Networking Forums

Networking Forums > Computer Networking > Windows Networking > Domain Trust over VPN...

Reply
Thread Tools Display Modes

Domain Trust over VPN...

 
 
Mike
Guest
Posts: n/a

 
      12-29-2005, 12:35 AM
Our company has 2 AD domains, abc.com (192.168.100.xxx) & xyz.com
(172.32.1.xxx).
They are in separate locations, I have a SonicWall TZ-170 on each end & have
a VPN connection between them.
I have WINS set up on each end, with each WINS server set as a push/pull
partner with the other server.
How can I get them to trust each other?
When I go to AD Domains & Trusts on abc & try to set xyz as a trusted
domain, what password is it wanting? Domain Admin password? If I try that,
it tells me that the domain can't be contacted. I can ping computers in the
other domain by IP address, but not by name.
Both DCs are set as DNS servers-do I need to add dns records for the other
domain?
Is there a way to have my DNS servers replicate between domains?


 
Reply With Quote
 
 
 
 
Todd J Heron
Guest
Posts: n/a

 
      12-29-2005, 01:24 AM
Hi, it wants the password you created during the establishment of the trust
not the domain admin password.

--
Todd J Heron, MCSE
Windows Server 2003/2000/NT; CCA

"Mike" <(E-Mail Removed)> wrote in message
news:%(E-Mail Removed)...
> Our company has 2 AD domains, abc.com (192.168.100.xxx) & xyz.com
> (172.32.1.xxx).
> They are in separate locations, I have a SonicWall TZ-170 on each end &
> have a VPN connection between them.
> I have WINS set up on each end, with each WINS server set as a push/pull
> partner with the other server.
> How can I get them to trust each other?
> When I go to AD Domains & Trusts on abc & try to set xyz as a trusted
> domain, what password is it wanting? Domain Admin password? If I try that,
> it tells me that the domain can't be contacted. I can ping computers in
> the other domain by IP address, but not by name.
> Both DCs are set as DNS servers-do I need to add dns records for the other
> domain?
> Is there a way to have my DNS servers replicate between domains?
>
>


 
Reply With Quote
 
Bill Grant
Guest
Posts: n/a

 
      12-29-2005, 02:17 AM
Regarding DNS. A common method with two sites is to make each DNS server
a secondary for the "other" primary zone. That way each site DNS can resolve
addresses for either zone.

Todd J Heron wrote:
> Hi, it wants the password you created during the establishment of the
> trust not the domain admin password.
>
>
> "Mike" <(E-Mail Removed)> wrote in message
> news:%(E-Mail Removed)...
>> Our company has 2 AD domains, abc.com (192.168.100.xxx) & xyz.com
>> (172.32.1.xxx).
>> They are in separate locations, I have a SonicWall TZ-170 on each
>> end & have a VPN connection between them.
>> I have WINS set up on each end, with each WINS server set as a
>> push/pull partner with the other server.
>> How can I get them to trust each other?
>> When I go to AD Domains & Trusts on abc & try to set xyz as a trusted
>> domain, what password is it wanting? Domain Admin password? If I try
>> that, it tells me that the domain can't be contacted. I can ping
>> computers in the other domain by IP address, but not by name.
>> Both DCs are set as DNS servers-do I need to add dns records for the
>> other domain?
>> Is there a way to have my DNS servers replicate between domains?



 
Reply With Quote
 
Mike
Guest
Posts: n/a

 
      12-29-2005, 02:47 AM
It never gave me an option to create a password.

"Todd J Heron" <todd_heron(delete)@hotmail.com> wrote in message
news:%(E-Mail Removed)...
> Hi, it wants the password you created during the establishment of the
> trust not the domain admin password.
>
> --
> Todd J Heron, MCSE
> Windows Server 2003/2000/NT; CCA
>
> "Mike" <(E-Mail Removed)> wrote in message
> news:%(E-Mail Removed)...
>> Our company has 2 AD domains, abc.com (192.168.100.xxx) & xyz.com
>> (172.32.1.xxx).
>> They are in separate locations, I have a SonicWall TZ-170 on each end &
>> have a VPN connection between them.
>> I have WINS set up on each end, with each WINS server set as a push/pull
>> partner with the other server.
>> How can I get them to trust each other?
>> When I go to AD Domains & Trusts on abc & try to set xyz as a trusted
>> domain, what password is it wanting? Domain Admin password? If I try
>> that, it tells me that the domain can't be contacted. I can ping
>> computers in the other domain by IP address, but not by name.
>> Both DCs are set as DNS servers-do I need to add dns records for the
>> other domain?
>> Is there a way to have my DNS servers replicate between domains?
>>
>>

>



 
Reply With Quote
 
Mike
Guest
Posts: n/a

 
      12-29-2005, 01:57 PM
Did that & I can ping computers in other domain by name or address.
Shouldn't I see the other domain in Network Neighborhood?

"Bill Grant" <not.available@online> wrote in message
news:(E-Mail Removed)...
> Regarding DNS. A common method with two sites is to make each DNS
> server a secondary for the "other" primary zone. That way each site DNS
> can resolve addresses for either zone.
>
> Todd J Heron wrote:
>> Hi, it wants the password you created during the establishment of the
>> trust not the domain admin password.
>>
>>
>> "Mike" <(E-Mail Removed)> wrote in message
>> news:%(E-Mail Removed)...
>>> Our company has 2 AD domains, abc.com (192.168.100.xxx) & xyz.com
>>> (172.32.1.xxx).
>>> They are in separate locations, I have a SonicWall TZ-170 on each
>>> end & have a VPN connection between them.
>>> I have WINS set up on each end, with each WINS server set as a
>>> push/pull partner with the other server.
>>> How can I get them to trust each other?
>>> When I go to AD Domains & Trusts on abc & try to set xyz as a trusted
>>> domain, what password is it wanting? Domain Admin password? If I try
>>> that, it tells me that the domain can't be contacted. I can ping
>>> computers in the other domain by IP address, but not by name.
>>> Both DCs are set as DNS servers-do I need to add dns records for the
>>> other domain?
>>> Is there a way to have my DNS servers replicate between domains?

>
>



 
Reply With Quote
 
Dave Shaw [MVP - Directory Services]
Guest
Posts: n/a

 
      12-29-2005, 08:34 PM
Are these domains in separate forests?

-ds


"Mike" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> It never gave me an option to create a password.
>
> "Todd J Heron" <todd_heron(delete)@hotmail.com> wrote in message
> news:%(E-Mail Removed)...
>> Hi, it wants the password you created during the establishment of the
>> trust not the domain admin password.
>>
>> --
>> Todd J Heron, MCSE
>> Windows Server 2003/2000/NT; CCA
>>
>> "Mike" <(E-Mail Removed)> wrote in message
>> news:%(E-Mail Removed)...
>>> Our company has 2 AD domains, abc.com (192.168.100.xxx) & xyz.com
>>> (172.32.1.xxx).
>>> They are in separate locations, I have a SonicWall TZ-170 on each end &
>>> have a VPN connection between them.
>>> I have WINS set up on each end, with each WINS server set as a push/pull
>>> partner with the other server.
>>> How can I get them to trust each other?
>>> When I go to AD Domains & Trusts on abc & try to set xyz as a trusted
>>> domain, what password is it wanting? Domain Admin password? If I try
>>> that, it tells me that the domain can't be contacted. I can ping
>>> computers in the other domain by IP address, but not by name.
>>> Both DCs are set as DNS servers-do I need to add dns records for the
>>> other domain?
>>> Is there a way to have my DNS servers replicate between domains?
>>>
>>>

>>

>
>



 
Reply With Quote
 
Bill Grant
Guest
Posts: n/a

 
      12-29-2005, 10:33 PM
No. Network Neighborhood is driven by the computer browser service, not
DNS. The computer browser service relies on broadcasts and uses Netbios
names. It is not reliable across a WAN. It might work if you set up
networkwideWINS so that the master browsers can find each other across the
WAN link.

Mike wrote:
> Did that & I can ping computers in other domain by name or address.
> Shouldn't I see the other domain in Network Neighborhood?
>
> "Bill Grant" <not.available@online> wrote in message
> news:(E-Mail Removed)...
>> Regarding DNS. A common method with two sites is to make each DNS
>> server a secondary for the "other" primary zone. That way each site
>> DNS can resolve addresses for either zone.
>>
>> Todd J Heron wrote:
>>> Hi, it wants the password you created during the establishment of
>>> the trust not the domain admin password.
>>>
>>>
>>> "Mike" <(E-Mail Removed)> wrote in message
>>> news:%(E-Mail Removed)...
>>>> Our company has 2 AD domains, abc.com (192.168.100.xxx) & xyz.com
>>>> (172.32.1.xxx).
>>>> They are in separate locations, I have a SonicWall TZ-170 on each
>>>> end & have a VPN connection between them.
>>>> I have WINS set up on each end, with each WINS server set as a
>>>> push/pull partner with the other server.
>>>> How can I get them to trust each other?
>>>> When I go to AD Domains & Trusts on abc & try to set xyz as a
>>>> trusted domain, what password is it wanting? Domain Admin
>>>> password? If I try that, it tells me that the domain can't be
>>>> contacted. I can ping computers in the other domain by IP address,
>>>> but not by name. Both DCs are set as DNS servers-do I need to add dns
>>>> records for
>>>> the other domain?
>>>> Is there a way to have my DNS servers replicate between domains?



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
domain trust Blake Windows Networking 3 11-14-2008 04:05 PM
Domain 2K-SBS + Trust or connection Frank Jacobs Windows Networking 3 05-04-2006 01:26 PM
trust domain win2003 with domain nt4 called INTERNET (HELP!!) Jeiden Windows Networking 0 06-22-2005 09:39 PM
trust between a domain & Workgroup? Brian Windows Networking 4 05-02-2005 02:35 PM
Domain Trust with Windows NT Thomas Windows Networking 2 08-13-2004 06:56 PM



1 2 3 4 5 6 7 8 9 10 11