WAN Forest Trust for different domains
hi there -we have co-location facility 1 way ad trust needed. working before when had ptp vpn tunnel t1 setup. week ago decided t1 no longer suffice our needs upgraded in mpls circuit. after installing , activating mpls, our ad trust broke. of in department scratching our heads thinking on might wrong. made sure possible ports/acls in our routers allowing traffic no luck.
we've noticed while ad trust being validated, per our colocation engineers responding 1 of our remote sites domain controllers instead of our primary dc in corporate instabilities in trust might occur in future on whom queries needs respond dc.
our setup follows: windows 2008 64bit, 1 domain (no child/sub-domains), 300 user base, t1 point point between corporate/small sites (5 branch sites approx. 10-15 miles apart), mpls connections in 2 large/mid size connected directly our colocation (10 miles apart), mpls connect directly our colocation, 1 local dcs in each remote sites in place, 2 dcs in corporate site, dcs same weight/priority, fsmo roles in corporate site.
i need expert advise if can assist:
1. when re-validating trust, why colocation querying our remote site instead of our corporate site?
2. how fix above scenario?
3. how make sure our colocation sees our corporate dcs them establish trust hide rest of dcs in remote sites?
cheers -
db
what see in nameserver tab zone's ns records. dcs in dns zone replication scope should appear, , if not, indicates replication problem. no, wouldn't remove dcs in zone's replication scope. example, if csaa.local zone set dcs in csaa.local domain, dcs have dns installed have ns record , in list.
.
how connected colo? vpn tunnel? firewall rules blocking traffic? installed av has sort of network protection feature (many of them do)? these possiblities would cause ability not verify trust, among other ad communications issues.
there huge list of ports need opened. take @ following link explain, how use portqry gui version determine if ports being blocked.
active directory firewall ports - let's try make simple
http://msmvps.com/blogs/acefekay/archive/2011/11/01/active-directory-firewall-ports-let-s-try-to-make-this-simple.aspx
.
ace fekay
mvp, mct, mcitp enterprise administrator, mcts windows 2008 & exchange 2007 & exchange 2010, exchange 2010 enterprise administrator, mcse & mcsa 2003/2000, mcsa messaging 2003
microsoft certified trainer
microsoft mvp - directory services
complete list of technical blogs: http://www.delawarecountycomputerconsulting.com/technicalblogs.php
this posting provided as-is no warranties or guarantees , confers no rights.
Windows Server > Directory Services
Comments
Post a Comment