Improve company productivity with a Business Account.Sign Up

x
?
Solved

Creating a forest trust

Posted on 2011-09-27
9
Medium Priority
?
1,134 Views
Last Modified: 2012-05-12
Hi Experts

I have three domain controllers; two 2008 DCs, and one 2003 DC (FSMO role holder).

I need to create a forest trust, and when I go to AD Domains and Trusts -> Domain properties, the 'New Trust' button is greyed out on the two 2008 DCs but is available on the 2003 DC.

Why is this?

Thanks
0
Comment
Question by:failed
9 Comments
 
LVL 4

Expert Comment

by:mustang83
ID: 36709584
What are the domain functional levels on both forests?
0
 

Author Comment

by:failed
ID: 36709603
2003
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36709631
That's because of Windows Server 2008 Firewall :)
Disable all 3 profiles and check again :]

Regards,
Krzysztof
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36709634
Of course, 3 firewall profiles :) (public, private and domain)

Krzysztof
0
 

Author Comment

by:failed
ID: 36709653
Yes I can see the button is available now after disabling the firewall, thanks.

Which ports do I need to open, as I'd rather not leave the firewall off in the long-run!
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 36709668
Grayed out New Trusts usually means you don't have specific rights to create trusts
0
 
LVL 39

Accepted Solution

by:
Krzysztof Pytko earned 2000 total points
ID: 36709693
Please check this MS article for whole necessary ports to be opened on firewall
http://technet.microsoft.com/en-us/library/cc756944%28WS.10%29.aspx#w2k3tr_trust_tools_knfk

Krzysztof
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36709700
Make exceptions in Domain firewall's profile :)

Krzysztof
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36710113
Do you need any other help on that?

Krzysztof
0

Featured Post

Get 10% Off Your First Squarespace Website

Ready to showcase your work, publish content or promote your business online? With Squarespace’s award-winning templates and 24/7 customer service, getting started is simple. Head to Squarespace.com and use offer code ‘EXPERTS’ to get 10% off your first purchase.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

How to deal with a specific error when using the Enable-RemoteMailbox cmdlet to create a mailbox in the cloud-based service, for an existing user in an on-premises Active Directory.
A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

588 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question