Re: Trusts between W2k domains in different forests

From: Dave Shaw [Microsoft MVP] (dhshaw@gNeOnSePsAiMs-ii.com)
Date: 09/28/02


From: "Dave Shaw [Microsoft MVP]" <dhshaw@gNeOnSePsAiMs-ii.com>
Date: Sat, 28 Sep 2002 15:11:44 -0400


inline -

"Matthew Melbourne" <matt@melbourne.org.uk> wrote in message
news:4b7d22c689matt@melbourne.org.uk...
> We are investigating setting up trusts between our corporate W2k domain
> and a W2k domain managed by a third party. For a variety of reasons, these
> Windows 2000 domains are in different forests (and have different AD
> schemas).
>
> We wish to grant access to resources in the Corporate Domain (Domain A),
> particularly web-based resources which are heavily integrated into the
> NTLM authentication model, to users in the third party domain (Domain B).

Certificates. Have you decided upon a PKI model?

> Since the domains are in different forests, an automatic transitive trust
> will not exist, and manual trusts will need to be created, in a similar
> manner to NT 4 trusts, i.e. Domain A trusts Domain B, for Domain B users
> to be granted access to resources in Domain A. In addition Domain A will
> need to locate Domain B's DCs through DNS (but this is a secondary issue).

Actually, only the PDC FSMO role holders need to *find* each other. They
are the machines that will make the trusts for the domain. To do this, they
need to each be able to locate and determine the ip address of the computers
in each domain holding the <1Bh> service (Domain Master Browser). These are
the PDC emulators. To do this, you will need to ensure NetBIOS Name
resolution of each machine to each machine.

> To complicated this further, a firewall exists between the two networks,
> so network traffic associated with W2k trusts will need to be permitted
> through the firewall. Domain A is a Windows 2000 native domain consisting
> of a number of domain controllers and Domain B will likely have a number
> of domain controllers too. When a one-way trust is created so that Domain
> A trusts Domain B, which domain controllers actually exchange traffic?
> Could it be any of the DCs, or just the DC on which the trust was created,
> as this will dictate the firewall rules.

Create a tunnel between the two firewalls.

-ds



Relevant Pages

  • Re: AD Trusts and Firewall
    ... you can pretty much ignore the client ports in MS's example IF the domain in which a client is a member of does not have a traverse over a firewall. ... trusted domains/forests only require communication between the domain/forest in which it explicitly trusts. ... you will need to setup communication through the firewall for all ports listed under "Server Ports" in MS's documentation for all of the domain controllers on each side of any trust you create. ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD Trusts and Firewall
    ... each domain controllers need to be able to communicate with each other? ... firewall. ... firewall between the trusts). ... Joseph T. Corey MCSE, Security+ ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD Trusts and Firewall
    ... I've got some questions concerning Trusts and Firewalls. ... I have a child domain with 2 domain controllers. ... migration purpose. ... What are the firewall rules to be added between each of these elements (For ...
    (microsoft.public.windows.server.active_directory)
  • RE: AD Trusts and Firewall
    ... I have 2 Sites separated by a firewall. ... CDC1 is set as BridgeHost Server. ... Will all the Domain Controllers communicate with the Parent Domain ... I've got some questions concerning Trusts and Firewalls. ...
    (microsoft.public.windows.server.active_directory)
  • Trusts between W2k domains in different forests
    ... We are investigating setting up trusts between our corporate W2k domain ... Windows 2000 domains are in different forests (and have different AD ... to users in the third party domain. ... of a number of domain controllers and Domain B will likely have a number ...
    (microsoft.public.win2000.security)