Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

strange dns/trust problem

Status
Not open for further replies.

bookouri

IS-IT--Management
Feb 23, 2000
1,464
US
Our forest has a trust relationship with another forest in the company. Both forests are running 2008 server dc's (mixed mode) and have forwarders to each other. We have shares on the other forest that our users have to get to. Periodically users get an error message: "no logon servers available" when they try to get to the other forest share. They can still ping the server by name or IP address, but they are not allowed to get in to the share. It doesnt seem to be a name resolution problem or DNS problem, BUT the only fix we have found is calling up the admin at the other forest and having them reload our dns in their dns servers. At that point the users are once again able to get to their files and everything works fine for a day or two or a few hours and then it starts over again.

We have researched this for weeks and tried anything we could find but have not been able to solve the problem.

anybody have any suggestions? ideas?

 
Get rid of the forwarders and just run a secondary off the other forest in DNS.
 
thanks, ill take a look at that.
 
Or use a Stub Zone. There's less maintenance involved that way and then you don't have to deal with what happens when you secondary zone has stale records. It does generate more a little more traffic, but you get the advantage of always getting answers from their DNS.

________________________________________
CompTIA A+, Network+, Server+, Security+
MCTS:Windows 7
MCSE:Security 2003
MCITP:Server Administrator
MCITP:Enterprise Administrator
MCITP:Virtualization Administrator 2008 R2
Certified Quest vWorkspace Administrator
 
i think i tried stub zones at one time when this problem started.. but ive tried so much i cant really remember at this point.. the odd thing is that the other guy's forest has to reload our dns records on his end.. doesnt seem to help for me to do it on my end.. i still dont understand exactly whats happening when one of my clients tries to access one of his shares.. even though my clients can ping/resolve the node name, they're refused access to the share...
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top