Solved

Trust agains forests with multiple domain controllers

Posted on 2013-06-23
5
438 Views
Last Modified: 2013-06-26
If I want to setup a trust between to forests with a single DC in each forest, then it's pretty much out of the box.

But what if there are multiple DC's in each forest?

I have two forest:
A: Two DC's (Windows Server 2008 R2)
B: Four DC's (Two Windows Server 2008 R2 / Two Windows Server 2012)

How do I setup the trust between theese two forests?
Must I take the necessary steps on all DC's or can it be done on one DC in each forest?

Regards
Kasper
0
Comment
Question by:Kasper Katzmann
  • 2
  • 2
5 Comments
 
LVL 15

Accepted Solution

by:
Rob Stone earned 500 total points
ID: 39269448
You just make the trust using AD Domains & Trusts from a DC or a client with the admin tools installed.

The number of DC's in each forest isn't relevant.

http://technet.microsoft.com/en-us/library/cc772440.aspx
0
 

Author Comment

by:Kasper Katzmann
ID: 39269457
How about port openings (53, 88, 389, 445, 636)? Will they have to be made between each DC?
0
 
LVL 17

Expert Comment

by:lruiz52
ID: 39269470
You will need to open all the below ports.

123/UDP      W32Time
135/TCP      RPC Endpoint Mapper
464/TCP/UDP      Kerberos password change
49152-65535/TCP      RPC for LSA, SAM, Netlogon (*)
389/TCP/UDP      LDAP
636/TCP      LDAP SSL
3268/TCP      LDAP GC
3269/TCP      LDAP GC SSL
53/TCP/UDP      DNS
49152 -65535/TCP      FRS RPC (*)
88/TCP/UDP      Kerberos
445/TCP      SMB
49152-65535/TCP      DFSR RPC (*)

http://support.microsoft.com/kb/179442
0
 

Author Comment

by:Kasper Katzmann
ID: 39269546
There should have been a "and so on" after my litlle listing.

But what about which server the openings should be between. All the DC's or...?
0
 
LVL 15

Expert Comment

by:Rob Stone
ID: 39269654
Generally you create a firewall rule on both sides (on the externally facing firewall).  Once that's configured, you then need to go through the checklist in the first hyperlink. If you are having issues, check the network logs on the firewalls to see if anything is still getting blocked.

If you use Windows Firewall on the servers, when you install the role the relevant ports should open automatically.  I'm not sure if that's the case if you use a 3rd party firewall.
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Internet Protocol Security question 3 66
server core and windows updates 3 38
Inactive computer in domain 7 57
Admin account lockout 10 36
The article will show you how you can maintain a simple logfile of all Startup and Shutdown events on Windows servers and desktops with PowerShell. The script can be easily adapted into doing more like gracefully silencing/updating your monitoring s…
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now