Trust relationships between Windows Server 2003 forests

Source: Internet
Author: User
Tags dns forwarder

As you should know, the trust relationship between the domains in the ad (forest) that you create using WIN2003 defaults to a two-way trust that is transitive. So what should we do if there are two or more forests in the enterprise's application, and when there is a mutual resource access? Because the default is only in one forest in which two-way trust can be passed, two forests (AD) does not have this relationship, then we need to manually configure the trust relationship between the forest, so as to ensure the exchange of resources in different forests. For example, mergers between enterprises, two companies are using Ms AD to manage, So you can imagine that these two enterprises must be two before the forest, then now after the merger, how to let these two forest to establish a trust relationship? So what's the way to do that? So today we're going to learn how to create a trust relationship between forests!

Trust between forests in a forest is divided into external trusts and forest trusts

A The external trust is a non-transitive trust created between domains in different forests

B Forest trust is a trust established between Windows 2003 forest root domains, a trust established between Windows SERVER 2003 forest root domains, and provides a one-way or bidirectional transitive trust relationship between domains within any forest

1. Create an external trust

You need to set up a DNS forwarder before you create an external trust: Configure forwarders for each DNS server between a two-forest DC:

Can parse benet.com.cn in the Project field

Can parse project.lcom in Benet domain

A first we configure the DNS server settings forwarder on the DC of the aptech.com domain to forward the parsing work of all benet.net domains to the 192.168.6.6 machine:

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.