Go Back   TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , , , , ,

Sponsored Links



Establish Windows 2000 to 2003 Active Directory Domain Trust with

Active Directory


Reply
 
Thread Tools Search this Thread
  #1  
Old 04-05-2005
RossBale
 
Posts: n/a
Establish Windows 2000 to 2003 Active Directory Domain Trust with

Trying to establish a Trust between an AD2003/AD2000 domain through a
firewall. Firewall doesn't seem to be blocking any traffic, although when I
run NLTEST /SC_QUERY:domain name, I get I_NetLogonControl Failed : Status =
1355 0x52b ERROR_NO_SUCH_DOMAIN, but if I do NLTEST /DSGETDC:DOMAIN NAME I
get all the information regarding DC's etc back.

NLTEST /DCLIST:DOMAIN NAME cannot DSBind to domain_name status = 2148074290
0x80090332 SEC_E_SECURITY_QOS_FAILED
I_NetGetDCList failed: Status = 6118 0x17e6 ERROR_NO_BROWSER_SERVERS_FOUND

NLTEST /DCNAME:DOMAIN NAME NetGetDCName Failed: status 2453 0x995
NERR_DCNotFound

Any help would be greatly appreciated.
Reply With Quote
  #2  
Old 05-05-2005
Member
 
Join Date: Apr 2005
Posts: 4
Can you actually create & validate the trust in AD Domains & trust. If you can then u can use Netdom command instead to verify the trust between the two domains. I believe the systax is like this:
netdom trust /d:firstdomain 2ndomain /verify /twoway
Reply With Quote
  #3  
Old 05-05-2005
Ross Bale
 
Posts: n/a
Re: Establish Windows 2000 to 2003 Active Directory Domain Trust w

Thanks for your response. I can create the trust in AD Domains and Trusts,
but not validate it, we are trying to establish a one way trust where the
w2k3 domain trusts the w2k domain.

Regards,

Ross Bale.

"SPollack" wrote:

>
> Can you actually create & validate the trust in AD Domains & trust. If
> you can then u can use Netdom command instead to verify the trust
> between the two domains. I believe the systax is like this:
> netdom trust /d:firstdomain 2ndomain /verify /twoway
>
>
> --
> SPollack
> ------------------------------------------------------------------------
> SPollack's Profile: http://forums.techarena.in/members/5880.htm
> View this thread: Establish Windows 2000 to 2003 Active Directory Domain Trust with
> Visit - http://forums.techarena.in/archive/index.php/
>
>

Reply With Quote
  #4  
Old 06-05-2005
Member
 
Join Date: Apr 2005
Posts: 4
Whats the error message that you get when you try to validate the trust using the Gui?
Reply With Quote
  #5  
Old 06-05-2005
Ross Bale
 
Posts: n/a
Re: Establish Windows 2000 to 2003 Active Directory Domain Trust w

I haven't tried to validate the trust using the GUI as there was an Error in
the W2K Domain Controller System Event Log:
Source: NetLogon
Event ID: 5721
The session setup to the Windows NT or Windows 2000 Domain controller
<unknown> for the Domain xxx failed because the Domain Controller does not
have an account for the computer xxxxx.

Domain xxx is the remote domain AD 2003, computer xxxx is the domain
controller for the local domain W2K.

"SPollack" wrote:

>
> Whats the error message that you get when you try to validate the trust
> using the Gui?
>
>
> --
> SPollack
> ------------------------------------------------------------------------
> SPollack's Profile: http://forums.techarena.in/members/5880.htm
> View this thread: Establish Windows 2000 to 2003 Active Directory Domain Trust with
> Visit - http://forums.techarena.in/archive/index.php/
>
>

Reply With Quote
  #6  
Old 07-05-2005
Member
 
Join Date: Apr 2005
Posts: 4
The only thing that comes to my mind right now is to verify that the secure channel is not broken and that netlogon service has started.
Reply With Quote
  #7  
Old 07-05-2005
ptwilliams
 
Posts: n/a
Re: Establish Windows 2000 to 2003 Active Directory Domain Trust w

Delete the trust, fix name resolution and create the trust again.

You need to be able to resolve SRV RRs in the other domain, particularly the
PDCe (and you must be able to physically contact the PDCe).

This is usually done through holding a secondary copy of that zone file.

Look at using NETDOM to delete the trust. However you could, as suggested
by SPollack, simply try resetting the secure channel --however, the trust
hasn't properly been created in my eyes.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net


Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Establish Windows 2000 to 2003 Active Directory Domain Trust with"
Thread Thread Starter Forum Replies Last Post
Software Restriction Policies using Windows 2003 Active Directory domain Group Policy Spin Active Directory 3 17-06-2009 01:40 AM
question on upgrading from active directory 2000 to active directory 2003 Gary M Window 2000 Help 2 17-03-2007 02:27 AM
A health-check script for Active Directory on Win 2000/2003 JackFlash Active Directory 5 19-02-2007 02:44 PM
Establish trust between NT 4 domain and 2003 native Bill Active Directory 7 06-09-2006 07:19 PM
Unable to establish trust with Windows 2003 Domain James Active Directory 8 03-06-2005 05:04 AM


All times are GMT +5.5. The time now is 02:09 PM.