Solved

Unable to establish trust on 2K8 R2 functional domains due to DNS namespace overlapping at COOP

Posted on 2014-03-10
2
277 Views
Last Modified: 2014-03-10
I built a COOP site domain to work as a warm site.  Because this is a secure network I was forced to complete the site/domain configurations before I was able to connect the two sites.  My first site domain is work.site.com, and I wanted my backup site to be created as a new site, so I selected coop.work.site.com.  When I connected the sites I found that I created a DNS scenario where lookups from work.site.com are not forwarding to coop.work.site.com because it believes it is authoritative.  Lookups from coop.work.site.com do successfully find servers on work.site.com.  Now I am stuck with the domain migration becuase I cannot even establish a two way trust due to DNS failures.  

I will have a very hard time changing the structure of the domain namespace at the COOP due to the fact that certificates have been issued and our security posture has been approved, so major changes will be scrutinized.  I do have full control of the domain migration process and the DNS, AD, Trusts, and Sites.  

Have I engineered myself into a corner?  How do I configure the routing to begin my migration?
0
Comment
Question by:astrofizix
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 26

Accepted Solution

by:
DrDave242 earned 500 total points
ID: 39917885
It sounds like you need to create a delegation for the coop.work.site.com domain on the DNS servers for the work.site.com domain. Creating a delegation in 2008 R2 is quite simple: right-click in the work.site.com zone, select New Delegation, and follow the prompts in the wizard. More information is here if you need it.
0
 

Author Comment

by:astrofizix
ID: 39918513
Thank you DrDave, while I have not solved this issue yet, I have convinced myself that this is a DNS issue which can be resolved by configuring the namespaces on both DNS servers until they can fully see each other.  I created the Delegation, but it did not resolve my problems immediately, I think I have a few more configuration changes to make.
0

Featured Post

Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I've written instructions for one router type, but this principle may be useful for others of the same brand and even other brands of router. Problem: I had an issue especially with mobile devices that refused to use DNS information supplied via…
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question