Re: trust forests without trusts



we have a VPN between 2 checkpoint boxes, NAT is running on the checkpoint
boxes to hide the internal network address because of conflicts. I called
PSS and they couldn't get it to work either and said it's not supported.
Problem is DNS related, if I lookup the external domain into, I can contact
the domain thru the NAT address but AD responds with the real IP and thus
fails to work


"Ace Fekay [MVP]" <PleaseAskMe@xxxxxxxxxxxxxx> wrote in message
news:edHukEwbGHA.628@xxxxxxxxxxxxxxxxxxxxxxx
In news:u1oDNDvbGHA.536@xxxxxxxxxxxxxxxxxxxx,
John M <sdkfj@xxxxxxxxxxxxx> stated, which I commented on below:
Is there some product that will basically take over a trust role? I
have external forests that I want to assign resources to. Because we
use NAT between the two forests, I can't setup a trust. Is there
something else I can do? If this product could also sync the GAL
from exchange that would be great.

thanks
John

You can create a trust between two NAT networks if your create a VPN with
the endpoints being the NAT routers, such as if they were PIX boxes on
each end, create a tunnel between them allowing unhindered access to each
others' subnets. This is normally done with many companies with multiple
remote locations/offices. If it is a partner organization or business
partner, you will need to sit down with them and explain what you want and
come up with a solution, possibly hiring a consultant who is familiar with
this very common procedure.

There are 3rd party tools, such as SimpleSync, to sync up different orgs,
but they still require full network access because of authentication and
communication, etc, because NAT does not translate Kerberos, NTLM, LDAP or
RPC traffic.


--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Having difficulty reading or finding responses to your post?
Instead of the website you're using, I suggest to use OEx (Outlook Express
or any other newsreader), and configure a news account, pointing to
news.microsoft.com. This is a direct link to the Microsoft Public
Newsgroups. It is FREE and requires NO ISP's Usenet account. OEx allows
you to easily find, track threads, cross-post, sort by date, poster's
name, watched threads or subject.

It's easy:
How to Configure OEx for Internet News
http://support.microsoft.com/?id=171164

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft MVP - Directory Services
Microsoft Certified Trainer

Infinite Diversities in Infinite Combinations
Assimilation Imminent. Resistance is Futile
"Very funny Scotty. Now, beam down my clothes."

The only thing in life is change. Anything more is a blackhole consuming
unnecessary energy. - [Me]



.



Relevant Pages

  • Re: XP Home: selective folder sharing
    ... >same would hold for any wireless connection. ... Explaining bridges vs NAT is not easy. ... network are visible to all other components on each network. ... With a bridge (if Falcon-II is providing one), ...
    (microsoft.public.windowsxp.network_web)
  • Re: XP Home: selective folder sharing
    ... > Explaining bridges vs NAT is not easy. ... > network are visible to all other components on each network. ... > With a bridge (if Falcon-II is providing one), ... > For protection inside the NAT router, ...
    (microsoft.public.windowsxp.network_web)
  • Re: [9fans] Do we have a catalog of 9P servers?
    ... I believe state information and communication buffers are the biggest memory spending for network operations. ... There _could_ be a trade-off between the transient NAT with its processing power toll and the persistent /net-import with its memory cost. ... By contrast, on a large network /net-import strategy could make a "powerful" gateway unavoidable because every machine on the network will need a session with the gateway even if it only rarely communicates with the outside world, unless you implement an ... Or is it because Plan 9 has much less inertia because of a smaller user base? ...
    (comp.os.plan9)
  • Re: [9fans] Do we have a catalog of 9P servers?
    ... network layer data units, ergo, NAT again. ... The "packet ...
    (comp.os.plan9)
  • Re: AD/DNS with NAT
    ... his entire network is based on a private range. ... Datacenters host servers as Domain Controllers AD2003, DNS, Exchange ... every small offices to use NAT in order to keep the private IP range ...
    (microsoft.public.windows.server.networking)

Loading