Re: One Way Trust

anonymous_at_discussions.microsoft.com
Date: 09/20/04


Date: Mon, 20 Sep 2004 02:27:46 -0700

The secondary forward look up zone has been created on
both the sides for each repective domain. However, my
production domain has several domain controllers and I
have created a secondary forward lookup zone only on the
domain controller which is connected on the same LAN of
the development domain to which I am trying to establish
a outgoing one way external trust.

I am usig the AD domains and trusts from my XP desktop
where I have the Admin pack installed to create this
trust. My question is, do I have to use the AD domains
and trust from the production domain controller where
secondary forward lookup zone is running for the dev.
domain or I should be able to do it from any DC or from
my XP using Admin pack?

Pls clarify.

SV

>-----Original Message-----
>Hi SV-
>
>ICMP (PING) is not a requirement for a trust to work.
It can be a good
>indicator of general network viability between two
servers though.
>
>It doesn't sound like you have created secondary forward
lookup zones on
>boths sides for each respective domain. If you haven't
done that then I
>would suggest it. You would need to have good name
resolution both ways
>even if the trust is only one way.
>
>Please repost if we can help more with this.
>
>--
>Tim Springston
>Microsoft Corporation
>This posting is provided "AS IS" with no warranties, and
confers no rights.
>
>
>"SV" <anonymous@discussions.microsoft.com> wrote in
message
>news:07f501c49ca2$9315c910$a501280a@phx.gbl...
>>I am trying to setup a one way outgoing trust between my
>> production AD domain (ms.test.mydomain.com)and another
>> development AD domain (test.com). When I try this from
>> the production domain, I get an error that the
>> destination domain does not exist or network problem is
>> preventing connection. I am able to ping the
destination
>> domain's domain controller by its IP address. However,
I
>> can not ping the destination domain by its domain name
>> test.com.
>>
>> In one of the DCs in the production domain, I have
>> configured a secondary DNS for test.com and from that
>> particular DC I get a reply when I ping using its
domain
>> name (test.com). Will I be able to establish a trust
if I
>> use the AD domains and trust snap-in from the DC where
I
>> have a secondary DNS zone running for the
>> domain "test.com"?
>>
>> Any help would be very much appreciated.
>>
>> Thanks,
>>
>> SV
>
>
>.
>



Relevant Pages

  • Re: Very Critical issue
    ... Since that you're able to recreate the trust that means that the DC that was used to create the trust is able to communicate and validate the trust. ... are the clients using that same DC/DNS or are they querying a different DC/DNS that may has issues in their DNS secondary Zone? ... was at that time that the clients started with issues when trying to access to the other servers in the other forest? ...
    (microsoft.public.windows.server.active_directory)
  • DANGER ZONE: Internet Explorer
    ... This may be achieved with the Internet Explorer series of so- ... and trust, ... The so-called "Trusted Site" zone setting in the Internet Explorer ... For example, we input into the so-called Trusted Zone, the ...
    (NT-Bugtraq)
  • DANGER ZONE: Internet Explorer
    ... This may be achieved with the Internet Explorer series of so- ... and trust, ... The so-called "Trusted Site" zone setting in the Internet Explorer ... For example, we input into the so-called Trusted Zone, the ...
    (Bugtraq)
  • [Full-Disclosure] DANGER ZONE: Internet Explorer
    ... This may be achieved with the Internet Explorer series of so- ... and trust, ... The so-called "Trusted Site" zone setting in the Internet Explorer ... For example, we input into the so-called Trusted Zone, the ...
    (Full-Disclosure)
  • Re: Admin rights between one-way trusts
    ... Sandy Wood ... It's an 'incoming' trust from test to production. ... group into the test global domain admin group, ... Sounds like your production domain is the trusting domain? ...
    (microsoft.public.windows.server.active_directory)