Trust between old 2000 domain and new 2003 domain

T

Tim Moen

I just finished setting up a new 2003 domain and I cannot
get a trust set up between this domain and our old 2000
domain. Both domains are in Native mode. I create a two-
way trust from the 2003 domain and it seems to work.
When you set up the trust from the 2000 domain it says
that it cannot find the 2003 domain and it fails. Any
ideas?

Tim

(e-mail address removed)
 
P

ptwilliams

How are you resolving names in the 2003 domain from the 200 side??

How are you resolving names in the 2000 domain from the 2003 side?

How are you trying to create the trust?


--

Paul Williams
http://www.msresource.net


Why not join us in our free, public forum?
http://forums.msresource.net
______________________________________
I just finished setting up a new 2003 domain and I cannot
get a trust set up between this domain and our old 2000
domain. Both domains are in Native mode. I create a two-
way trust from the 2003 domain and it seems to work.
When you set up the trust from the 2000 domain it says
that it cannot find the 2003 domain and it fails. Any
ideas?

Tim

(e-mail address removed)
 
T

Tim

Here's the whole story: The 2000 domain is pg.com with a
10.10.11.x network. The DC is 10.10.11.5. The new 2003
domain (etm.com) is eventually going to have a 10.10.13.x
network and be moved off site. However, in the mean time
I need to give it a 10.10.13.x network to create a trust
and move Exchange mailboxes over. Right now I gave the
DC on 2003 a static IP of 10.10.11.104 static IP and I
have 10.10.13.5 (DC on the 2000 network) as the DNS.
When I originally installed the 2003 domain I had used
the 10.10.13.x network, but changed it to the 10.10.11.x
network later.

To create the trust on 2003 I go into ADDT, right click
on the etm.com, go into properties, then to the Trusts
tab, then to New Trust. I type in PG.com then choose Two
Way for the direction of the trust. Then I choose This
Domain Only, and Domain-wide authentication, then enter a
password. It then tells me I must create the trust from
the other end.

On the 2000 side I do a similar thing, but it just asks
for the other domain and a password. It then informs me
that it cannot contact the other domain.

Any help at all would be appreciated.

Tim
(e-mail address removed)
 
P

ptwilliams

How are you resolving names in each forest (I assume, as you have to create
the trust manually these domains reside in different forests)?

There are several ways of doing this, more with 2003 (I think). One way is
for each domain to hold a secondary copy of the other's zone, e.g. domA has
both it's own DNS zone(s) and a secondary (read-only) copy of domB's too.

Another option is to forward to the other DNS servers. Conditional
forwarding is another.

In order to create that trust, you have to be able to locate the domain
controller - which means the SRV records.


--

Paul Williams
http://www.msresource.net


Why not join us in our free, public forum?
http://forums.msresource.net
______________________________________
Here's the whole story: The 2000 domain is pg.com with a
10.10.11.x network. The DC is 10.10.11.5. The new 2003
domain (etm.com) is eventually going to have a 10.10.13.x
network and be moved off site. However, in the mean time
I need to give it a 10.10.13.x network to create a trust
and move Exchange mailboxes over. Right now I gave the
DC on 2003 a static IP of 10.10.11.104 static IP and I
have 10.10.13.5 (DC on the 2000 network) as the DNS.
When I originally installed the 2003 domain I had used
the 10.10.13.x network, but changed it to the 10.10.11.x
network later.

To create the trust on 2003 I go into ADDT, right click
on the etm.com, go into properties, then to the Trusts
tab, then to New Trust. I type in PG.com then choose Two
Way for the direction of the trust. Then I choose This
Domain Only, and Domain-wide authentication, then enter a
password. It then tells me I must create the trust from
the other end.

On the 2000 side I do a similar thing, but it just asks
for the other domain and a password. It then informs me
that it cannot contact the other domain.

Any help at all would be appreciated.

Tim
(e-mail address removed)
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top