• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 458
  • Last Modified:

Trust agains forests with multiple domain controllers

If I want to setup a trust between to forests with a single DC in each forest, then it's pretty much out of the box.

But what if there are multiple DC's in each forest?

I have two forest:
A: Two DC's (Windows Server 2008 R2)
B: Four DC's (Two Windows Server 2008 R2 / Two Windows Server 2012)

How do I setup the trust between theese two forests?
Must I take the necessary steps on all DC's or can it be done on one DC in each forest?

Regards
Kasper
0
Kasper Katzmann
Asked:
Kasper Katzmann
  • 2
  • 2
1 Solution
 
Rob StoneCommented:
You just make the trust using AD Domains & Trusts from a DC or a client with the admin tools installed.

The number of DC's in each forest isn't relevant.

http://technet.microsoft.com/en-us/library/cc772440.aspx
0
 
Kasper KatzmannSeniorkonsulentAuthor Commented:
How about port openings (53, 88, 389, 445, 636)? Will they have to be made between each DC?
0
 
lruiz52Commented:
You will need to open all the below ports.

123/UDP      W32Time
135/TCP      RPC Endpoint Mapper
464/TCP/UDP      Kerberos password change
49152-65535/TCP      RPC for LSA, SAM, Netlogon (*)
389/TCP/UDP      LDAP
636/TCP      LDAP SSL
3268/TCP      LDAP GC
3269/TCP      LDAP GC SSL
53/TCP/UDP      DNS
49152 -65535/TCP      FRS RPC (*)
88/TCP/UDP      Kerberos
445/TCP      SMB
49152-65535/TCP      DFSR RPC (*)

http://support.microsoft.com/kb/179442
0
 
Kasper KatzmannSeniorkonsulentAuthor Commented:
There should have been a "and so on" after my litlle listing.

But what about which server the openings should be between. All the DC's or...?
0
 
Rob StoneCommented:
Generally you create a firewall rule on both sides (on the externally facing firewall).  Once that's configured, you then need to go through the checklist in the first hyperlink. If you are having issues, check the network logs on the firewalls to see if anything is still getting blocked.

If you use Windows Firewall on the servers, when you install the role the relevant ports should open automatically.  I'm not sure if that's the case if you use a 3rd party firewall.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Cloud Class® Course: Amazon Web Services - Basic

Are you thinking about creating an Amazon Web Services account for your business? Not sure where to start? In this course you’ll get an overview of the history of AWS and take a tour of their user interface.

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now