Networking Forums

Networking Forums > Computer Networking > Windows Networking > Another Trust issue

Reply
Thread Tools Display Modes

Another Trust issue

 
 
MS News
Guest
Posts: n/a

 
      01-15-2004, 10:28 PM
I have three domains. Two NT and one AD. I can establish a trust between one
of the NT1 domains and the AD domain, and I can establish a trust between
the two NT domains, but I can not establish a trust between the second NT2
domain and the AD domain. I get the error "No logon servers available"

I have checked the lmhosts and removed and added the trusts several times
between the NT2 and the AD domain and still nothing.

Using the Domain monitor on the AD server I can see NT1 fine. The NT2 domain
is red with no trusted domains listed in that column. When I look at the
properties for NT2 I see the following: DC Name - \\NT2Server, DC State -
OnLine, DC Status - AccDeni, Replication Status - Unknown, Connection to
PDC - BadPath, Link to Trusted Domain - Success

Using the Domain Monitor on the NT2 server I can see the NT1 fine. The AD is
red with all the lines filled in properly. When I select the properties I
have two servers listed, which are both AD DCs. The first server is insync
and everything looks good. the second server has DC Status - NoLogSr,
Connection to PDC - Bad Path, Link to Trusted Domain - Error


 
Reply With Quote
 
 
 
 
David Brandt [MSFT]
Guest
Posts: n/a

 
      01-16-2004, 01:16 PM
I'm not sure what exactly you put in your lmhosts file, but but for those
two that aren't working, be sure that it includes the 1B registration for
both the nt4 pdc and your win2k pdce. If that isn't there, you can look at
the following to get it in there, and be sure that you see the registration
with you run nbtstat;
180094 How to Write an LMHOSTS File for Domain Validation and Other Name
http://support.microsoft.com/?id=180094

Also compare the following registry entries between the one nt4 pdc that
will set the trust with win2k, and the one where it won't.
Restrictanonymous is a fairly common cause, and may need to be set to "0",
at least initially to get the trust established;
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Contro l\LSA\Lmcompatibilitylevel

And

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\LSA\restrictanonymous





--
David Brandt
Microsoft Corporation

This posting is provided "AS IS" with no warranties, and confers no rights.
Please do not send e-mail directly to this alias. This alias is for
newsgroup purposes only.
"MS News" <(E-Mail Removed)> wrote in message
news:%(E-Mail Removed)...
> I have three domains. Two NT and one AD. I can establish a trust between

one
> of the NT1 domains and the AD domain, and I can establish a trust between
> the two NT domains, but I can not establish a trust between the second NT2
> domain and the AD domain. I get the error "No logon servers available"
>
> I have checked the lmhosts and removed and added the trusts several times
> between the NT2 and the AD domain and still nothing.
>
> Using the Domain monitor on the AD server I can see NT1 fine. The NT2

domain
> is red with no trusted domains listed in that column. When I look at the
> properties for NT2 I see the following: DC Name - \\NT2Server, DC State -
> OnLine, DC Status - AccDeni, Replication Status - Unknown, Connection to
> PDC - BadPath, Link to Trusted Domain - Success
>
> Using the Domain Monitor on the NT2 server I can see the NT1 fine. The AD

is
> red with all the lines filled in properly. When I select the properties I
> have two servers listed, which are both AD DCs. The first server is insync
> and everything looks good. the second server has DC Status - NoLogSr,
> Connection to PDC - Bad Path, Link to Trusted Domain - Error
>
>



 
Reply With Quote
 
MS News
Guest
Posts: n/a

 
      01-16-2004, 11:12 PM
I did all that, still no luck.

"David Brandt [MSFT]" <(E-Mail Removed)> wrote in message
news:4007f258$(E-Mail Removed)...
> I'm not sure what exactly you put in your lmhosts file, but but for those
> two that aren't working, be sure that it includes the 1B registration for
> both the nt4 pdc and your win2k pdce. If that isn't there, you can look

at
> the following to get it in there, and be sure that you see the

registration
> with you run nbtstat;
> 180094 How to Write an LMHOSTS File for Domain Validation and Other Name
> http://support.microsoft.com/?id=180094
>
> Also compare the following registry entries between the one nt4 pdc that
> will set the trust with win2k, and the one where it won't.
> Restrictanonymous is a fairly common cause, and may need to be set to "0",
> at least initially to get the trust established;
>

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Contro l\LSA\Lmcompatibilitylevel
>
> And
>
> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\LSA\restrictanonymous
>
>
>
>
>
> --
> David Brandt
> Microsoft Corporation
>
> This posting is provided "AS IS" with no warranties, and confers no

rights.
> Please do not send e-mail directly to this alias. This alias is for
> newsgroup purposes only.
> "MS News" <(E-Mail Removed)> wrote in message
> news:%(E-Mail Removed)...
> > I have three domains. Two NT and one AD. I can establish a trust between

> one
> > of the NT1 domains and the AD domain, and I can establish a trust

between
> > the two NT domains, but I can not establish a trust between the second

NT2
> > domain and the AD domain. I get the error "No logon servers available"
> >
> > I have checked the lmhosts and removed and added the trusts several

times
> > between the NT2 and the AD domain and still nothing.
> >
> > Using the Domain monitor on the AD server I can see NT1 fine. The NT2

> domain
> > is red with no trusted domains listed in that column. When I look at the
> > properties for NT2 I see the following: DC Name - \\NT2Server, DC

State -
> > OnLine, DC Status - AccDeni, Replication Status - Unknown, Connection to
> > PDC - BadPath, Link to Trusted Domain - Success
> >
> > Using the Domain Monitor on the NT2 server I can see the NT1 fine. The

AD
> is
> > red with all the lines filled in properly. When I select the properties

I
> > have two servers listed, which are both AD DCs. The first server is

insync
> > and everything looks good. the second server has DC Status - NoLogSr,
> > Connection to PDC - Bad Path, Link to Trusted Domain - Error
> >
> >

>
>



 
Reply With Quote
 
Michael Giorgio - MS MVP
Guest
Posts: n/a

 
      01-20-2004, 01:04 PM
Open a dos prompt and run nbtstat -c on the W2k DC
then mark, copy and post the contents. You can mask
the names and tcp/ip addresses.

"MS News" <(E-Mail Removed)> wrote in message
> I did all that, still no luck.



 
Reply With Quote
 
MS News
Guest
Posts: n/a

 
      01-20-2004, 09:45 PM
Local Area Connection:
Node IpAddress: [10.0.0.8] Scope Id: []

NetBIOS Remote Cache Name Table

Name Type Host Address Life [sec]
------------------------------------------------------------
AD <1C> GROUP 10.0.0.12 -1
NT1 <1C> GROUP 10.10.0.24 -1
NT1 <1C> GROUP 10.0.0.67 -1
NT1 <1B> UNIQUE 10.0.0.67 -1
NT1Server <03> UNIQUE 10.0.0.67 -1
NT1Server <00> UNIQUE 10.0.0.67 -1
NT1Server <20> UNIQUE 10.0.0.67 -1
NT2 <1B> UNIQUE 10.10.0.24 -1
NT2Server <03> UNIQUE 10.10.0.24 -1
NT2Server <00> UNIQUE 10.10.0.24 -1
NT2Server <20> UNIQUE 10.10.0.24 -1


"Michael Giorgio - MS MVP" <(E-Mail Removed)> wrote in
message news:uxqfE%(E-Mail Removed)...
> Open a dos prompt and run nbtstat -c on the W2k DC
> then mark, copy and post the contents. You can mask
> the names and tcp/ip addresses.
>
> "MS News" <(E-Mail Removed)> wrote in message
> > I did all that, still no luck.

>
>



 
Reply With Quote
 
MS News
Guest
Posts: n/a

 
      01-20-2004, 09:47 PM
From the win2k server.

C:\WINDOWS\system32\drivers\etc>net view \\nt2
System error 5 has occurred.

Access is denied.

"MS News" <(E-Mail Removed)> wrote in message
news:%(E-Mail Removed)...
> I have three domains. Two NT and one AD. I can establish a trust between

one
> of the NT1 domains and the AD domain, and I can establish a trust between
> the two NT domains, but I can not establish a trust between the second NT2
> domain and the AD domain. I get the error "No logon servers available"
>
> I have checked the lmhosts and removed and added the trusts several times
> between the NT2 and the AD domain and still nothing.
>
> Using the Domain monitor on the AD server I can see NT1 fine. The NT2

domain
> is red with no trusted domains listed in that column. When I look at the
> properties for NT2 I see the following: DC Name - \\NT2Server, DC State -
> OnLine, DC Status - AccDeni, Replication Status - Unknown, Connection to
> PDC - BadPath, Link to Trusted Domain - Success
>
> Using the Domain Monitor on the NT2 server I can see the NT1 fine. The AD

is
> red with all the lines filled in properly. When I select the properties I
> have two servers listed, which are both AD DCs. The first server is insync
> and everything looks good. the second server has DC Status - NoLogSr,
> Connection to PDC - Bad Path, Link to Trusted Domain - Error
>
>



 
Reply With Quote
 
MS News
Guest
Posts: n/a

 
      01-20-2004, 11:17 PM
This might help. I orginally installed the 2k3 server with a different
domain name. At that time the trust worked. I then decided to change the
domain name so I completely reinstalled the 2k3 with the same server name,
but new domain name. Now the trust does not work.


"MS News" <(E-Mail Removed)> wrote in message
news:%(E-Mail Removed)...
> I have three domains. Two NT and one AD. I can establish a trust between

one
> of the NT1 domains and the AD domain, and I can establish a trust between
> the two NT domains, but I can not establish a trust between the second NT2
> domain and the AD domain. I get the error "No logon servers available"
>
> I have checked the lmhosts and removed and added the trusts several times
> between the NT2 and the AD domain and still nothing.
>
> Using the Domain monitor on the AD server I can see NT1 fine. The NT2

domain
> is red with no trusted domains listed in that column. When I look at the
> properties for NT2 I see the following: DC Name - \\NT2Server, DC State -
> OnLine, DC Status - AccDeni, Replication Status - Unknown, Connection to
> PDC - BadPath, Link to Trusted Domain - Success
>
> Using the Domain Monitor on the NT2 server I can see the NT1 fine. The AD

is
> red with all the lines filled in properly. When I select the properties I
> have two servers listed, which are both AD DCs. The first server is insync
> and everything looks good. the second server has DC Status - NoLogSr,
> Connection to PDC - Bad Path, Link to Trusted Domain - Error
>
>



 
Reply With Quote
 
MS News
Guest
Posts: n/a

 
      01-20-2004, 11:36 PM
I don't know if this mens anything or not.
I added the AD server to the Server Manager in the NT2 computer. If I select
the AD server I can see everything. Not only that but I can change to the AD
domain in the Server Manager and see all the computer, shares and everything
in the AD domain. But if I try to add AD domain users to a folder it can't
browse the corp domain. I am assuming that that means that one way of the
trust works, but not the other.


"MS News" <(E-Mail Removed)> wrote in message
news:%(E-Mail Removed)...
> I have three domains. Two NT and one AD. I can establish a trust between

one
> of the NT1 domains and the AD domain, and I can establish a trust between
> the two NT domains, but I can not establish a trust between the second NT2
> domain and the AD domain. I get the error "No logon servers available"
>
> I have checked the lmhosts and removed and added the trusts several times
> between the NT2 and the AD domain and still nothing.
>
> Using the Domain monitor on the AD server I can see NT1 fine. The NT2

domain
> is red with no trusted domains listed in that column. When I look at the
> properties for NT2 I see the following: DC Name - \\NT2Server, DC State -
> OnLine, DC Status - AccDeni, Replication Status - Unknown, Connection to
> PDC - BadPath, Link to Trusted Domain - Success
>
> Using the Domain Monitor on the NT2 server I can see the NT1 fine. The AD

is
> red with all the lines filled in properly. When I select the properties I
> have two servers listed, which are both AD DCs. The first server is insync
> and everything looks good. the second server has DC Status - NoLogSr,
> Connection to PDC - Bad Path, Link to Trusted Domain - Error
>
>



 
Reply With Quote
 
Michael Giorgio - MS MVP
Guest
Posts: n/a

 
      01-21-2004, 02:54 PM
Assuming the NT1 1c group name pointing towards
tcp/ip address 10.10.0.24 is a typo and should be NT2?
I think name resolution looks good. I suspect something
is blocking the necessary netbios traffic between the two
domains e.g., router or firewall.

"MS News" <(E-Mail Removed)> wrote in message
> Local Area Connection:
> Node IpAddress: [10.0.0.8] Scope Id: []
>
> NetBIOS Remote Cache Name Table
>
> Name Type Host Address Life [sec]
> ------------------------------------------------------------
> AD <1C> GROUP 10.0.0.12 -1
> NT1 <1C> GROUP 10.10.0.24 -1
> NT1 <1C> GROUP 10.0.0.67 -1
> NT1 <1B> UNIQUE 10.0.0.67 -1
> NT1Server <03> UNIQUE 10.0.0.67 -1
> NT1Server <00> UNIQUE 10.0.0.67 -1
> NT1Server <20> UNIQUE 10.0.0.67 -1
> NT2 <1B> UNIQUE 10.10.0.24 -1
> NT2Server <03> UNIQUE 10.10.0.24 -1
> NT2Server <00> UNIQUE 10.10.0.24 -1
> NT2Server <20> UNIQUE 10.10.0.24 -1
>
>
> "Michael Giorgio - MS MVP" <(E-Mail Removed)> wrote

in
> message news:uxqfE%(E-Mail Removed)...
> > Open a dos prompt and run nbtstat -c on the W2k DC
> > then mark, copy and post the contents. You can mask
> > the names and tcp/ip addresses.
> >
> > "MS News" <(E-Mail Removed)> wrote in message
> > > I did all that, still no luck.

> >
> >

>
>



 
Reply With Quote
 
MS News
Guest
Posts: n/a

 
      01-21-2004, 08:44 PM
Your correct looks like a typo.

There is a router separating the two domains. I have an NT trust between the
two working. NT1 and NT2 trust each other fine. NT1 is on the same side of
the router as AD.

In another email I mentioned that I had the trust working at one time. I
changed the name of the AD domain by completely reinstalling win2k3. I used
the same server name, but different domain name. Now I can not get it to
connect.

"Michael Giorgio - MS MVP" <(E-Mail Removed)> wrote in
message news:Ouy$(E-Mail Removed)...
> Assuming the NT1 1c group name pointing towards
> tcp/ip address 10.10.0.24 is a typo and should be NT2?
> I think name resolution looks good. I suspect something
> is blocking the necessary netbios traffic between the two
> domains e.g., router or firewall.
>
> "MS News" <(E-Mail Removed)> wrote in message
> > Local Area Connection:
> > Node IpAddress: [10.0.0.8] Scope Id: []
> >
> > NetBIOS Remote Cache Name Table
> >
> > Name Type Host Address Life [sec]
> > ------------------------------------------------------------
> > AD <1C> GROUP 10.0.0.12 -1
> > NT1 <1C> GROUP 10.10.0.24 -1
> > NT1 <1C> GROUP 10.0.0.67 -1
> > NT1 <1B> UNIQUE 10.0.0.67 -1
> > NT1Server <03> UNIQUE 10.0.0.67 -1
> > NT1Server <00> UNIQUE 10.0.0.67 -1
> > NT1Server <20> UNIQUE 10.0.0.67 -1
> > NT2 <1B> UNIQUE 10.10.0.24 -1
> > NT2Server <03> UNIQUE 10.10.0.24 -1
> > NT2Server <00> UNIQUE 10.10.0.24 -1
> > NT2Server <20> UNIQUE 10.10.0.24 -1
> >
> >
> > "Michael Giorgio - MS MVP" <(E-Mail Removed)> wrote

> in
> > message news:uxqfE%(E-Mail Removed)...
> > > Open a dos prompt and run nbtstat -c on the W2k DC
> > > then mark, copy and post the contents. You can mask
> > > the names and tcp/ip addresses.
> > >
> > > "MS News" <(E-Mail Removed)> wrote in message
> > > > I did all that, still no luck.
> > >
> > >

> >
> >

>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Lost trust issue steve.quist@biotronik.com Windows Networking 0 09-17-2009 01:31 PM
No logon server available - Windows 2003 Trust Issue? NS Issue? newsgroups.jd@gmail.com Windows Networking 15 08-21-2006 07:38 PM
Senao 2611CB3+Deluxe setup issue, network configuration issue, orboth? RWM Wireless Internet 0 01-27-2006 06:00 PM
Exchange / Trust Issue Mark Williams Windows Networking 1 07-22-2004 03:17 PM
NT4 Trust across a VPN NAT HELP Fast Eddie Windows Networking 1 06-17-2004 02:14 PM



1 2 3 4 5 6 7 8 9 10 11