Re: Permissions with Trusts

From: ptwilliams (ptw2001_at_hotmail.com)
Date: 09/08/04


Date: Wed, 8 Sep 2004 21:08:10 +0100

Where's the nearest GC? If these domains are in the same forest, a local
(to the site) GC is very much needed. If these domains reside in different
forests, then it is almost certainly a name resolution problem. Do all
clients point to the same DNS servers? Are some DNS servers setup as
forwards and others not? Is the IM down (if same forest and not all DCs are
GCs)? Have you had any replication issues?

If you don't have a copy of their DNS on your side, I assume you're
forwarding across to them?!?

Can you try and provide a little more background to the domains and sites
please? What versions of Windows? What modes are the Directory's running
in, etc.?

-- 
Paul Williams
_________________________________________
 http://www.msresource.net
Join us in our new forums!
  http://forums.msresource.net
_________________________________________
"Arc J. Thames" <revarcjt@hotmail.com> wrote in message
news:%23wOWdcblEHA.2864@TK2MSFTNGP14.phx.gbl...
Gotta be something other then SRV records because on some servers I can
connect to it and we have none of their SRV records on our side.
Arc
"ptwilliams" <ptw2001@hotmail.com> wrote in message
news:%23a97G5RlEHA.208@TK2MSFTNGP12.phx.gbl...
> Sounds like a name resolution problem.
>
> How did you configure the zones?  One way is to hold a secondary copy of
> DOM1 in DOM2 and vice-versa.  You shouldn't really create the SRV records
> manually if you're not using BIND -let Windows do it - less room for
error.
> Restarting netlogon will create the appropriate SRV records, providing the
> DHCP client service is running -even though you're not a DHCP client!
>
>
> -- 
>
> Paul Williams
> _________________________________________
>  http://www.msresource.net
>
>
> Join us in our new forums!
>   http://forums.msresource.net
> _________________________________________
>
>
> "Arc J. Thames" <revarcjt@hotmail.com> wrote in message
> news:uQDtkvRlEHA.952@TK2MSFTNGP14.phx.gbl...
> PS...It says "The server is not operational"
> "Arc J. Thames" <revarcjt@hotmail.com> wrote in message
> news:eiNJKrRlEHA.1152@TK2MSFTNGP11.phx.gbl...
> > I am trying to set up permissions between our company and one of our
> sister
> > companies.  When trying to assign permissions to resources in my domain,
> > giving the sister company permissions to our resources, their domain
name
> > shows up in the list but when you click on it...it searches for a little
> bit
> > and then then says the domain can not be contacted.  I can ping all of
> their
> > DC's and I can view the accounts when trying to assign permissions from
> one
> > of my domain controllers but not from anyother server.  I have tried
> > creating a zone in DNS and also tried created domain records in DNS, no
> luck
> > yet. Anyone had this problem/know what to do?
> >
> >
> > Arc
> >
> >
>
>
>


Relevant Pages

  • Re: Protected Forest with One Child domain
    ... All servers are Win2K3. ... The forest is in native mode. ... I have setup my child domains to conditionally forward to the forest domain ... I can click on the root of the forest (in dns) and then ...
    (microsoft.public.windows.server.dns)
  • Re: Forward lookup zone not automatically created for new domain in fo
    ... Company.biz is the forest root. ... forward lookup zones on the domain controllers hosting shell.company. ... You need your DNS servers in every domain/tree ... servers are Win2003 you can do forest wide AD Integration ...
    (microsoft.public.windows.server.active_directory)
  • Re: Forward Lookup Zone missing when new tree added to forest
    ... I have a forest with three domains that are in separate trees: ... DNS is Active Directory-Integrated. ... to 'only to servers listed on the Name Servers tab'. ... shell.company domain forward lookup zone. ...
    (microsoft.public.windows.server.dns)
  • Forward Lookup Zone missing when new tree added to forest
    ... Company.biz is the forest root. ... DNS is Active Directory-Integrated. ... servers listed on the Name Servers tab'. ... Starting test: CrossRefValidation ...
    (microsoft.public.windows.server.dns)
  • Forward lookup zone not automatically created for new domain in fo
    ... Company.biz is the forest root. ... DNS is Active Directory-Integrated. ... servers listed on the Name Servers tab'. ... Starting test: CrossRefValidation ...
    (microsoft.public.windows.server.active_directory)

Loading