Re: Domain Confusion



That is exactly what I'm talking about. The trust relationship should allow you to do that. You cannot log into another domain without a trust relationship between the two domains. Even if you could force the domain into the dropdown list without the trust, it would do you absolutely no good.

Jeff Pitsch
Microsoft MVP - Terminal Server
Citrix Technology Professional
Provision Networks VIP

Forums not enough?
Get support from the experts at your business
http://jeffpitschconsulting.com

pj2k05 wrote:
Jeff
thanks for the response but I'm not sure which domains you mean as I mentioned three. The aim is to end up with just two domains... the DMZ one (in the DMZ!) and the 'newdomain' on the LAN. Do you mean a trust between 'DMZ and 'new' domains? How would that put the 'new' domain in the drop-down on the log on dialog so the user can log on to the correct domain? It seems that somehow I have to make the TS machine know about the 'new' domain without losing its place in the 'DMZ' domain.

Apologies if I am not explaining this very well.

Regards
Phil

"Jeff Pitsch" wrote:

If I"m understanding correctly, it sounds like you need to setup a trust relationship between the domains.

Jeff Pitsch
Microsoft MVP - Terminal Server
Citrix Technology Professional
Provision Networks VIP

Forums not enough?
Get support from the experts at your business
http://jeffpitschconsulting.com

pj2k05 wrote:
Hi all
I inherited a W2k Server running Terminal Services and used by our offsite employees to access their shares and email on our internal servers. The TS machine is in the DMZ and is a member of the DMZ domain. There are also two internal domains, for example sake I'll call them 'olddomain' and 'newdomain'. A W2003 server (non DC) in 'olddomain' provides file shares and a W2k Server (DC) in 'newdomain' hosts the Exchange server. When logging in from outside the user could log into their account on 'olddomain' (their account also exists in 'newdomain') and access both servers.

I recently had to move the W2003 server out of 'olddomain' and into 'newdomain'. I recreated the local shares and allocated permissions within 'newdomain' and local logon and access works fine. However logging on in TS creates a problem as the users can no longer access the W2003 server, trying to get to it causes a "logon failure: the target account name is incorrect" message.

When the user logs on the domain drop-down shows DMZ domain, 'olddomain' and 'this machine' as available. How do I make 'newdomain' available and stop 'olddomain' being an option (as the plan is to decommision it). I'm concerned that merely joining the TS server to 'newdomain' will create more problems because it currenty shows it belongs to DMZ domain NOT 'olddomain' and I assume it is that way for a good reason. I don't know how to allow multiple domain options from the logon drop-down as I am not at all familiar with TS and various Google searches have not made things any clearer.

Sorry this is rather verbose but I wanted to provide as much information as possible. If you can offer any suggestions, preferably pitched at a simple level then I would be grateful.

Thanks
Phil

.



Relevant Pages

  • Re: Domain Confusion
    ... (in the DMZ!) ... Microsoft MVP - Terminal Server ... from outside the user could log into their account on 'olddomain' (their ... account also exists in 'newdomain') and access both servers. ...
    (microsoft.public.windows.terminal_services)
  • RE: fedora-list Digest, Vol 6, Issue 266
    ... Re: OT: Setting up a forwarding mail domain in DMZ without ... Re: Sound Problem ... downloaded the yum.conf for fedora from Redhat's website. ... Server: Fedora.us Extras ...
    (Fedora)
  • RE: Webserver on a DMZ still needed?
    ... Certainly your suggestion to have a email server in a DMZ but still have ... having the exchange server on the internal LAN with only the smtp ports ... Talking of the financial cost of setup by the book vs the security cost ...
    (Security-Basics)
  • RE: Failed to create a trust relationship between NT4 and 2003 AD
    ... For Windows 2000 and 2003 these settings may be applied/configured via ... Digitally sign communications (if server ... With NT4 the only way to verify the settings is with the Regedt32 tool. ... Failed to create a trust relationship between NT4 and 2003 AD ...
    (microsoft.public.windows.server.migration)
  • Re: Man gets nine years for spamming
    ... > I don't think we've ever had web access. ... > connect to an inner server where you logged in and actually did stuff. ... We have 12 DMZ interfaces. ... the DMZs and in between the Internet routers and the first ...
    (alt.computer.security)