Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Creating a forest trust

Posted on 2011-09-27
9
Medium Priority
?
1,095 Views
Last Modified: 2012-05-12
Hi Experts

I have three domain controllers; two 2008 DCs, and one 2003 DC (FSMO role holder).

I need to create a forest trust, and when I go to AD Domains and Trusts -> Domain properties, the 'New Trust' button is greyed out on the two 2008 DCs but is available on the 2003 DC.

Why is this?

Thanks
0
Comment
Question by:failed
9 Comments
 
LVL 4

Expert Comment

by:mustang83
ID: 36709584
What are the domain functional levels on both forests?
0
 

Author Comment

by:failed
ID: 36709603
2003
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36709631
That's because of Windows Server 2008 Firewall :)
Disable all 3 profiles and check again :]

Regards,
Krzysztof
0
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36709634
Of course, 3 firewall profiles :) (public, private and domain)

Krzysztof
0
 

Author Comment

by:failed
ID: 36709653
Yes I can see the button is available now after disabling the firewall, thanks.

Which ports do I need to open, as I'd rather not leave the firewall off in the long-run!
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 36709668
Grayed out New Trusts usually means you don't have specific rights to create trusts
0
 
LVL 39

Accepted Solution

by:
Krzysztof Pytko earned 2000 total points
ID: 36709693
Please check this MS article for whole necessary ports to be opened on firewall
http://technet.microsoft.com/en-us/library/cc756944%28WS.10%29.aspx#w2k3tr_trust_tools_knfk

Krzysztof
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36709700
Make exceptions in Domain firewall's profile :)

Krzysztof
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36710113
Do you need any other help on that?

Krzysztof
0

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

824 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question