Solved

Two Way Domain Trust - ACL Problem on One Server

Posted on 2016-10-13
2
54 Views
Last Modified: 2016-10-18
I've googled this for a few hours now and I haven't been able to solve this problem.

Domains are ole.local and ept.local.  Two way domain trust. Trust type = Forest, Transitive = Yes.

Both domains have stubs in DNS to resolve to each other. I can ping the root domain ole.local from ept,local and it resolves with one of ole.local's DNS servers and visa versa.  I can add a user or group (from ept.local) to the ACL of an ole.local shared folder on any of the three Windows 2008R2 or 2012 servers at OLE.

I can add a user or group (from ole.local) to the ACL of a ept.local shared folder to all (server 2008 and 2012) but one server 2008R2 machine. When I try this on any of the folders on this machine I get the error "The Active Directory Domain Controllers required to find the selected objects in the following domains are not available: ole.local"...  I have confirmed that I can ping from this server the root of the ole.local domain. Again I can add an ole.local user on the other servers at ept with no issue.

Can anyone shed some light on this situation?

Thanks
Rob
0
Comment
Question by:robertgibson
2 Comments
 
LVL 36

Accepted Solution

by:
Mahesh earned 500 total points
ID: 41848737
Instead of using stub zone, either use conditional forwarding or secondary zone both side for cross forest name resolution

It might be possible that while resolving other domain users, DC to DC communication not happening because stub zone may resolve to some other DC for which AD ports are not opened
0
 

Author Comment

by:robertgibson
ID: 41848763
Based on your comment I went back and checked the two DNS servers on the ept.local side.  One still had an old record in there referencing an old DC.  Once I did a reload it suddenly worked.

Thanks
Rob
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
A safe way to clean winsxs folder from your windows server 2008 R2 editions
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question