Controlling Trust Traffic

A

AJ

Hi Guys

I have a trust linking two forests together (Windows 2003 and Windows
2008R2). I want the trust to only ever create its secure channel with
two specific domain controllers in one of the forests, so if one fails
the other DC is used as the endpoint. Basically we want to limit the
machines that one of the forests communicates with for authentication
requests. I know you can reset the secure channel using NLTEST etc but
we need to be able to restrcit the trust from jumping to other DCs in
the forest, how can we do this? I dont think creating an additional
site in the forest and installing the domain controllers we want to
handle the auth requests would help, becuase I dont beleive trusts are
site aware and it would ignore the site boundary. Is this possible?

TIA
AJ
 
A

Ace Fekay [MVP-DS, MCT]

AJ said:
Hi Guys

I have a trust linking two forests together (Windows 2003 and Windows
2008R2). I want the trust to only ever create its secure channel with
two specific domain controllers in one of the forests, so if one fails
the other DC is used as the endpoint. Basically we want to limit the
machines that one of the forests communicates with for authentication
requests. I know you can reset the secure channel using NLTEST etc but
we need to be able to restrcit the trust from jumping to other DCs in
the forest, how can we do this? I dont think creating an additional
site in the forest and installing the domain controllers we want to
handle the auth requests would help, becuase I dont beleive trusts are
site aware and it would ignore the site boundary. Is this possible?

TIA
AJ


Actually, the trusts end points are the PDC Emulators. Is there any reason you are trying to do it this way in your scenario? Are there any communications restrictions?

--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and confers no rights.

Please reply back to the newsgroup or forum for collaboration benefit among responding engineers, and to help others benefit from your resolution.

Ace Fekay, MVP, MCT, MCITP EA, MCTS Windows 2008 & Exchange 2007, MCSE & MCSA 2003/2000, MCSA Messaging 2003
Microsoft Certified Trainer
Microsoft MVP - Directory Services

If you feel this is an urgent issue and require immediate assistance, please contact Microsoft PSS directly. Please check http://support.microsoft.com for regional support phone numbers.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top