• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

Win 2003 Active Directory Trusts

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    Win 2003 Active Directory Trusts

    I have 2 win2003 server's acting as DCs in seperate forests.
    I can create an external 2-way trust between them and validate it but after about 6 minutes it breaks.

    I have absolutely no idea why. The only thing I have to go on is that I sometimes receive an error regarding the RPC server being unavailable, though the service is running on both servers.


    Any help appreciated while I start Googling.



    #2
    From memory RPC Unavailable errors are generally cause by a DNS failure - one or the other machine cannot lookup the other in DNS. Failing that check firewalls, RPC Permissions, DCOM Permissions etc.
    "Being nice costs nothing and sometimes gets you extra bacon" - Pondlife.

    Comment


      #3
      Agree with previous poster - more than likely DNS.

      Check the DC event logs on both DC's - the clue will be in there!

      Alo whathappn if you create a one-way incoming trust on one domain and a one way outgoing on the other domain? Does this hold? What about the other way round? This could point youat permissions.

      Also - the account that you are using to create and validate the trust - is this locking out? Are you using this account for anything else (services etc?)

      Cheers.

      Comment


        #4
        I'm working my way through a MS checklist and looking into the DNS issues. I think the problem is there tbh.

        I'm actually using an administrative account to create the trusts. It's used often to log onto the boxes. Perhaps a dedicated account is needed...?


        Thanks

        Comment


          #5
          Are there any firewalls between them?

          I would check that both forwards and reverse entries are resolvable via DNS.

          The account should not be an issue as this not used after the trust has been established.
          Last edited by spoons; 13 August 2008, 12:12. Reason: spool chucker failure

          Comment


            #6
            Sorted it, thanks.

            I needed to set up secondary zone files on each server and then allow the originating zones to be shared.

            Simple really.....


            Comment

            Working...
            X