failed
asked on
Creating a forest trust
Hi Experts
I have three domain controllers; two 2008 DCs, and one 2003 DC (FSMO role holder).
I need to create a forest trust, and when I go to AD Domains and Trusts -> Domain properties, the 'New Trust' button is greyed out on the two 2008 DCs but is available on the 2003 DC.
Why is this?
Thanks
I have three domain controllers; two 2008 DCs, and one 2003 DC (FSMO role holder).
I need to create a forest trust, and when I go to AD Domains and Trusts -> Domain properties, the 'New Trust' button is greyed out on the two 2008 DCs but is available on the 2003 DC.
Why is this?
Thanks
What are the domain functional levels on both forests?
ASKER
2003
That's because of Windows Server 2008 Firewall :)
Disable all 3 profiles and check again :]
Regards,
Krzysztof
Disable all 3 profiles and check again :]
Regards,
Krzysztof
Of course, 3 firewall profiles :) (public, private and domain)
Krzysztof
Krzysztof
ASKER
Yes I can see the button is available now after disabling the firewall, thanks.
Which ports do I need to open, as I'd rather not leave the firewall off in the long-run!
Which ports do I need to open, as I'd rather not leave the firewall off in the long-run!
Grayed out New Trusts usually means you don't have specific rights to create trusts
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Make exceptions in Domain firewall's profile :)
Krzysztof
Krzysztof
Do you need any other help on that?
Krzysztof
Krzysztof