Re: Windows 2000 --> 2003 Trust

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Jonathan (Jonathan_at_discussions.microsoft.com)
Date: 10/20/04


Date: Wed, 20 Oct 2004 03:51:01 -0700

Glenn,

I can see the 2000 domain as an option on the security tab, but when I try
and browse it I can not view any groups or users. But I can if I do the same
on the 2000 domain.

Error I get on the 2003 server is "Server not operational".

I have been using these external trusts with 2000 --> 2000 for a while with
no problem.

So I set the DNS up in the same way as before.
I created a new forward lookup zone on each server and names the zone to be
the same as the other servers domainname. Then put a new host record in the
zone to point to the servername.

The above has been working perfectly with just 2000 servers, is there
anything different to how Windows 2003 handles DNS?

Jonathan (same company as Rich)

"Glenn L" wrote:

> When you say you can't see AD objects, are you talking about the the
> security tab of an object and attempting to add a user of group from the
> trusted domain.
> Is this what is failing. Does the trusted domain not show up as an option,
> or does it show up as an option.
> What is the exact error you are seeing?
> If this is so, then this is a DNS issue.
>
>
>
>
> --
> Glenn L
> CCNA, MCSE 2000, MCSE 2003 + Security
>
>
> "Rich" <ihate@spammers.com> wrote in message
> news:e2dNINotEHA.636@TK2MSFTNGP09.phx.gbl...
> > Hi,
> >
> > I am trying to create an external trust between a 2000 forest and a 2003
> > forest. The trusts seem to create fine, I can even see the 2003 active
> > directory objects on the 2000 server. But not the other way around on the
> > 2003 server (which is what I need).
> > The trusts are set to two-way non-transitive and the DNS appears to be
> > correct.
> >
> > I was using this method two join a couple of 2000 forests together and
> that
> > works ok, but I can't seem to do it using 2003, even to another 2003
> forest.
> >
> > Just incase, I have tried different domain and forest modes, at the moment
> I
> > am using 2003 native mode.
> >
> > This is not a forest trust, and I cannot use one due to the other forest
> > being 2000, it has to be an external trust.
> >
> > TIA
> >
> > Rich
> >
> >
>
>
>



Relevant Pages

  • Re: Protected Forest with One Child domain
    ... The forest is in native mode. ... so your child DNS servers can resolve both their ... INTERNAL zone on every DNS server using AD-Integrated Forest ...
    (microsoft.public.windows.server.dns)
  • Missing site connector to parent DC
    ... servers created a "forest wide". ... wouldn't reach the forest wide zone and vise versa. ... it only has a connector to the PDC. ... replicated from the specified server". ...
    (microsoft.public.win2000.active_directory)
  • Re: 1 DNS for 2000AD,2003AD and NT servers.. setup q??
    ... >> other forest dns servers.. ... Pick a DNS server. ... Allow Dynamic Updates on each zone. ... > by pointing to any DNS server in your infrastructure. ...
    (microsoft.public.windows.server.dns)
  • Re: DNS-Urgent-Help -Please
    ... One DC can host multiple ZONESs in the forest, ... ensure you have at least 2 DNS servers with each zone. ... DC a DNS server and point the DCs and clients to this server for name ...
    (microsoft.public.win2000.active_directory)
  • Re: Admin account ID removed - cannot admin Portal now
    ... Check which zone your server is in, then in ie go tools - internet options - ... security tab, select the zone your portal is in, click custom level ... >>> remove this TEST id as an administrator?? ...
    (microsoft.public.sharepoint.portalserver)