[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

Can't ccess DFS share in Resource Forest from Account Forest

Posted on 2010-11-15
12
Medium Priority
?
1,238 Views
Last Modified: 2012-05-10
Hi Experts

I need some urgent help here.

So I'm having 2 Account Forests (1 site each) and 1 Resource Forest (2 sites). I setup DFS on a fileserver in one site of the Resource Forest. The plan is to have 2 fileservers in the 2 sites replicating data back and forth. I've setup the the Namespace (public) with Folders and folder targets. Within the Resource Forest everything works fine and I can map to the share with ResourceForest.local\public.
This doesn't work with the Account Forest though.

The conditional forwarders are all setup and I can ping. Even by doing ping resourceforest.local I get a response from the domain controller. So it can't be DNS resolving.

Does it just take a long time to replicate accross and if so what can I do to improve this?

If I'm not clear here please ask. I'm totally stuck on this and I'm desperate to get this fixed.

Thanks in advance
0
Comment
Question by:Dan-IT
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 6
12 Comments
 

Author Comment

by:Dan-IT
ID: 34143149
This is a domain integrated DFS name space
0
 
LVL 24

Expert Comment

by:Awinish
ID: 34144532
You have two different domain or forest & one site & two site is in different domain or different domain in forest?
0
 

Author Comment

by:Dan-IT
ID: 34145970
We have 3 Forest. EU, US and the Resource Forest.
That's in 4 different sites.
US (1 site) Resource Forest (2 sites) and EU (1 site)

Basically like this:

Account Forest -------------------------Resource   Forest -----------------------------------Account Forest
US-------------------------------------------US---------EU--------------------------------------------------------EU
User Account ----------------------DFS\Shared----DFS\Shared-----------------------------------------User Account

I would like the User Accounts to acces the DFS\shared on the server closest to them. So EU user will access DFS\Shared on the EU Fileserver in the resource forest and US User will access DFS\shared on the US Fileserver in the resource forest.
0
Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 24

Expert Comment

by:Awinish
ID: 34146379
DFS replication is dependent on Active Directory replication & it uses AD replication mechanism to replicate the data.

You can use repadmin /replicate /force

http://www.windowsitpro.com/article/file-systems/q-forcing-dfs-replication-dfsr-members-to-replicate-.aspx
http://blogs.technet.com/b/filecab/archive/2008/10/24/what-does-dfsdiag-do.aspx

As i said,dfsr depends on AD,so i force replication on AD will initiate replication & there is tool called dfsrdiag & it can used to monitor,test DFSR.

References:
http://blogs.technet.com/b/askds/archive/2008/02/12/get-out-and-push-getting-the-most-out-of-dfsr-pre-staging.aspx
http://blogs.technet.com/b/filecab/archive/2006/06/19/437214.aspx

http://technet.microsoft.com/en-us/library/cc773238%28WS.10%29.aspx
0
 

Author Comment

by:Dan-IT
ID: 34146501
That's cool and replication within the resource forest works just fine.

What we are trying to do is access the DFS share from the Account Forest. One way transitive Forest Trust is in place.
0
 
LVL 24

Expert Comment

by:Awinish
ID: 34146579
You are using three different forest any special requirement of setting three different forest as i have seen different domain in forest but 3 different forest the only thing i can think of having different exchange organization.

0
 
LVL 24

Expert Comment

by:Awinish
ID: 34146585
Do clients from account forest can resolves dfs share servername using nslookup & can ping?
0
 

Author Comment

by:Dan-IT
ID: 34146726
NSlookup and Ping is succesfully yes.
0
 

Author Comment

by:Dan-IT
ID: 34146739
and clients in the account forest can even resolve the \\fileserver\share
0
 
LVL 24

Expert Comment

by:Awinish
ID: 34146816
What error they are getting while access dfs share?
0
 

Author Comment

by:Dan-IT
ID: 34146942
I found out what was the problem.
I had to add the DNS suffix from the Resource Forest althought I have conditional forwarders in place.
Would you recommend using a Stubzone instead? Would this improve performance maybe?

I have set roaming profile on one useraccount and logon/logoff times are very poor. It takes about 5 minutes to save the profile. The user account has the right access permissions to that \\domain.local\DFS share\userprofiles\%username%\


The error message was

Windows cannot access \\domain.local\shared\....etc
Check the spelling of the name. Otherwise, there might be a problem with your network. To try to identify and resolve network problems, click Diagnose.
0
 
LVL 24

Accepted Solution

by:
Awinish earned 2000 total points
ID: 34147088
Stub(Only Dns host server records i.e name server record,SOA) zone or secondary (it includes all the records from other domain dns)zone,so secondary dns can be best but as you have created one way trust so i would recommend stub zone in this scenario which will have faster name resolution as it will have all the dns server listed for other domain.

http://www.windowsnetworking.com/articles_tutorials/DNS_Stub_Zones.html


You can enable universal group caching from ADSS for fast logi.
http://msmvps.com/blogs/donna/archive/2004/03/31/4452.aspx
http://www.windowsnetworking.com/kbase/WindowsTips/Windows2003/AdminTips/ActiveDirectory/Whentouseandnotuseuniversalgroupmembershipcaching.html
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Group policies can be applied selectively to specific devices with the help of groups. Utilising this, it is possible to phase-in group policies, over a period of time, by randomly adding non-members user or computers at a set interval, to a group f…
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Suggested Courses

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question