Domain trusts and FireWalls
hi
i'm going set 1 way domain trust. scenation:
domain (forest a):
- contains users going access resources in domain b. (user a)
- contains server (server a) used access server b in domain b
- contains windows 2008 r2 (back bone + dmz a1+a2) and windows 2003 (a few) (dmz a1) dcs
- dcs on multible dmzs
domain b (forest b):
- contains resource servers; separet dmz (dmz b2) from dcs in domain b. (server b)
- windows 2008 r2 domain controllers in dmz (dmz b1).
- trusts domain a (one way trust)
preferable use kerberos authentication.
i want user a on server a to able access resources on server b. have question:
- does server b need have network access or any dcs in domain a? if yes, there way limit dcs try communicate with? (besides doing split dns static records (not solution)).
i'm suspecting direct access server b domain dcs required kerberos authentication, maybe not ntlm?
i haven't been able find articles describing servers , dcs need communicate in setup this, found articles on intra forest setups.
any appreciated. thanks
regards
michael
hello,
please see firewall ports http://support.microsoft.com/kb/179442 , http://technet.microsoft.com/en-us/library/dd772723(ws.10).aspx
for dclocator problem dcs see http://blogs.technet.com/b/askds/archive/2008/09/24/domain-locator-across-a-forest-trust.aspx , srv records check out http://social.technet.microsoft.com/forums/en-us/winserverds/thread/28f8884f-c073-41e0-b2ee-0dbb2dff5a1f
best regards
meinolf weber
mvp, mcp, mcts
microsoft mvp - directory services
my blog: http://msmvps.com/blogs/mweber/
disclaimer: posting provided no warranties or guarantees , confers no rights.
Windows Server > Directory Services
Comments
Post a Comment