AD trust - firewall


we have ad trust established between 2 forests. working fine except on 1 dc there event logs (event id 83 in operations manager log) generated. contains:

ad monitor trusts : trusts between domain (<domain_name1>) , following domain(s) in error state: <domain_name2> (inbound).
error is: specified domain either not exist or not contacted. (0x54b)

there firewall between 1 dc , trusted domain dcs. wondering whether domain controllers in both forests must have connection each other or ok dcs (all except one) 1 forest have connection dcs in trusted domain?

the answer no. if ports being firewalled necessary resource endpoints (your dcs in case), ad functionality fail, includes trusts.

so if you've established fact ports blocked, have contingency plan allow traffic?

is there vpn tunnel between locations?

why ports blocked 1 set of dcs , not others? designed way networking group?


ace fekay
mvp, mct, mcse 2012, mcitp ea & mcts windows 2008/r2, exchange 2013, 2010 ea & 2007, mcse & mcsa 2003/2000, mcsa messaging 2003
microsoft certified trainer
microsoft mvp - directory services
complete list of technical blogs: http://www.delawarecountycomputerconsulting.com/technicalblogs.php

this posting provided as-is no warranties or guarantees , confers no rights.

facebook twitter linkedin



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Motherboard replacement

Cannot create Full Text Search catalog after upgrading to V12 - Database is not fully started up or it is not in an ONLINE state

Remote Desktop App - Error 0x207 or 0x607