Forest Trust via IPSEC

Posted on 2007-11-20
Last Modified: 2012-05-05
Looking for information on how to create a trust between 2 seperate forest using ipsec. Firewalls seperate the forests and I do not want to open the convential ports to allow a trust.
Question by:58872
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 48

Expert Comment

ID: 20323852
you cant create a trust without opening up the trust required ports
LVL 19

Accepted Solution

SteveH_UK earned 500 total points
ID: 20342043
You can do this but only if you use a gateway-to-gateway vpn.

This can be completed using most enterprise firewalls, including ISA Server and GnatBox (GTA).

The traffic is encrypted between the gateways but acts normally from the servers' perspective.

Author Closing Comment

ID: 31410127

Expert Comment

ID: 33556654
what are the trust required ports ?

i want to open that trust required ports into this current setup : ipsec using juniper and cisco asa.. please let me know how to do it.. many thanks

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
Group policies can be applied selectively to specific devices with the help of groups. Utilising this, it is possible to phase-in group policies, over a period of time, by randomly adding non-members user or computers at a set interval, to a group f…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question