gallery.technet.microsoft.com · web viewits time configure the cross forest mail-flow. when it...

25
Cross forest Mail-flow under Two way AD trust Now as we successfully configured the cross forest AD two way trust in my previous post which you can find over here https://gallery.technet.microsoft.com/Lab-for-cross-forest-AD-e40c001f . Its time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in trusts with each other. I could have thought about sending an email to internet and made the DNS MX records for the target forest exchange server and shot email expecting it to reach over there. But in actual scenario this does not work as there is a strong reason behind it. So when an AD trust is established, the point till you get in order to establish an AD trust you have to be able to ping the DC in the forest on the FQDN and vice-versa. Now the important thing to keep in mind is the two DCs are able to Ping each other only because there are we used conditional forwarders in the first place to be able to route the ping query to destination forest. And that is the main reason why DNS MX record query will not be used for mail delivery in this case. As when an email is shot according to AD topology configuration DNS will recognize that the domain for which the email is intended to is already in trust with it. So because of that reason it will look for a connector instead of going to the internet and look for a Public DNS MX record. So if connectors with the destination server IP address are not configured mail delivery will not be possible. Check the steps on how to create cross forest connectors.

Upload: others

Post on 10-Feb-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in

Cross forest Mail-flow under Two way AD trust

Now as we successfully configured the cross forest AD two way trust in my previous post which you can find over here https://gallery.technet.microsoft.com/Lab-for-cross-forest-AD-e40c001f . Its time configure the cross forest Mail-flow.

When it comes to the question about how the email flow will work when two AD forests are in trusts with each other. I could have thought about sending an email to internet and made the DNS MX records for the target forest exchange server and shot email expecting it to reach over there. But in actual scenario this does not work as there is a strong reason behind it. So when an AD trust is established, the point till you get in order to establish an AD trust you have to be able to ping the DC in the forest on the FQDN and vice-versa. Now the important thing to keep in mind is the two DCs are able to Ping each other only because there are we used conditional forwarders in the first place to be able to route the ping query to destination forest. And that is the main reason why DNS MX record query will not be used for mail delivery in this case. As when an email is shot according to AD topology configuration DNS will recognize that the domain for which the email is intended to is already in trust with it. So because of that reason it will look for a connector instead of going to the internet and look for a Public DNS MX record. So if connectors with the destination server IP address are not configured mail delivery will not be possible. Check the steps on how to create cross forest connectors.

Page 2: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 3: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 4: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 5: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 6: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 7: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 8: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 9: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 10: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 11: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 12: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 13: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in

Now we need to do the same in the exchange server of the other forest

Page 14: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 15: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 16: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 17: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 18: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 19: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 20: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 21: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 22: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in
Page 23: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in

Time to test Sending email from user [email protected] to [email protected]

Page 24: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in

And the email arrives

Page 25: gallery.technet.microsoft.com · Web viewIts time configure the cross forest Mail-flow. When it comes to the question about how the email flow will work when two AD forests are in