Re: Two way trust between NT4 PDC and NT2003 server

From: Oli Restorick [MVP] (oli_at_mvps.org)
Date: 05/06/04


Date: Wed, 5 May 2004 23:30:55 +0100

Reading that back, I whizzed very quickly between three different setups.
To clarify:

1) Full WINS -- it should just work if all DCs are set to use the same WINS
infrastructure.

2) No WINS -- use LMHOSTS

3) Two WINS islands -- use static enties (or LMHOSTS).

Oli

"Oli Restorick [MVP]" <oli@mvps.org> wrote in message
news:eHQ79$uMEHA.3400@TK2MSFTNGP09.phx.gbl...
> One thing you didn't mention here is WINS.
>
> Are you using WINS? Are all DCs able to communicate and register with the
> same (or replicated) WINS server?
>
> See the following for how to write LMHOSTS files to allow the DCs to find
> each other.
>
> Domain Trust Relationship Cannot be Created
> http://support.microsoft.com/default.aspx?scid=kb;en-us;197808
>
> If you have two separate WINS databases that you don't want to replicate
> to each other, you can also create static domain records (1B and 1C) in
> each WINS database to allow the other side of the trust to be found.
>
> Bear in mind that Microsoft does not generally recommend using static
> entries in WINS.
>
> If one DC can resolve the other domain and another can't you'll get
> seemingly-random incidents of users being unable to log in across the
> trust. The Domain Monitor (dommon.exe) utility from the Windows 2000
> Resource Kit is great for checking that you've got everything right.
> Unfortunately, it doesn't seem to be available for download, although you
> will have it if you are a TechNet subscriber.
>
> Hope this helps
>
> Oli
>
>
> "Lillian" <anonymous@discussions.microsoft.com> wrote in message
> news:8ec801c432de$050ec8c0$a101280a@phx.gbl...
>> I have to establish two way trust between NT4(PDC) and
>> NT2003 server with active directory, the NT4 server
>> domain name is call "infoservices", host name is call
>> costandby, the NT2003 server is call "glc.training.gov"
>> has DNS, when I try to establish two way trust, first
>> from NT4 I add "training" from trusted, then from NT2003
>> server I new trust "infoservices" as incoming, then
>> outgoing, then NT4 server I add "training" as
>> trusting,the final when I want to validate from NT2003,
>> it say" verification of trust between domain traing.gov
>> and domain infoservices was unsuccessful because there
>> are current no logon servers available to service the
>> logon request, to repair a trust a pre-windows 2000
>> domian you must remove and re-add the trust on both
>> sides." before I do this I created an username"trust" on
>> both NT4 and NT2003 server with same password has domain
>> admins and administrators prevelidge, so what is wrong
>> with this setup? can someone help me? what is meant
>> by "no logon servers available to service the logon
>> request"
>>
>> Thanks.
>>
>> Lillian
>>
>
>



Relevant Pages

  • Re: Resetting a Secondary Controller
    ... DCs are just DCs. ... If these are different domains in the same forest, then the trust that was (or should ... "netdom trust /reset" to reset the trust, which can sometimes fix a trust problem by itself.) ... > 5722 Netlogon The session setup from the fails ...
    (microsoft.public.windows.server.general)
  • Re: A simple one...?
    ... Does this mean in practice that at a given time I need to connect the DCs for DomainA and DomainB together and establish a trust between DomainA to DomainB. ... a user logs onto a computer in domain A, there is a trust between domain A and domain B. Because of the trust the user can access the resources in domain B. But at no time does the user have to log onto domain B. ... Does this also apply when the domains are on physically separate subnets? ...
    (microsoft.public.windows.server.general)
  • Re: Authentication not working across trusted domains
    ... transitive trust relationship. ... Ensure that both child domains have their own, ... run the following commands on both DCs to see if all is well with DNS: ... Can you now logon via the other DC? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Cannot Establish Trust WinNT Win2K
    ... "Mike Tindall" wrote in message ... > two domains that I need to establish a trust for in order to migrate ... Usually it's a issue with finding the right domain and DCs. ... the Domain in the LMHost-File of your DCs (or have a WINS which works ...
    (microsoft.public.windows.server.active_directory)
  • Trusts between Win2k domain and NT 4.0 domain
    ... is there a firewall between dcs? ... have you checked that lmhosts is cached correctly? ... try this in command prompt: ...
    (microsoft.public.win2000.active_directory)