Re: Multiple Forest woes . . .

Tech-Archive recommends: Fix windows errors by optimizing your registry



Your computer can only be a member of one domain. Simply creating a
computer object in the internal domain isn't going to help. On your
workstation, disjoin from the domain (the same way you add) by dropping into
a workgroup and rebooting. Then change the TCP/IP settings so that you are
pointing to the internal DC for DNS and join to the internal domain.

Now create a trust on the internal domain to the external domain. If both
trusts created successfully (int trusts ext and is also trusted by ex and
vice-versa) then you will see both domains available in the Winlogon
dropdown. You will need an account (user or inetorgperson) in each domain
if you wish to logon to either domain.

Personally, I would configure each DNS server to forward to the ISP. If you
have 2003, you should conditionally forward to the other domain. If not,
you will need a secondary zone for the opposite domain on each DC.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net


.



Relevant Pages

  • Re: Kerberos Event ID 4
    ... > Our internal network has a 2000 DNS server. ... > Client Realm: ... > Error Data is in record data. ... > internal domain name is pai.com. ...
    (microsoft.public.win2000.security)
  • Re: DNS and Host File
    ... Would implemention another dns server work. ... the internal domain name is the same as the public domain. ... This is what I was afraid of, unfortunately, the hosts file is going to be ...
    (microsoft.public.windows.server.dns)
  • Re: Changed hosting company
    ... > However we use .local for our internal domain and .com for external. ... Do you have a zone in your internal DNS server for the public domain? ... is the record in the DNS server cache? ...
    (microsoft.public.win2000.dns)
  • Re: Newbie: DNS problem
    ... Do you have an internal domain defined for scholasticfundinggroup.com? ... external DNS servers. ... internal DNS server resolves epcs.scholasticfundinggroup.com to ... I don't know why DNS server can't update itself. ...
    (microsoft.public.win2000.dns)
  • Re: Cant get to our own website
    ... Is your Internal domain name the same as your real Internet Domain Name? ... may have to add a www record in your DNS server for this site. ... > Our internal Win2k DNS servers are configured as forwarders. ...
    (microsoft.public.win2000.dns)