Re: DMZ server and access to AD / Logon server
From: Glenn L (the.only_at_gmail.com)
Date: 10/20/04
- Next message: news.microsoft.com: "Custom MMC consoles"
- Previous message: Glenn L: "Re: 2003 Group Policies not applying to 2003"
- In reply to: Lasse Taul Bjerre: "DMZ server and access to AD / Logon server"
- Next in thread: Lasse Taul Bjerre: "Re: DMZ server and access to AD / Logon server"
- Reply: Lasse Taul Bjerre: "Re: DMZ server and access to AD / Logon server"
- Messages sorted by: [ date ] [ thread ]
Date: Wed, 20 Oct 2004 04:02:14 -0700
I'm no exchange guru, but I know you can specifiy the domain controllers you
want it to talk to on the DSACCESS tab of the server properties page.
Perhaps the old ones are specified, or you could configure the new ones, and
make sure you have host and lmhost entries for them.
I suspect Exchange needs access to DNS to enumerate all the GC records
before it will "discover" there existence.
Maybe you could temporarily open up TCP port 53 and allow that discovery to
take place, then close the hole, unplug the old DCs from the network and see
what happens.
-- Glenn L CCNA, MCSE 2000, MCSE 2003 + Security "Lasse Taul Bjerre" <LasseTaulBjerre@discussions.microsoft.com> wrote in message news:46B3547B-1238-40DA-8628-7658E0D6630B@microsoft.com... > HI, > > We are in the process of moving our system to 2003 from win2K. > I've moved my 2 Domain Controllers to 2 new 2003 servers, the 2 old win2K > Domain Ccontrollers are still running, but all the rolls are moved to the new > servers. > > The servers on LAN side use the new domain controllers as logon servers - no > problems. > > In a DMZ zone we have an Exchange 2003 FrontEnd. It works, but persists to > use the old Domain Controllers as logon serves. > Since the server in the DMZ cannot get the correct IP via DNS we use host > and lmhost files for that. > > I'm now planning to remove the old Win2K Domain Controllers, but can't > because of the DMZ server. > > To make sure there are no conflicting firewall rules, I've for test purposes > enabled all traffic between the DMZ (Exchange Frontend) and the LAN side > Exchange and the 2 Win2K3 Domain Controllers. > > Any good ideas why the DMZ server won't use the new Win2K3 Domain Controllers? > > Lasse
- Next message: news.microsoft.com: "Custom MMC consoles"
- Previous message: Glenn L: "Re: 2003 Group Policies not applying to 2003"
- In reply to: Lasse Taul Bjerre: "DMZ server and access to AD / Logon server"
- Next in thread: Lasse Taul Bjerre: "Re: DMZ server and access to AD / Logon server"
- Reply: Lasse Taul Bjerre: "Re: DMZ server and access to AD / Logon server"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|