[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Trust only working one way.

Posted on 2010-08-23
10
Medium Priority
?
1,232 Views
Last Modified: 2012-05-10
We have a two way trust connecting two different domains. When using the ABC domain it gives us an error message about the RPC not able to contact the one domain controller on the other domain. When using the 123 domain it says it is working.

I can ping the host name and IP Address. I also used dcdiag on both domain servers and tested dns.

I did not test dcdiag on the domain controller that is not working, because it is not acting as a DNS server.

We have also restarted all servers involved.

Any thoughts?

Thanks!
0
Comment
Question by:EHS_IT
  • 6
  • 3
10 Comments
 
LVL 24

Expert Comment

by:Mike Thomas
ID: 33501624
Is there a firewall between the DC's domain naming masters need to be able to communicate on the below ports but ideally all DC should be able to communicate.


RPC endpoint mapper 135/tcp, 135/udp
LSA RPC 42020/tcp
NetBIOS name service 137/tcp, 137/udp
NetBIOS datagram service 138/udp
NetBIOS session service 139/tcp
LDAP 389/tcp+udp
LDAP over SSL 636/tcp
Global catalog LDAP 3268/tcp
Global catalog LDAP over SSL 3269/tcp
Kerberos 88/tcp, 88/udp
DNS 53/tcp, 53/udp
0
 
LVL 1

Author Comment

by:EHS_IT
ID: 33501637
We have a firewall, but i do not think there is an issue.

The abc domain can connect to another dc on 123 domain, just not the second dc. It does not make sense that one would work and the other would not.
0
 
LVL 24

Expert Comment

by:Mike Thomas
ID: 33501651
Depends on the firewall rules, they key server here is the domain naming master btw as they maintain the trusts, is that role on the server you can communicate with? what happens when you try to verify the trust?

0
Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

 
LVL 1

Author Comment

by:EHS_IT
ID: 33501662
When you verify the trust from abc domain it does not work. When you verify the trust from the 123 domain it says it is working fine.
0
 
LVL 24

Expert Comment

by:Mike Thomas
ID: 33501680
Then you need to check the firweall  for those ports to those server and for the roles on the servers. etc thats where you need to start looking.

Maybe some changed something? moved the roles? server problems (dc) etc?
0
 
LVL 1

Author Comment

by:EHS_IT
ID: 33501687
Ok. Will start looking around.
0
 
LVL 1

Author Comment

by:EHS_IT
ID: 33502002
I am still looking, but it just does not make sense that it was working Friday and we come in on Monday and it is not working. Nothing was done to the firewall all last week. Something was done about a week and a half or two weeks ago, but it was working until this morning.

Just does not make sense.

Still looking. Our firewall settings are a disaster from the people who originally set it up.
0
 
LVL 6

Accepted Solution

by:
guydemarco earned 2000 total points
ID: 33502296
0
 
LVL 1

Author Comment

by:EHS_IT
ID: 33502318
Will do, Thanks!
0
 
LVL 1

Author Comment

by:EHS_IT
ID: 33512537
I restarted the server last night and was able to validate the trusts both ways this morning. I am no longer getting the RPC error, but the one server on 123 domain still cant find the one server on the abc domain.

When i try to connect to a shared drive from 123 domain on abc domain it says: "The mapped network drive could not be connected because of the following err: Logon failure: The target account name is incorrect"



0

Featured Post

Configuration Guide and Best Practices

Read the guide to learn how to orchestrate Data ONTAP, create application-consistent backups and enable fast recovery from NetApp storage snapshots. Version 9.5 also contains performance and scalability enhancements to meet the needs of the largest enterprise environments.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

873 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question