Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Active Directory > Re: DMZ authentication issues with trust relationships issues

Reply
Thread Tools Display Modes

Re: DMZ authentication issues with trust relationships issues

 
 
im07
Guest
Posts: n/a

 
      01-26-2006
Why have you placed the server in the DMZ? If you have read the
installation guides provided by Microsoft, you would know that you would
have to open up just about every port just to get the services to
communicate properly. This is why Microsoft changed their thoughts on how
to properly implement Exchange 2003 and that is to keep all servers within
the LAN and if desired, place the SMTP Gateway in the DMZ. Then open only
the ports to the Frontend only within the firewall to that single IP. If you
do not do this, then there are a TON of ports you must open between them...
(DMZ to LAN and back)

Between the two domains, you must open certain ports are well. Goto
Microsoft.com/exchange and read up on proper installation and migration and
search for ports used by Exchange 2003 and ports for trust relationships for
Windows 2003 native-mode.

This will give you a start.

<> wrote in message
news: oups.com...
> First, here is my environment:
> ===============================
> - I have a single forest with two separate 2003 native mode domains;
> A.COM and B.COM. Domain A.COM is the forest root domain. There is a
> two-way trust relationship between the two domains.
>
> - I have a single server in a DMZ that is a member of A.COM
> (DMZserver.A.COM). This is a front-end server for Exchange OWA and my
> back-end server is also a member of A.COM and resides on my internal
> network.
>
> - The appropriate ports are opened for this DMZ server to authenticate
> and talk to the domain controllers in A.COM. No ports are opened for
> this server to talk to DCs in B.COM.
> ===============================
>
> OK, up until last week I could login to DMZserver.A.COM as
> . Last week I did an in place upgrade of Exchange 2000
> to 2003, and Windows Server 2000 to 2003. After the upgrade, logging
> into the server with worked just fine of course.
> However, now trying to log into DMZserver.A.COM as
> yields "The specified domain either does not exist or could not be
> contacted." So my question is what changed and why. The firewall
> was not touched and it worked just fine before the upgrade. There were
> no ports open for DMZserver.A.COM to directly talk to domain
> controllers in B.COM, so the DCs in A.COM were taking care "pass
> through" authentication to B.COM. Did something change in the
> Windows Server 2003 upgrade? Any thoughts are appreciated.
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
trust relationships ... E-Double Active Directory 5 09-20-2005 03:17 PM
Re: DNS & Other Requirements for Interforest Trust Relationships? Ace Fekay [MVP] Active Directory 0 08-20-2005 04:51 PM
Trust relationships betweem forests Henry Active Directory 2 02-04-2005 03:07 AM
Trust Relationships Nextcert Active Directory 1 01-13-2005 03:28 PM
Error - SID inconsistent with trust relationships Bruce Active Directory 0 12-09-2004 06:21 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59