Re: DNS related issue in a 2003 trust environment



Sorry, I was really poor of infos, I hope to be complete now:
Intranet
I have two dc that both of them are dns server too:
the zone is active directory integrated, and include Forward lookup zone and
Reverse lookup zone
Both of the servers forward dns request for Extranet domain via conditional
forwarding to the Extranet dns server.

Extranet
I have one dc that is dns server too:
the zone is active directory integrated, and include Forward lookup zone and
Reverse lookup zone
The server forward dns request via conditional forwarding to the 2 Intranet
dns servers.



"Kevin D. Goodknecht Sr. [MVP]" wrote:

Read inline please.

In news:3226C83E-B050-408F-8AE1-D4CC03379794@xxxxxxxxxxxxx,
Matteo <Matteo@xxxxxxxxxxxxxxxxxxxxxxxxx> typed:
Dear all,

I am facing with this issue, the envirnoment is:

into the Intranet we have a 2003 domain at the Interim level that is
trusted in a one-way trust relationship by the extranet domain
(Windows Server 2003 functional level) that is located into the dmz.

Actually each time I have to add an Intranet account into Extranet
groups the DSA.msc snap in is waiting at least 2 minutes after
recognizing the account, it seems that wait a reponse from something
that doesn't arrive and after the timeout show me informations that
found.

Cheking with the firewall log that divide Lan from DMZ I don't have
nothing blocked between the DC of the extranet and the DC of the
INTRANET, any idea?



Another strange thing happen connecting via RDP to the Extranet DC
with a Intranet user account, It takes at least 5 minutes to login
also if it's not the first time (I mean it has to create the profile,
and apply personal settings and so on)



I am thinking in a DNS problem but I cannot realize what is doing
this.


It could be DNS, but you did not tell us how you have DNS set up.
Where are the DNS zones hosted at for these two domains?
How is the extranet DC finding the intranet DC? (Stub zone, Secondary zone,
or Conditional Forwarder)


--
Best regards,
Kevin D. Goodknecht Sr. [MVP]
Hope This Helps

===================================
When responding to posts, please "Reply to Group"
via your newsreader so that others may learn and
benefit from your issue, to respond directly to
me remove the nospam. from my email address.
===================================
http://www.lonestaramerica.com/
http://support.wftx.us/
http://message.wftx.us/
===================================
Use Outlook Express?... Get OE_Quotefix:
It will strip signature out and more
http://home.in.tum.de/~jain/software/oe-quotefix/
===================================
Keep a back up of your OE settings and folders
with OEBackup:
http://www.oehelp.com/OEBackup/Default.aspx
===================================



.



Relevant Pages

  • Re: Replication issues
    ... I wanted to say Zone Transfers not Zone Forwarding. ... AD-Integrated DNS does not do zone transfers between the ... your DNS server will bypass ...
    (microsoft.public.windows.server.active_directory)
  • Re: DNS Redesign Issue
    ... This is because tbe TLD DNS server is the only ... set the new child domain DNS server as primary for the domain controllers? ... -Using DNS console you can right-click the zone and export to a File, ...
    (microsoft.public.windows.server.dns)
  • Re: Windows 2003 DNS Setup for Sub-Domain off of Root
    ... > dns in any other zone than the one that is assigned to them. ... > delegating each sub-domains zone from the root domain. ... they are not needed on the root domain DNS servers as the actual ... > the root zone from the sub-domains dns server. ...
    (microsoft.public.windows.server.dns)
  • Re: DNS Redesign Issue
    ... set the new child domain DNS server as primary for the domain controllers? ... -If you are going to create a new AD Integrated Zone in each child domain, ...
    (microsoft.public.windows.server.dns)
  • Re: DHCP Clients getting DNS lookup failures
    ... It sounds to me like you had a DNS issue but you fixed it, ... The DNS server has encountered a critical error from the Active ... Check that the Active Directory is functioning properly. ... Active Directory for this zone and is unable to load the zone without ...
    (microsoft.public.windows.server.sbs)

Loading