Link to home
Start Free TrialLog in
Avatar of failed
failed

asked on

Creating a forest trust

Hi Experts

I have three domain controllers; two 2008 DCs, and one 2003 DC (FSMO role holder).

I need to create a forest trust, and when I go to AD Domains and Trusts -> Domain properties, the 'New Trust' button is greyed out on the two 2008 DCs but is available on the 2003 DC.

Why is this?

Thanks
Avatar of mustang83
mustang83

What are the domain functional levels on both forests?
Avatar of failed

ASKER

2003
Avatar of Krzysztof Pytko
That's because of Windows Server 2008 Firewall :)
Disable all 3 profiles and check again :]

Regards,
Krzysztof
Of course, 3 firewall profiles :) (public, private and domain)

Krzysztof
Avatar of failed

ASKER

Yes I can see the button is available now after disabling the firewall, thanks.

Which ports do I need to open, as I'd rather not leave the firewall off in the long-run!
Grayed out New Trusts usually means you don't have specific rights to create trusts
ASKER CERTIFIED SOLUTION
Avatar of Krzysztof Pytko
Krzysztof Pytko
Flag of Poland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Make exceptions in Domain firewall's profile :)

Krzysztof
Do you need any other help on that?

Krzysztof