Trusting two forests/domains with the same FQDN or Netbios name


hi,

i'm trying put design satisfy requirements of customer of mine.  scenario this...

they have root domain in forest has resources need accessed multiple subdomains , / or external forest trusts.  of external forests have same fqdn , /or netbios name root forest domain, or same name forest / domain has trust relationship established root domain.

i know not possible create trust relationship domain name same root domain / subdomain or other domain has trust relationship root domain.

what wondering if following scenarios possible or if else knows of way round this:

scenario 1

external domain 1 = abc.local

external domain 2 = abc.local

internal forest root domain = xyz.local

internal subdomain = 123.xyz.local

internal subdomain = 456.xyz.local

trust relationship can established between external domain 1 , 123.xyz.local.  external domain 1 accesses resources in subdomain 123.xyz.local, , xyz.local

trust relationship can established between external domain 2 , 456.xyz.local.  external domain 2 accesses resources in subdomain 456.xyz.local, , xyz.local

scenario 2

external domain 1 = abc.local

external domain 2 = abc.local

internal forest root domain 1 = xyz.local

internal forest root domain 2 = 123.local

two way trust relationship exists between forest root domain 1 , forest root domain 2.

external domain 1 trusts xyz.local. external domain 1 access resources in xyz.local.

external domain 2 trusts 123.local.  external domain 2 access resources in 123.local

internal forest root domain 1 access resources in forest root domain 2 , vice/versa.

hello,

trust between domain suing same names not work. please understand name resolution must clear  2 times same name not possible.

a way around rename 1 domain or migrate name admt or other tools not free, quest ad migration example.


best regards

meinolf weber
mvp, mcp, mcts
microsoft mvp - directory services
my blog: http://msmvps.com/blogs/mweber/

disclaimer: posting provided no warranties or guarantees , confers no rights.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group