Celebrate National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Unable to establish trust on 2K8 R2 functional domains due to DNS namespace overlapping at COOP

Posted on 2014-03-10
2
Medium Priority
?
285 Views
Last Modified: 2014-03-10
I built a COOP site domain to work as a warm site.  Because this is a secure network I was forced to complete the site/domain configurations before I was able to connect the two sites.  My first site domain is work.site.com, and I wanted my backup site to be created as a new site, so I selected coop.work.site.com.  When I connected the sites I found that I created a DNS scenario where lookups from work.site.com are not forwarding to coop.work.site.com because it believes it is authoritative.  Lookups from coop.work.site.com do successfully find servers on work.site.com.  Now I am stuck with the domain migration becuase I cannot even establish a two way trust due to DNS failures.  

I will have a very hard time changing the structure of the domain namespace at the COOP due to the fact that certificates have been issued and our security posture has been approved, so major changes will be scrutinized.  I do have full control of the domain migration process and the DNS, AD, Trusts, and Sites.  

Have I engineered myself into a corner?  How do I configure the routing to begin my migration?
0
Comment
Question by:astrofizix
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 27

Accepted Solution

by:
DrDave242 earned 1500 total points
ID: 39917885
It sounds like you need to create a delegation for the coop.work.site.com domain on the DNS servers for the work.site.com domain. Creating a delegation in 2008 R2 is quite simple: right-click in the work.site.com zone, select New Delegation, and follow the prompts in the wizard. More information is here if you need it.
0
 

Author Comment

by:astrofizix
ID: 39918513
Thank you DrDave, while I have not solved this issue yet, I have convinced myself that this is a DNS issue which can be resolved by configuring the namespaces on both DNS servers until they can fully see each other.  I created the Delegation, but it did not resolve my problems immediately, I think I have a few more configuration changes to make.
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Citrix XenApp, Internet Explorer 11 set to Enterprise Mode and using central hosted sites.xml file.
Resolve DNS query failed errors for Exchange
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question