Link to home
Start Free TrialLog in
Avatar of EHS_IT
EHS_ITFlag for United States of America

asked on

Trust only working one way.

We have a two way trust connecting two different domains. When using the ABC domain it gives us an error message about the RPC not able to contact the one domain controller on the other domain. When using the 123 domain it says it is working.

I can ping the host name and IP Address. I also used dcdiag on both domain servers and tested dns.

I did not test dcdiag on the domain controller that is not working, because it is not acting as a DNS server.

We have also restarted all servers involved.

Any thoughts?

Thanks!
Avatar of Mike Thomas
Mike Thomas
Flag of United Kingdom of Great Britain and Northern Ireland image

Is there a firewall between the DC's domain naming masters need to be able to communicate on the below ports but ideally all DC should be able to communicate.


RPC endpoint mapper 135/tcp, 135/udp
LSA RPC 42020/tcp
NetBIOS name service 137/tcp, 137/udp
NetBIOS datagram service 138/udp
NetBIOS session service 139/tcp
LDAP 389/tcp+udp
LDAP over SSL 636/tcp
Global catalog LDAP 3268/tcp
Global catalog LDAP over SSL 3269/tcp
Kerberos 88/tcp, 88/udp
DNS 53/tcp, 53/udp
Avatar of EHS_IT

ASKER

We have a firewall, but i do not think there is an issue.

The abc domain can connect to another dc on 123 domain, just not the second dc. It does not make sense that one would work and the other would not.
Depends on the firewall rules, they key server here is the domain naming master btw as they maintain the trusts, is that role on the server you can communicate with? what happens when you try to verify the trust?

Avatar of EHS_IT

ASKER

When you verify the trust from abc domain it does not work. When you verify the trust from the 123 domain it says it is working fine.
Then you need to check the firweall  for those ports to those server and for the roles on the servers. etc thats where you need to start looking.

Maybe some changed something? moved the roles? server problems (dc) etc?
Avatar of EHS_IT

ASKER

Ok. Will start looking around.
Avatar of EHS_IT

ASKER

I am still looking, but it just does not make sense that it was working Friday and we come in on Monday and it is not working. Nothing was done to the firewall all last week. Something was done about a week and a half or two weeks ago, but it was working until this morning.

Just does not make sense.

Still looking. Our firewall settings are a disaster from the people who originally set it up.
ASKER CERTIFIED SOLUTION
Avatar of guydemarco
guydemarco
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of EHS_IT

ASKER

Will do, Thanks!
Avatar of EHS_IT

ASKER

I restarted the server last night and was able to validate the trusts both ways this morning. I am no longer getting the RPC error, but the one server on 123 domain still cant find the one server on the abc domain.

When i try to connect to a shared drive from 123 domain on abc domain it says: "The mapped network drive could not be connected because of the following err: Logon failure: The target account name is incorrect"