Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

DFS replication between two trusting domains

Status
Not open for further replies.

cchipman

IS-IT--Management
Sep 16, 2002
125
US
The scenario:

We've split off another company and they have their own Server2003 AD based domain. I've set up DFS on it, and can set up a link on their DFS root to their data contained upon our (the original company) servers.

Our domain is a Win2k AD domain.

What I'd like to do is set up the replication between a folder on their server and upon their project data already located in our DFS tree.

When I attempt to add the replica to the set however, (regardless of which DFS tree I try to do it from), it does not work. From the 2003 machine, when I run the Configure Replication Wizard it show "Unknown" for the staging folder and gives a status message of "Unknown: Access is Denied"

Has anyone seen this behaviour or handled this circumstance? I figure that I need to add some permission, but I'm not sure which one...
 
do you have trusts set up between the domains?

if so how? are they separate forests or parent/child?
 
Yah, we have trusts set up in both directions between the forests.

People in Domain1 can access resrouces in Domain2 (as long as they are given proper permissions) and vice versa...

 
This is covered in the DFS FAQ up on Here's the info:

If you are a member of the Enterprise Admins group, you can configure FRS replication on a DFS link whose targets are in different domains. If you are not a member of the Enterprise Admins group, permissions must be configured as follows:

You must have Read and Create All Child Objects permissions for the computer object of each computer that will be part of the replica set.

You must be a member of the local Administrators group on each computer that will be part of the replica set.

You must have Read and Create All Child Objects permissions for the File Replication Service container and all its child objects. Although the File Replication Service container can exist in every domain, you must add these permissions to the File Replication Service container that is in the domain where the domain-based root is configured.

If any of these permissions are not configured correctly, you will get an Access Denied message when you try to enable replication by using the Configure Replication Wizard in the Distributed File System snap-in. For more information, see article 296183, "Overview of Active Directory Objects That Are Used by FRS" at
 
What if the domains are in different forests? One of the domains is nomadics.com and the other is engius.com
 
Sorry, I missed your second post that these were in different forests. FRS replication only works across trusted domains within the same forest.
 
@#$@$ %@@#$ That's what I was afraid of... its okay as I can manually copy the files over using robocopy, but was wanting to do the uber-lazy way and to provide the ability to allow users in both domains to work off their respective computers...

Oh well.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top