I have four Windows 2008 R2 domain controllers, each a primary DNS server. All have high bandwidth connections. Currently only DC1 has "Allow Zone Transfers" enabled, and only on one Forward Lookup zone (our main domain name). DC2-4 do not have Zone Transfers enabled.
First, should Zone Transfers be enabled on all Forward Lookup zones? What about Reverse Lookup Zones?
Second, should each DC/DNS server also have Zone Transfers enabled on all the Forward or Reverse zones?
Thanks!