Re: Not able to establish trust with another window 2003 domain

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hi Guys,

Thank you for the information. I had tried the suggestions by you all guys
but no luck. All the result using the Port Query tools with the result on all
port is "listening" and "exit with return code 0x00000000. I assume all the
port is opened and working.

Also, i install a new server on each domain and try to create a DNS zone for
each of the domain. Then i try to establish the trust but still fail. I try
to create a secondary zone on the newly created DNS server and try to
establish the trust again but its still fail. I also try to create a Stub
zone for both domain and establish the trust again and still fail.
Conditional forwarding also try on both Domain DNS and trust still fail.

I had check with the network guy and all the port had been open up on the
firewall.

Is there anyway that I can try to do beside all these?

Thank you very much for the suggestions. Hope to hear more you all guys.

Thank you
Eng

"Jorge Silva" wrote:

Hi
Download port query and test the availabel ports for domain and trust
http://support.microsoft.com/kb/310099

--
I hope that the information above helps you

Good Luck
Jorge Silva
MCSA
Systems Administrator
"Eng" <Eng@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:EE9430A2-6132-40CC-8AF3-3E4DFB60B5D2@xxxxxxxxxxxxxxxx
Hi All,

I have a problem establish a trust with one of my domain. I have an
existing
windows 2003 domain call Source and I am planning for a migration. I setup
a
test Target domain,windows 2003 as well, call Target, to test the
migration.

I try to create/establish trust between this 2 domain but fail with the
following error :""The Local Secutiry Authority is unable to obtain an RPC
connection to the domain controller w2k3.source.local. Please check the
name
can be resolve and the server is available."

I had check the name resolution and its working. I had created conditional
forwarding but still fail. Also, I had edit the lmhost file on both Domain
PDC but its still fail. RPC server services on both domain is started.

I had perform the NLTEST and NSLOOKUP and comeback with a positive result.
nslookup -type=srv _ldap._tcp.pdc._msdcs.domain-name.com
nslookup -type=srv _ldap._tcp.dc._msdcs.domain-name.com
nltest /dsgetdc:domain-name.com
But I still not able to resolve this issue.

I had tried to create a secondary zone on each DNS on each domain but
still
fail to establish the trust. Which mean, on Source DNS, I created the
secondary zone of Target domain, and on Target domain DNS, I created a
secondary zone of Source domain.

Can anyone tell me what's wrong with my environment? Or something that I
can
do to resolve this issue?

Thank you

Eng



.



Relevant Pages

  • Re: Not able to establish trust with another window 2003 domain
    ... i had try to use your web tool to generate the syntax but still fail. ... I try to remove the trust that created at my Source and re-create again. ... Not the "Packet needs to be fragmented but DF set". ... size of the packets are too big for the routers and the routers are ...
    (microsoft.public.windows.server.active_directory)
  • RE: Trust relationship betwen Win2003 & WinNT 4.0 Server
    ... regarding the LSA RPC port and the NetLogon RPC port (and the other RPC ... The directions said that the registry settings were located in place X. ... "RPS.LOCAL" in the Trusting Domains section of the Trust Relationships ... from the Win2003 server I can ping qtech1 without issue. ...
    (microsoft.public.windows.server.dns)
  • Re: Not able to establish trust with another window 2003 domain
    ... size of the packets are too big for the routers and the routers are not ... The trust that I try to create is external trust. ... "Packet needs to be fragmented but DF set." ... Then i try to establish the trust but still fail. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Not able to establish trust with another window 2003 domain
    ... Not the "Packet needs to be fragmented but DF set". ... I try to use my target domain to create a trust to one of my ... establish a trust to my source, its fail. ... i install a new server on each domain and try to create a DNS ...
    (microsoft.public.windows.server.active_directory)
  • RE: Height of paranoia
    ... PC shutdown by 7pm, disabled the port, or firewall it. ... emails of other, unless the direction approves it" (patch it with a more ... "Everything that can fail, will fail. ... I am the security guy. ...
    (Security-Basics)