Monday, August 13, 2018

Build trust relationship between two forests

Creating trust relationship between two different forests is required in numerous scenarios. There are few steps for this.

First it should be confirmed the connectivity between two domain controllers. Then name resolution must be inplace to resolve domain names. There are number of ways for this.

  1. Conditional Forwarder
  2. Secondary Zone
  3. Stub Zone
The best solution is Stub Zone which is more secure (For more info : https://social.technet.microsoft.com/Forums/windowsserver/en-US/bf6b6f2b-a2da-4e85-970f-778180393fc4/dns-stub-zone?forum=winserverNIS). Follow the steps to configure stub zones in adatum.com and milestone.com domains.

DC in adatum.com

Open DNS manager
Expand the server and Forward Lookup Zones folder
Right click on Forward Lookup Zones folder
Click New Zone and click Next
Click on Stub Zone radio button and click Next
Select To all DNS servers running on domain controllers in this forest: domain.com
And click Next.