Re: Not able to establish trust with another window 2003 domain

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Hi Guys,

Thank you very much for the help. Its really help a lot.

Once again, thank you

Eng

"Paul Bergson [MVP-DS]" wrote:

Follow the troubleshooting tips from the article you listed, it is hard for
anyone to give much of an answer on something such as this.

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

"Eng" <Eng@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:795B1D25-1284-4F53-8666-4ECF174F32E4@xxxxxxxxxxxxxxxx
Hi Guys,

There is a new finding. I try to connect to the admin shared on both my
Source and my Target using command prompt, net use command, I can create
the
Trust. But I fail to verify the Trust and its give the same error, the RPC
service is not available.

I believe there is something that need to be done, perhap the permission
on
both side. I had check the RSop on both, the source and the target and
they
are same as stated in the KB article
http://support.microsoft.com/default.aspx/kb/889030/en-us.

Is there anything that I miss out? Could this be due to permission
problem?

Thank you

Eng

"Eng" wrote:

Hi All,

I have a problem establish a trust with one of my domain. I have an
existing
windows 2003 domain call Source and I am planning for a migration. I
setup a
test Target domain,windows 2003 as well, call Target, to test the
migration.

I try to create/establish trust between this 2 domain but fail with the
following error :""The Local Secutiry Authority is unable to obtain an
RPC
connection to the domain controller w2k3.source.local. Please check the
name
can be resolve and the server is available."

I had check the name resolution and its working. I had created
conditional
forwarding but still fail. Also, I had edit the lmhost file on both
Domain
PDC but its still fail. RPC server services on both domain is started.

I had perform the NLTEST and NSLOOKUP and comeback with a positive
result.
nslookup -type=srv _ldap._tcp.pdc._msdcs.domain-name.com
nslookup -type=srv _ldap._tcp.dc._msdcs.domain-name.com
nltest /dsgetdc:domain-name.com
But I still not able to resolve this issue.

I had tried to create a secondary zone on each DNS on each domain but
still
fail to establish the trust. Which mean, on Source DNS, I created the
secondary zone of Target domain, and on Target domain DNS, I created a
secondary zone of Source domain.

Can anyone tell me what's wrong with my environment? Or something that I
can
do to resolve this issue?

Thank you

Eng



.



Relevant Pages

  • Re: Not able to establish trust with another window 2003 domain
    ... Not the "Packet needs to be fragmented but DF set". ... I try to use my target domain to create a trust to one of my ... establish a trust to my source, its fail. ... i install a new server on each domain and try to create a DNS ...
    (microsoft.public.windows.server.active_directory)
  • Re: Not able to establish trust with another window 2003 domain
    ... Source and my Target using command prompt, net use command, I can create ... But I fail to verify the Trust and its give the same error, ... Which mean, on Source DNS, I created the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Not able to establish trust with another window 2003 domain
    ... i had try to use your web tool to generate the syntax but still fail. ... I try to remove the trust that created at my Source and re-create again. ... Not the "Packet needs to be fragmented but DF set". ... size of the packets are too big for the routers and the routers are ...
    (microsoft.public.windows.server.active_directory)
  • Re: Not able to establish trust with another window 2003 domain
    ... size of the packets are too big for the routers and the routers are not ... The trust that I try to create is external trust. ... "Packet needs to be fragmented but DF set." ... Then i try to establish the trust but still fail. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Not able to establish trust with another window 2003 domain
    ... All the result using the Port Query tools with the result on all ... Then i try to establish the trust but still fail. ... to create a secondary zone on the newly created DNS server and try to ...
    (microsoft.public.windows.server.active_directory)