Re: Win3k Forest Trusts

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Can you check the logs on the firewall that sits between DMZ and LAN and
check what traffic gets dropped?

Can you list users from internal domain on DC in DMZ for test? Try to add a
user from internal domain permissions on a folder on this DC...

--
Mike
Microsoft MVP - Windows Security

"DTM" <dan.moynihan@xxxxxxxxxxx> wrote in message
news:ePNiacEGGHA.1032@xxxxxxxxxxxxxxxxxxxxxxx
> We are trying to setup a trust between our DMZ and Internal network. The
> DMZ and Internal network are their own Forest both running Win3k with SP1
> (firewall disabled). We have a firewall sitting between the two domains
> and we opened the necessary ports between them according to this MS link
> (http://support.microsoft.com/kb/q179442/). We have successfully created
> a one-way trust between the two forests. We are able to validate the
> trust without any errors. The problem comes when we are on our DMZ SQL
> server and try to add a new login with an AD user in the other forest
> (Internal). Our Internal domain shows up in the drop down menu but when
> we try to add a user it says the domain is unavailable.
>
>
>
> Maybe we have our trust setup incorrectly. Any ideas on what we could
> look at in our situation.
>
>
>
> Thanks,
>
>


.



Relevant Pages

  • Re: DNS in DMZ
    ... > forest in the DMZ. ... There will be no trust relationships whatsoever ... admin on the internal domain will ... > need to access servers in the DMZ and DMZ servers will have to access ...
    (microsoft.public.windows.server.dns)
  • Trust question
    ... Having a problem with an external trust. ... that the dmz domain trusts the internal domain. ... through terminal services to the dmz servers. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Access denied on network share in an other domain
    ... If the internal domain trusts the DMZ domain, the dmz can Pull files out from it. ... trust relationship between my internal domain and my DMZ domain. ... On my remote file server, I'm able to see the account of my ...
    (microsoft.public.windows.server.security)
  • Re: ISA 2004 VPN Client can access DMZ but not Internal Domain
    ... How is your ISA 2 configured? ... you will need to publish the internal domain to the DMZ. ... On my test DMZ I have a single machine that acts as a Domain ... My VPN clients can authenticate and access all machines on the DMZ. ...
    (microsoft.public.isa)
  • RE: Servers in DMZ particpitating in internal Domain
    ... I am not sure why you want to get an application in DMZ to be authenticated ... internal domain, the DMZ will lost its value to protect your network. ... Servers in DMZ particpitating in internal Domain ... >that have applications that need to authenticate against ...
    (microsoft.public.win2000.security)