Trust Relationship between two W2k3 AD domains!


hello,

i've got 2 windows 2003 domains (labruh.com , labjed.com) want create 1 way trust between them i.e labruh.com must able authenticate in labjed.com (this way only).  ip configuration done , both domain controllers can ping each other.

what required steps in dns servers on both dcs? dns stub zone involved in here?

what steps involved in domains , trusts in both dcs?

appreciate tips!

 

you can create dns forwarders or allow zone transfers configure server allow zone , create secondary zone depending upon n/w bandwidth.
http://www.techrepublic.com/blog/window-on-windows/configuring-dns-forwarders-to-support-windows-server-2003-forest-trusts/501

both domain controllers must ping each other ip.proper routing necessary if resides in separate subnet
add dc1 secondary dns in tcp/ip property of dc2
add dc2 secondary dns in tcp/ip property of dc1
user account performing activity should have domain admin , enterprise admin rights.

ensure required ports are open.
http://support.microsoft.com/kb/17944

refer below link more details:
http://technet.microsoft.com/en-us/library/cc779045(ws.10).aspx
http://technet.microsoft.com/en-us/library/cc779840(ws.10).aspx
http://technet.microsoft.com/en-us/library/cc776940(ws.10).aspx


hope helps.

regards,
sandesh dubey.
-------------------------------
mcse|mcsa:messaging|mcts|mcitp:enterprise adminitrator
blog: http://sandeshdubey.wordpress.com
posting provided no warranties, , confers no rights.




Windows Server  >  Directory Services



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS