Solved

Running an application between domains with no trust relationship

Posted on 2014-03-07
4
594 Views
Last Modified: 2014-03-14
We have seperated our environment into two AD domains on two different subnets.  We have the need to temporarily open Domain A to allow Domain B to access to an application running on Domain A.  Access rules are wide open and can access the server by IP address and all of it's resources.  Have put in an entry into the hosts file to resolve the server by name.  Can get the application to run, but with a slight glitch - it prints to a shared printer on Domain A that has print software which charges for pages printed.  The confirmation box that is supposed to popup to give a total of the job and how many pages does not, but job goes into the queue.

Without knowing how the application works does it appear that a trust is needed between domains even though resources are accessible?  Or is it maybe a DNS issue?

How to setup DNS between the two domains?

Thx
0
Comment
Question by:Webcc
4 Comments
 
LVL 16

Expert Comment

by:Learnctx
ID: 39914305
Looking in the security logs should tell you if you're having access issues. If it is DNS, you could to a zone transfer of Domain A's DNS zone to a DNS server in Domain B. If it is access related maybe look at doing a 1 way selective trust to allow the account in Domain B to access the app in Domain A. Seeing as it is temporary, when you're doing just remove the trust.
0
 
LVL 26

Assisted Solution

by:Leon Fester
Leon Fester earned 250 total points
ID: 39917560
For the DNS setup, you only need to setup stub zones.
It's a better option than zone transfers.

http://technet.microsoft.com/en-us/library/cc771898.aspx

Regarding the printing issue.
Your application is most likely using client-server architecture, so it is the Server that is calling the printing to that printer.

I'd go back and look at the setup on one of the workstations in Domain A to confirm if that are any special software installed or printer driver configuration required. Without a domain trust you could be missing the security for the 3rd-party app that does the billing, but printing could still work. Go investigate how it works in Domain A and apply the same to Domain B.
0
 
LVL 27

Accepted Solution

by:
Steve earned 250 total points
ID: 39920759
some modern printers have bi-directional support and show fancy popups etc. This can complicate the traffic involved, even through the process of sending the actual print job is fairly straight forward.
there are various ways for this to work so we may not be able to guess it unless we have the same software available to test.

best option is probably to run monitoring software on a machine in domain A that works and see what communication is occurring when printing. You can then assess if you want to allow the same traffic to flow in your temporary setup.
0
 

Author Closing Comment

by:Webcc
ID: 39929827
Thank you.
0

Join & Write a Comment

Occasionally you run into the website or two that will not resolve properly using your own DNS servers.  Some people simply set up global forwarders for their DNS server.  I don’t recommend doing this because it can cause problems resolving addresse…
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now