we have another window 2000 replicate DC Server it is call "Spoon. the ip
address of spoon is, I specify the ip address of on
the certificate setting > LDAP on our netscreen VPN/ Firewall. the automatic
CRL retrive works.

after this test I suspect there may be some default security setting may
have disallow Netscreen to communicate with our windows 2003. do you know or
is there any settting i need to be aware of ?

Windows Server 2003 domain controllers do not allow anonymous access to
the directory by default unlike Windows 2000 domain controllers.

