RE: Guidence required in the low level workings of Domain Trusts



Well I shouldn't have any trouble sleeping tonight ;-)

Everything is working fine with the trust and DNS but that doesn't mean it
can't work better. Just trying to get into the nuts and bolts of it.

Thanks

"Greg" wrote:

I once read that 80% of Active Directory problems are DNS related and
experience has proven that to be true. I highly recommend that you spend
some time making sure DNS is working properly in your environment. That
being said, you asked for some documentation so here you go. Not trying to
bury you in books but there really is a lot of good info here.

Understanding Logon and Authentication
http://technet.microsoft.com/en-us/library/bb457114.aspx

How to optimize pass-through authentication of user accounts after you
create an external trust between two Microsoft Windows Server 2003 Service
Pack 1 (SP1)-based forests
http://support.microsoft.com/kb/916474

How Domain Controllers Are Located in Windows
http://support.microsoft.com/kb/247811

How to optimize the location of a domain controller or global catalog that
resides outside of a client's site
http://support.microsoft.com/kb/306602

How DNS Support for Active Directory Works
http://technet2.microsoft.com/windowsserver/en/library/9d62e91d-75c3-4a77-ae93-a8804e9ff2a11033.mspx?mfr=true

Windows 2000 Startup and Logon Traffic Analysis
http://technet.microsoft.com/en-us/library/bb742590.aspx

Global Catalog Tools and Settings
http://technet2.microsoft.com/windowsserver/en/library/0d34c3b9-499b-41d3-a55f-527ce61e78581033.mspx?mfr=true

Name Resolution
http://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/distrib/dsbi_add_xvuo.mspx?mfr=true




Best Regards,
Greg



"Dysan" wrote:

Hi all,

I was hoping someone would be able to either point me in the direction of
some good documentation that will cover this or be able to explain (Google is
failing me).

I'm trying to find out how (step by step) if possible how user
authentication takes place across an external trust in a Windows 2003 AD
environment. I'll briefly explain the environment.

We have two organisations 1 has a domain within a larger forest that is part
of another organisation and is both Windows 2003 domain and forest functional
level. The 2nd organisation has its own forest with 1 domain and is Windows
2000 native. Both organisations are multi-site and have domain controllers
across some of these sites and are joined by a private pipe which has a
firewall at each end. We have an external trust in place between the 2
domains that is functioning no problem.

If a user from one organisation logs into a machine at the other
organisation which domain controller at the users home organisation is going
to process the authentication request? At the moment it seems to be randon
i.e. which ever one it gets out of DNS first.

I am trying to concentration the trust authentications to just the domain
controllers residing in the sites that have the joining connection instead of
authentication traffic bouncing all over the WAN.

Will adding remote subnets into Sites and Services and attaching to a dc
have any impact?

Also I believe the process can change depending on the authentication type,
if kerberos fails then NTLM uses a different technique.

Can anyone help me out on this?

Thanks
.



Relevant Pages

  • RE: Trust between two Forests Fail
    ... WINS AND DNS are working. ... "THE trust has been validated. ... I can access their Active Directory from my side and can nodify users (using ... Niether side can see the other sides Donain in Windows Explorer " Network ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain Admin Access across Trusted domains
    ... You may have a DNS issue. ... not attempting to next externals into your globals. ... Microsoft MVP (Windows Security) ... > The trust is a two way external trust. ...
    (microsoft.public.win2000.security)
  • RE: Guidence required in the low level workings of Domain Trusts
    ... some time making sure DNS is working properly in your environment. ... How to optimize pass-through authentication of user accounts after you ... How Domain Controllers Are Located in Windows ...
    (microsoft.public.windows.server.active_directory)
  • Re: Datadomain Windows 2008 DC
    ... I recall when we established a trust between NT4 and 2003 we had to loosen some of our authentication protocols. ... It may require the use of the older LMHash storage as opposed to the Windows Hash. ... DC1 and now when i run netdiag, i do not get DNS errors, ... Please describe more details about datadomain and the integration ...
    (microsoft.public.windows.server.active_directory)
  • Re: Datadomain Windows 2008 DC
    ... yep i agree as well, i wont know what is causing this issue until i talk to support at datadomain, unfortunetly i am not the storage admin and i dont have access to the device, so i am doing what i can from an AD side to try and figure this out. ... I am willing to detune SMB on one of the 2008 DC's but i want to make sure this setting doesnt negetively effect other applications that are using Kerberos authentication like SQL. ... It may require the use of the older LMHash storage as opposed to the Windows Hash. ... DC1 and now when i run netdiag, i do not get DNS errors, ...
    (microsoft.public.windows.server.active_directory)