Forest Trust 2003
Windows Server Forum Index Windows Server
Server discussion on Windows platform.
 
 FAQFAQ   MemberlistMemberlist     RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
 
Google
 
Web winserverhelp.com
Forest Trust 2003

 
Post new topic   Reply to topic    Windows Server Forum Index -> Migration
Author Message
maTT
Guest





Posted: Fri Jan 21, 2005 10:15 pm    Post subject: Forest Trust 2003 Reply with quote

We have a Forest Trust

From a Domain Controller I can add Security Groups from the other Domain.
From a Memeber Server I can not.

Forest wide authenication.

Why on the Member Servers I can not see the other Domain???

This is both ways!!!

Thanks
MaTT
Back to top
Bob Qin [MSFT]
Guest





Posted: Mon Jan 24, 2005 3:56 pm    Post subject: RE: Forest Trust 2003 Reply with quote

HI MaTT,

Thanks for your posting here.

I would like to suggest that you check the DNS settings in TCP/IP
properties on the Member server. Please make sure that that you have point
it to the same DNS server with DC in the domain.

Have a nice day!

Regards,
Bob Qin
Microsoft Online Partner Support

Get Secure! - www.microsoft.com/security

====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.

--------------------
From: "maTT" <matt.smith@jacobsonco.com>
Subject: Forest Trust 2003
Date: Fri, 21 Jan 2005 10:15:15 -0600
Newsgroups: microsoft.public.windows.server.migration


We have a Forest Trust

From a Domain Controller I can add Security Groups from the other
Domain.
From a Memeber Server I can not.

Forest wide authenication.

Why on the Member Servers I can not see the other Domain???

This is both ways!!!

Thanks
MaTT
Back to top
maTT
Guest





Posted: Mon Jan 24, 2005 8:50 pm    Post subject: Re: Forest Trust 2003 Reply with quote

Bob,

Yes, all are member server point to the Primary DNS Server.

I can log into the other Domain just fine by selecting the drop down.
At this point I can add GG to Local Groups.

If I log off and back on a Domain Admin in my Domain I can not see the other
domain
under the Security Poperities.

Thanks
MaTT


"Bob Qin [MSFT]" <bobqin@online.microsoft.com> wrote in message
news:7vgQ%23rfAFHA.2504@cpmsftngxa10.phx.gbl...
Quote:
HI MaTT,

Thanks for your posting here.

I would like to suggest that you check the DNS settings in TCP/IP
properties on the Member server. Please make sure that that you have point
it to the same DNS server with DC in the domain.

Have a nice day!

Regards,
Bob Qin
Microsoft Online Partner Support

Get Secure! - www.microsoft.com/security

====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
====================================================
This posting is provided "AS IS" with no warranties, and confers no
rights.

--------------------
From: "maTT" <matt.smith@jacobsonco.com
Subject: Forest Trust 2003
Date: Fri, 21 Jan 2005 10:15:15 -0600
Newsgroups: microsoft.public.windows.server.migration


We have a Forest Trust

From a Domain Controller I can add Security Groups from the other
Domain.
From a Memeber Server I can not.

Forest wide authenication.

Why on the Member Servers I can not see the other Domain???

This is both ways!!!

Thanks
MaTT



Back to top
Bob Qin [MSFT]
Guest





Posted: Tue Jan 25, 2005 2:14 pm    Post subject: Re: Forest Trust 2003 Reply with quote

Hi MaTT,

Does the porblem occur on all the clients or just this certain one?
What is the operation system in each domain side?

Please run "ipconfig /all" on a DC and a client in the same domain, then
copy the result in your post.

I would like to suggest that you try the following sugestion to reset
trusts.

1. Break the trust on both sides using the GUI.
2. Configure a Netdom command thusly:

Use on Domain A

NETDOM TRUST /d:DomainB DomainA /ADD /TWOWAY /Ud:DomainB\Admin_Account_in_
DomainB /Pd:*

Have a nice day!

Regards,
Bob Qin
Microsoft Online Partner Support

Get Secure! - www.microsoft.com/security

====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.

--------------------
From: "maTT" <matt.smith@jacobsonco.com>
Subject: Re: Forest Trust 2003
Date: Mon, 24 Jan 2005 08:50:17 -0600
Newsgroups: microsoft.public.windows.server.migration

Bob,

Yes, all are member server point to the Primary DNS Server.

I can log into the other Domain just fine by selecting the drop down.
At this point I can add GG to Local Groups.

If I log off and back on a Domain Admin in my Domain I can not see
the other
domain
under the Security Poperities.

Thanks
MaTT


"Bob Qin [MSFT]" <bobqin@online.microsoft.com> wrote in message
news:7vgQ%23rfAFHA.2504@cpmsftngxa10.phx.gbl...
Quote:
HI MaTT,

Thanks for your posting here.

I would like to suggest that you check the DNS settings in TCP/IP
properties on the Member server. Please make sure that that you
have point
it to the same DNS server with DC in the domain.

Have a nice day!

Regards,
Bob Qin
Microsoft Online Partner Support

Get Secure! - www.microsoft.com/security

====================================================
When responding to posts, please "Reply to Group" via your
newsreader so
that others may learn and benefit from your issue.
====================================================
This posting is provided "AS IS" with no warranties, and confers no
rights.

--------------------
From: "maTT" <matt.smith@jacobsonco.com
Subject: Forest Trust 2003
Date: Fri, 21 Jan 2005 10:15:15 -0600
Newsgroups: microsoft.public.windows.server.migration


We have a Forest Trust

From a Domain Controller I can add Security Groups from the
other
Domain.
From a Memeber Server I can not.

Forest wide authenication.

Why on the Member Servers I can not see the other Domain???

This is both ways!!!

Thanks
MaTT



Back to top
 
Post new topic   Reply to topic    Windows Server Forum Index -> Migration All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




New Topics Powered by phpBB