IPA should support BIND forward zones, conditional forwarding based on the domain suffix of the name trying to be resolved, in addition to the global forwarders that it already supports
For example, all records that end with
someDomain.example.com forwarded to 10.0.0.1
It would be nice to be able to prioritize forwarding. Global forwarders and conditional forwarders could be ranked in a list box like
someDomain.example.com -> 10.0.0.1 (conditional Forwarder)
* -> 192.168.1.1 (Global Forwarder)
from BIND manual:
A "forward zone" is a way to configure forwarding on a per-domain basis. A zone statement of type forward can contain a forward and/or forwarders statement, which will apply to queries within the domain given by the zone name. If no forwarders statement is present or an empty list for forwarders is given, then no forwarding will be done for the domain, canceling the effects of any forwarders in the options statement. Thus if you want to use this type of zone to change the behavior of the global forward option (that is, "forward first to", then "forward only", or vice versa, but want to use the same servers as set globally) you need to respecify the global forwarders.
Technical note added. If any revisions are required, please edit the "Technical Notes" field
accordingly. All revisions will be proofread by the Engineering Content Services team.
Cause: IPA server does not allow to create DNS zones with conditional forwarding which lets the name server to forward all request to these zones to a custom forwarder.
Consequence: IPA DNS plugin has a limited capability in a conditional forwarding support compared with plain text files.
Change: IPA DNS plugin now allows user to create a DNS zone and set a conditional forwarder and a forwarding policy for the zone.
Result: User can create conditionally forwarded zones both with a plain text configuration and IPA configuration stored in LDAP server.
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.