One forest, two child domains, three subnets

Posted on 2014-01-12
Medium Priority
Last Modified: 2014-01-23
I need some serious help.....

I have been charged with setting up two separate domains that will share resources and reside on the same forest yet have thier own subnets.  Is this possible?

I have setup a 2008 forest.  I am trying to set up one of the 2008 child domains but of course during dcpromo, the new dc doesn't see the forest because it is on a different subnet.

I can ping the forest server.  All subnets have been created on the router and all can access the internet.

What am I doing wrong or missing?  Anyone?  Pleeeeeease......
Question by:carolinasgirl28
  • 2

Expert Comment

by:Sasha Kranjac
ID: 39775397
You have network connectivity between the servers - the routing is working. Did you run ping using netbios, FQDN or IP address?
Is DNS working? Have you tried nslookup and checked if the name resolution works as it should?
The steps are:
1. verified and working connectivity (addressing, routers, gateways)
2. verified and working name resolution (names, FQDNs, name servers, services, DNS records...)
3. only when 1. and 2. are working flawlessly proceed setting up Active Directory

Please double check steps 1. and 2.

Can you post the error you get when dcpromo fails?

Author Comment

ID: 39775462
I am in the process of putting everything back (painstakingly) so that everyone can funcion Monday morning. I will have to try this again next weekend.

All servers are connected via fibre.
Could ping servers via ip address

The error I got from dcpromo was that the forest could not be contacted.  I'm assuming because the server was on another subnet?

Expert Comment

by:Sasha Kranjac
ID: 39775487
I suspect that it might be a name resolution issue (DNS) because you have connectivity and DC still could not be contacted.

Accepted Solution

Brad Held earned 2000 total points
ID: 39775630
So on the new server, its dns must only point to DC's in the parent domain.

So if ServerB is the child DC then it's dns must point to ServerA in the Parent.

Once its promoted and child domain is created, then some conditional forwarders need to be in place or the DNS forward lookup zones need to be replicated forest wide. This will allow clients to locate those resources in the other domain(s).

Featured Post

Train for your Pen Testing Engineer Certification

Enroll today in this bundle of courses to gain experience in the logistics of pen testing, Linux fundamentals, vulnerability assessments, detecting live systems, and more! This series, valued at $3,000, is free for Premium members, Team Accounts, and Qualified Experts.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

An article on effective troubleshooting
In this article, WatchGuard's Director of Security Strategy and Research Teri Radichel, takes a look at insider threats, the risk they can pose to your organization, and the best ways to defend against them.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

627 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question