A
Alex
Guest
Unable to create basic domain trust between two Windows 2003 domains - logon servers not available ?
Hi. I am currently trying to create a basic one way non-transitive trust
between two Windows 2003 domains. We will be merging the domains of two
companies in the future but for the time being need to give one domain
access to resources in another. Both domains are standalone within their
own forest i.e. domain1.net is the only domain in the domain1.net forest and
domain2.net is the same. Both domain1 and domain2 have Windows Server 2003
domain and forest functional levels.
So far I have created Stub zones on the DNS servers in each domain i.e.
domain1.net has a stub zone for domain2.net and domain2.net has a stub zone
for domain1.net. Both domains have a single domain controller called DC1 on
each domain i.e. dc1.domain1.net and dc1.domain2.net. I can ping from one
DC to the other and resolve names of workstations and servers in the remote
domain. If I run a nslookup from each DC the output seems normal
(DC1.domain1.net nslookup result below).
When I try to create the one way non-transitive trust I get to the end of
the wizard and select to 'Validate' the trust, I get the error :
The secure channel (SC) reset on domain controller \\DC1.comain2.net of
domain2.net to domain domain1.net failed with error: There are currently no
logon servers available to service the logon request.
The accounts I have used in both domains are Domain and Enterprise Admins.
Only dc1.domain2.net has an error in the System Log with ID 5719 and the
same error as above i.e. logon servers not available to service the logon
request.
Can anyone suggest where I am going wrong ?
Thanks,
Alex.
DC1.domain1.net nslookup result:
C:\>nslookup
Default Server: localhost
Address: 127.0.0.1
> set type=srv
> dc1.domain2.net
Server: localhost
Address: 127.0.0.1
domain2.net
primary name server = dc1.domain2.net
responsible mail addr = hostmaster
serial = 21
refresh = 900 (15 mins)
retry = 600 (10 mins)
expire = 86400 (1 day)
default TTL = 3600 (1 hour)
Hi. I am currently trying to create a basic one way non-transitive trust
between two Windows 2003 domains. We will be merging the domains of two
companies in the future but for the time being need to give one domain
access to resources in another. Both domains are standalone within their
own forest i.e. domain1.net is the only domain in the domain1.net forest and
domain2.net is the same. Both domain1 and domain2 have Windows Server 2003
domain and forest functional levels.
So far I have created Stub zones on the DNS servers in each domain i.e.
domain1.net has a stub zone for domain2.net and domain2.net has a stub zone
for domain1.net. Both domains have a single domain controller called DC1 on
each domain i.e. dc1.domain1.net and dc1.domain2.net. I can ping from one
DC to the other and resolve names of workstations and servers in the remote
domain. If I run a nslookup from each DC the output seems normal
(DC1.domain1.net nslookup result below).
When I try to create the one way non-transitive trust I get to the end of
the wizard and select to 'Validate' the trust, I get the error :
The secure channel (SC) reset on domain controller \\DC1.comain2.net of
domain2.net to domain domain1.net failed with error: There are currently no
logon servers available to service the logon request.
The accounts I have used in both domains are Domain and Enterprise Admins.
Only dc1.domain2.net has an error in the System Log with ID 5719 and the
same error as above i.e. logon servers not available to service the logon
request.
Can anyone suggest where I am going wrong ?
Thanks,
Alex.
DC1.domain1.net nslookup result:
C:\>nslookup
Default Server: localhost
Address: 127.0.0.1
> set type=srv
> dc1.domain2.net
Server: localhost
Address: 127.0.0.1
domain2.net
primary name server = dc1.domain2.net
responsible mail addr = hostmaster
serial = 21
refresh = 900 (15 mins)
retry = 600 (10 mins)
expire = 86400 (1 day)
default TTL = 3600 (1 hour)