Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

when creating new Forest does it need to be published? 2

Status
Not open for further replies.

blade10

IS-IT--Management
Feb 2, 2008
144
US
All-

When creating a new disparate Forest does it need to be published with an ISP in order for the administrator to create a trust to it from the Admin's corporate domain?

Is the only way to see this forest root domain is by having its parent dns name placed on an ISP's name server.


thanks for any info at all and have a Happy New Year\

blade
 
when you say disparate Forest; what are you meaning? Is it physically located somewhere else (ISP Hosting?) or what? Is it remote, but accessible through a VPN?
 
Techy,

I just mean that it is a physical site and carries a different parent dns namespace, in the Windows text books they call this a separate or "disparate" forest. So I would need to make a one way trust from this trusting forest to the trusted forest which is my corporate forest.

Thanks for all the info you've provided.

blade
 
Well, in order to establish the trust, the two forests need to be able to get name resolution for the other. You can create lookup zones for the other forest in each forest, which generally works fine. Then, you can create your trust.

Pat Richard MVP
Plan for performance, and capacity takes care of itself. Plan for capacity, and suffer poor performance.
 
All-

Thanks again, so I set up DNS lookup zones on both trusting and trusted and created the trust..

I will not be incorporating SID filtering via netdom at this moment but that could change..

any comments on this please feel free.

thanks

blade
 
All-

Another brief one for those that know better, should I be creating secondary zones ? or primary ones? based on the one way trust I'm creating, I'm not sure...

thanks for any info

blade
 
Have Primaries in your root domains for those domains only. Secondaries are not needed if you set up DNS forwarders to the other domain to resolve that domain name.
 
techy,

let me ask you this...

my manager didn't like the name convention I used for this domain root DC.. I know it's not good practice to just rename it but there isn't anything replicating to this DC (forest root) server at this point.. how can I make sure that once I just change the name that it won't hold any old information on the box from the previous name i.e- right now I see the workstation domain name is the older name yet the computer name is reflecting the new name that I just changed it to.. is there a quick and dirty clean up tool I could use so I don't have to go thru a demotion process and start over?

thanks for any info

blade
 
Hi techy

I ended up demoting the server and starting over.. clean metadata etc..

thank you though, I appreciate your support

blade
 
Star for Techy for providing yet another outstanding solution.

I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top