Re: Trust between two Forests Fail




"John Kolodziejski" <John Kolodziejski@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message news:85296541-7405-43AD-837F-25CD657B09E5@xxxxxxxxxxxxxxxx
I work for a company that has just been purchased by another company. As
per
Microsoft Technet "When to create a Forest Trust" a Forest trust fits
our
situation perfectly. We are attempting to create a Forest level-two-way
trust.
We have run the complete check list " Checklist: Creating a forest trust
".


Both companies are running only Windows 2003 Servers. Both Domain and
Forest
Functional Levels are set to the highest Level. Company A is running all
services under Windows Active Directory (DNS, WINS and so on), Company B
is
not running DNS under Windows Active Directory. They are using Linux.

While using non-Microsoft DNS is possible, the Microsoft DNS is almost
always superior to support AD domains and clients.

We have set up secondary zones in each DNS name space

Presumably you setup secondary DNS on each DNS server set for the OTHER
DNS (name tree). This is not however likely to be your problem unless they
have messed up the DYNAMIC DNS on their side.

.. and we have established Zone
transfers between our two DNS Servers. A DNS lookup does work for both
sides.

So everything for Forest B DNS can be found from Forest A DNS? And vice
versa?

When company A tries to complete a Forest Level Trust, the trust Wizard
works, and the trust is completed and shows on both active directories,
but
when a "Validate " is done on "Incoming" and "Out Going" we receive an
error.
"the Trust cannot be validated for the following reasons: The outgoing
trust

It seems that I MAY RECALL (very unconfirmed) that sometimes the "validate"
may be brokent with the trust working. Does it function? Is validate the
only
thing that gives errors?

was successfully validated. Secure channel (SC) reset on Domain Controller
\\x.companyBdomain.com of domain companyB.com to domain companyA.com
failed
with error. There are currently no logon servers available to service the
logon request.

Do all DCs in BOTH forests pass a complete "DCDiag /c" with NO FAIL or WARN
messages?

When company B tries to complete the trust wizard, they enter in our
company's domain name, and they get an error, "Domain not found".

You should carefully check the DNS resolution from that side to the other
resources.

We have search all over an only came up with a KB document that allies to
Windows NT 4 and earlier.


--
Herb Martin, MCSE, MVP
http://www.LearnQuick.Com
(phone on web site)


.



Relevant Pages

  • Re: Active Directory Restructure Question
    ... If you are building a new forest you can use the Active Directory ... To start would have to establish dns connectivity both ways, ... Once established you can then go and create your external trust, ... domains for your UNIX/LINUX servers, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Trust between two Forests Fail
    ... Microsoft Technet "When to create a Forest Trust" a Forest trust fits ... services under Windows Active Directory (DNS, WINS and so on), Company B ... Presumably you setup secondary DNS on each DNS server set for the OTHER ...
    (microsoft.public.windows.server.active_directory)
  • RE: Domain Trusts
    ... since forest trusts is not supported in pre-2003 modes. ... forest trust, make sure to initiate the trust wizard from Admin.local and not ... OS is server 2003 standard edition, the domain and forest function level is ... 2- Open the DNS console on the stdavids.local, go to the properties of the ...
    (microsoft.public.windows.server.active_directory)
  • RE: Two way forest trust fails only in one direction
    ... After deep research of the SMB signing, we saw that both servers need Reg Key: ... needed to match on both servers on both sides of the trust. ... B's Forest, but Company B can not access Company As forest at all. ... running DNS and WINS under Windows Active Directory. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Protected Forest with One Child domain
    ... The forest is in native mode. ... so your child DNS servers can resolve both their ... INTERNAL zone on every DNS server using AD-Integrated Forest ...
    (microsoft.public.windows.server.dns)

Loading