Are you configuring forwarders within a regular zone or are you setting up a forwarding zone?

I believe the latter will accomplish what you want. 

On Tue, Oct 2, 2018, 1:02 AM TomK via FreeIPA-users <freeipa-users@lists.fedorahosted.org> wrote:
Hey All,

(Hopefully) a quick DNS Forwarding question.

My Windows DNS is authoritative on MY.DOM .  My IPA servers are
authoritative on NIX.MY.DOM .  Forwarding from the Windows DNS to the
IPA DNS servers seems to work just fine.  But not the other way despite
having the forwarder defined in IPA:

   Zone name: my.dom.
   Active zone: TRUE
   Zone forwarders: 192.168.0.224, 192.168.0.220, 192.168.0.221
   Forward policy: first

So when I list the IPA DNS servers in /etc/resolv.conf first, they won't
resolv on MY.DOM.  But if I place the Windows DNS server first
(192.168.0.224) then resolution on MY.DOM and NIX.MY.DOM work just fine.

Any hints to make the forwarder work on the IPA side?

--
Cheers,
Tom K.
-------------------------------------------------------------------------------------

Living on earth is expensive, but it includes a free trip around the sun.
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-leave@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org