Domain trusts and FireWalls


hi

i'm going set 1 way domain trust. scenation:

domain (forest a):

  • contains users going access resources in domain b. (user a)
  • contains server (server a) used access server b in domain b
  • contains windows 2008 r2 (back bone + dmz a1+a2) and windows 2003 (a few) (dmz a1) dcs
  • dcs on multible dmzs

domain b (forest b):

  • contains resource servers; separet dmz (dmz b2) from dcs in domain b. (server b)
  • windows 2008 r2 domain controllers in dmz (dmz b1).
  • trusts domain a (one way trust)

preferable use kerberos authentication.

i want user a on server a to able access resources on server b. have question:

  1. does server b need have network access or any dcs in domain a? if yes, there way limit dcs try communicate with? (besides doing split dns static records (not solution)).

i'm suspecting direct access server b domain dcs required kerberos authentication, maybe not ntlm?

i haven't been able find articles describing servers , dcs need communicate in setup this, found articles on intra forest setups.

any appreciated. thanks

regards

michael

hello,

please see firewall ports http://support.microsoft.com/kb/179442 , http://technet.microsoft.com/en-us/library/dd772723(ws.10).aspx

for dclocator problem dcs see http://blogs.technet.com/b/askds/archive/2008/09/24/domain-locator-across-a-forest-trust.aspx , srv records check out http://social.technet.microsoft.com/forums/en-us/winserverds/thread/28f8884f-c073-41e0-b2ee-0dbb2dff5a1f


best regards

meinolf weber
mvp, mcp, mcts
microsoft mvp - directory services
my blog: http://msmvps.com/blogs/mweber/

disclaimer: posting provided no warranties or guarantees , confers no rights.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file