanna know your DHCP
and your DNS functionality

250
00:14:18,540 --> 00:14:20,490
and the servers and where they might be

251
00:14:20,490 --> 00:14:25,490
and what they can do, DHCP
and DNS servers do things

252
00:14:25,530 --> 00:14:28,140
that happen behind the scenes,

253
00:14:28,140 --> 00:14:31,053
even more so than your typical server.

254
00:14:31,980 --> 00:14:36,570
Nevertheless, they are
vital to a network's smooth

255
00:14:36,570 --> 00:14:38,733
and automated operation.
