Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

External Domain Trust Relationship Problem - Cannot find DC?

Posted on 2012-03-12
6
Medium Priority
?
1,803 Views
Last Modified: 2012-03-18
Experts:

I just setup (for ease, I intend to restrict later) a two-way domain-wide trust relationship between our internal domain and a domain I just set up in our DMZ.  The DMZ DC is running Server 2008 R2, the internal DC is 2003.

I've set up all the DNS entries as best I can, I can ping the FQDN of either domain from any place in either domain.  BUT - here's the issue: when trying to grant permissions for a DMZ user in the internal domain or an internal user in the DMZ domain, I only seem to be able to do so on Windows 7 computers, but not on server operating systems (2000, 2003, 2008, or 2008 R2).

That is with the notable exception of the internal DC itself, which allows me to give DMZ users permissions to folders, etc., despite being 2003.

Any idea what is going on?  Why can't I give DMZ users rights to internal resources and vice versa when I have such an open trust?

Final note: When trying to do such an operating on a Win2k server box, I get the following message: "No authority could be contacted for authentication."  BUT, I can ping the DMZ domain's FQDN on it without issue.

Thanks,
Matt
0
Comment
Question by:mhentrich
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
6 Comments
 
LVL 26

Expert Comment

by:Leon Fester
ID: 37713282
What type of groups are your trying to add the users to?
You should use Domain Local to assign cross domain permissions.
0
 

Author Comment

by:mhentrich
ID: 37714682
In this situation, I am not trying to add anyone to groups, but rather grant someone permissions directly to a folder or share.  Like I said, it works in some places and not others.
0
 
LVL 26

Expert Comment

by:Leon Fester
ID: 37714963
Pinging the domain names could work because of a host file entry of a single DNS zone entry.
It does not verify that the trust is working correctly.

Can you validate the trust between your domains by using AD Domains and Trusts?
A quick test to check if the trust is working is to access the domain by UNC path, i.e. from the run command enter \\<<remoteDomainName>>

You should see the netlogon and sysvol folder being displayed, if not then your trust is either not working or your server are being blocked from accessing that network.

So even firewall restrictions could be the reason why your DC apply permissions but not your other servers.

For the trust validation and user authentication, Windows 2000 would be looking for the server holding the PDC emulator role on the domain being referenced.

Check with the firewall adminstrators others check the following post.
http://support.microsoft.com/kb/179442
0
Fill in the form and get your FREE NFR key NOW!

Veeam® is happy to provide a FREE NFR server license to certified engineers, trainers, and bloggers.  It allows for the non‑production use of Veeam Agent for Microsoft Windows. This license is valid for five workstations and two servers.

 

Author Comment

by:mhentrich
ID: 37715164
All,

Thanks, I've made a little headway but am having a different problem now.  Maybe you can help with this?  I'm going to make a new question for it anyways.

I've remade the trusts and they seem to be working fine - I can take a user from domain A and give them permissions to folders in domain B with no problem, and vice versa.

BUT - when I try to grant that person a login on SQL Server, no dice.  I can see the domain, find the user, etc. but when I click OK to actually add the user, it responds with "Error 15401: Windows NT user or group '%s' not found. Check the name again. "

What's the deal with that?  I've confirmed that I can resolve user names in Windows from across domains with no problem; why wouldn't SQL instances on those same servers be able to add these users?

Thanks,
Matt
0
 

Accepted Solution

by:
mhentrich earned 0 total points
ID: 37716754
0
 

Author Closing Comment

by:mhentrich
ID: 37734395
This solved the problem, sorry I didn't come across it before starting the thread.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question