microsoft · web viewtype in the ip address of the domain controller in xyz.com and press tab...

56
Lab done for cross forest AD two way trust Network Configuration for AD DC for domain abc.com

Upload: others

Post on 08-Jul-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

Lab done for cross forest AD two way trustNetwork Configuration for AD DC for domain abc.com

Page 2: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 3: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

================================================================================== Network Configuration for AD DC for domain xyz.com

Page 4: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 5: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

Network configuration for Router which will manage traffic between domain abc.com and xyz.com

You have to assign both the network cards to the router machine

Firewall is also off

Page 6: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 7: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 8: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

Ping from Router machine to AAD in xyz.com

Ping from DC in abc.com to router

Ping from DC in xyz.com to router

Page 9: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

Ping from DC in abc.com to DC in xyz.com

Ping from DC n xyz.com to DC in abc.com

Ping from Exchange server in abc.com to DC in abc.com Then ping to DC in xyz.com Then another exchange server in xyz.com

Page 10: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

Ping from Exchange server in xyz.com to DC in xyz.com Then ping to DC in abc.com Then another exchange server in abc.com

Page 11: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

One important thing though. When you ping FQDN from DC in abc.com to DC in xyz.com it doesn't work

And same is the case vice versa

Page 12: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

To over this create DNS forwarders

Page 13: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 14: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 15: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

Type In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer name

Page 16: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 17: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 18: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

After Some time you will see that it will have a Green check mark next to it as the IP resolves to the computer in other network then you press OK button

Page 19: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

When you will come back to the first page it will show you the computer name of the DC in other forest

Page 20: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

Now when you will Ping FQDN of domain controller from ABC.com to Domain controller in XYZ.com it will be successful

Page 21: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

Do the same on Other DC as well

Page 22: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 23: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 24: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 25: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 26: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 27: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 28: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

And here are the Ping statistics that shows positive results.

Page 29: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

Now we will Create Cross forest Two Way trust. We will start creating it in the first Domain controller in Forest ABC.com

Right click on the domain name and click on Properties from ‘Active Directory Domains and Trust snapin’

Page 30: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

In the Properties Dialog Box click on ‘Trusts’ tab and then click on New trust Button at the bottom.

Page 31: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 32: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

This is a very important step. You have to only mention the domain name of the other Forest in the field below like I Did as it’s a forest wide trust

Select the option Forest Trust below and click next

Page 33: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

Then select Two-way trust and then click Next

Then click on option ‘Both this domain and specified domain’

Page 34: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

Now you have to mention the password of system admin of the other forest as the query for authentication will reach the remote forest to create a two-Way trust.

Once done click on option ‘Selective authentication’

Page 35: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

Then select the option ‘Forest-wide authentication’

Once the trust wizard will be at its completion it will you will have the summary displayed

Page 36: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

Once you will click Next button you will have the result summary displayed confirming that the trust has been created successfully.

Select the Option yes to confirm outgoing Trust.

Page 37: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

Do the same for the Incoming trust as well.

End of the wizard. Click Finish Button

Page 38: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

When You will come back to the page you will have the domain name mentioned under trust section

Page 39: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

And when you go to the Domain Controller of the other forest you do not need to re-run the trust creation wizard as it will be already created as we selected the option ‘two-Way trust’ and mentioned the credentials for the remote forest’s administrator

Page 40: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

Now its time to validate the Trust

Page 41: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 42: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

When you click the validate Button mentioned the credentials of the remote forest’s administrator

Page 43: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

In the Next statement to enable name suffix routing for the trust click Yes

Page 44: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

Same has to be done in the XYZ.com forest as well.

Page 45: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 46: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 47: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 48: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

Now I'll Show you a user names User1 from domain ABC.com will log into a system which is domain joined in XYZ.com

Page 49: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 50: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 51: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 52: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest

And off course the other user names [email protected] can also log into same machine

Page 53: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 54: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest
Page 55: Microsoft · Web viewType In the IP address of the Domain controller in XYZ.com and press TAB button so as to let it Auto resolve the computer nameNow we will Create Cross forest