Active Directory through VPN tunnel Server 2003

Posted on 2007-10-06
Last Modified: 2010-08-05
I have a VPN tunnel configured with two firewalls.  Domain A has its own Forest, Domain B has its own Forest.  I want to create a trust or make domain B a subdomain if possible of Domain A.  I can ping and access all server by typing the ip address, So I know my connection is good. Both servers are windows 2003 active directory master domain contollers with DNS on them.  I am having difficulty as to where to start in DNS to allow Domain B to see Domain A to create any sort of trust relationship.
Question by:playton
    1 Comment
    LVL 30

    Accepted Solution

    > "I want to create a trust or make domain B a subdomain if possible of Domain A. "

    The only way to make domainB a sub-domain of domainA is to perform a full-on Active Directory migration; there's no simple way to take an existing forest root domain and say "Okay, we're going to graft you onto this other forest over here now."

    On to the trust relationship.  In order to create a trust, DomainA must be able to resolve the A records and SRV records for DomainB's domain controllers, and vice versa.  Two common ways to do this:

    [1] Set up conditional forwarding on your DNS servers.  Configure DomainA DNS with conditional forwarders that forward all * queries to the IP addresses of DomainB's DNS servers, and vice versa.

    [2] Set up a stub zone in DomainA that points to DomainB's DNS servers, and vice versa.

    Also ensure that the correct ports are open between DomainA's DCs and DomainB's DCs:

    Featured Post

    Highfive + Dolby Voice = No More Audio Complaints!

    Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

    Join & Write a Comment

    A quick step-by-step overview of installing and configuring Carbonite Server Backup.
    Learn about cloud computing and its benefits for small business owners.
    This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    728 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    18 Experts available now in Live!

    Get 1:1 Help Now