Hello, everyone! Today we are going to learn how to achieve trust between forests. Through the Activity Directory Series VII: Trust (ON) learning, we know the meaning of trust, but also know that there are two kinds of trust in the forest can not be deleted: Father and son trust, Root trust. This is why we can access resources and use resources in a forest-wide way without hindrance. But how can this be achieved in two different forests? That's what we're talking about today.
Scene: Two forests, one is a net.com domain, there are child domains sub.net.com is a parent-child domain, one is the blogcn.com domain. We want to implement the Blogcn.com domain trust net.com domain, so that users in the net.com domain can access the blogcn.com domain resources without losing the password, or they can log on to their domain on the client computer in the blogcn.com domain. This often happens when the two companies are working together. The above can be divided into two situations:
1. There is a trust relationship between the blogcn.com domain and the subdomain sub.net.com domain. --> External Trust
2. There is a relationship of trust between blogcn.com forests and net.com forests. -----> Forest Trust
A trust relationship exists between the blogcn.com domain and the subdomain sub.net.com domain. --> External Trust
This trust relationship only exists between the specified two domains and is not passed to the other domain. We can do the "external trust" directly between the two.
Suppose blogcn.com----->sub.net.com (that is, the former trusts the latter)
After this trust is complete: users in the sub.net.com domain can log on to their domain on the blogcn.com domain, while users in the sub.net.com domain can access the blogcn.com domain's resources without losing the password.
Operation:
We do one-way blogcn.com (arrows outward), or we can do one-way incoming on sub.net.com (arrows inward).
1. DNS forwarding on two domain DNS, pointing to the corresponding dnsip. There's no need to repeat it here. You can do it yourself.
2. Open the ad Domain and trust relationship for the blogcn.com domain, right-click the attribute on the blogcn.com domain, click Trust--New trust--fill out the "sub.net.com" at the trust name, and click Next, as shown in the figure:
Select "One-way: Outbound", in the next diagram, select "This domain and specified domain", continue, enter the sub.net.com domain Administrator and password, click again, as shown in the summary information: