Solved

Creating a forest trust

Posted on 2011-09-27
9
996 Views
Last Modified: 2012-05-12
Hi Experts

I have three domain controllers; two 2008 DCs, and one 2003 DC (FSMO role holder).

I need to create a forest trust, and when I go to AD Domains and Trusts -> Domain properties, the 'New Trust' button is greyed out on the two 2008 DCs but is available on the 2003 DC.

Why is this?

Thanks
0
Comment
Question by:failed
9 Comments
 
LVL 4

Expert Comment

by:mustang83
ID: 36709584
What are the domain functional levels on both forests?
0
 

Author Comment

by:failed
ID: 36709603
2003
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36709631
That's because of Windows Server 2008 Firewall :)
Disable all 3 profiles and check again :]

Regards,
Krzysztof
0
The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36709634
Of course, 3 firewall profiles :) (public, private and domain)

Krzysztof
0
 

Author Comment

by:failed
ID: 36709653
Yes I can see the button is available now after disabling the firewall, thanks.

Which ports do I need to open, as I'd rather not leave the firewall off in the long-run!
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 36709668
Grayed out New Trusts usually means you don't have specific rights to create trusts
0
 
LVL 39

Accepted Solution

by:
Krzysztof Pytko earned 500 total points
ID: 36709693
Please check this MS article for whole necessary ports to be opened on firewall
http://technet.microsoft.com/en-us/library/cc756944%28WS.10%29.aspx#w2k3tr_trust_tools_knfk

Krzysztof
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36709700
Make exceptions in Domain firewall's profile :)

Krzysztof
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 36710113
Do you need any other help on that?

Krzysztof
0

Featured Post

Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Resolve DNS query failed errors for Exchange
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question