Login to Domain Controller which is not in network

Scenario
I've taken an online clone of one of my Virtual Window 2003 Enterprise Domain Contoller which doesn't hold any roles. Removed the Clone Domain Controller from Network & powered it on.
Now I want to log into that Domain Controller using my Domain Admin credentials but it's not working.
Is there a way to log in to that Domain Controller which is taken out of network USING DOMAIN ADMIN ID ?
I can log in to Restore Mode but that's not what I'm looking for, I need to log in to that DC using my Domain Admin credentials while It's not in network.
This is for lab purpose.

Hi Yankee,
Have you cached credentials on the Domain Controller before you cloned one?
I just tested that if I cache credentials, users are able to log on when domain controllers are offline.
If not, you can try to clone another after cached credentials then test again, please note that do not take the cloned DC online, which will lead USN rollback.
More information for you:
Cached domain logon information
http://support.microsoft.com/kb/172931/en-us
Running Domain Controllers in Hyper-V
http://technet.microsoft.com/en-us/library/virtual_active_directory_domain_controller_virtualization_hyperv(v=WS.10).aspx
Best Regards,
Amy

Similar Messages

  • Can i install 9ias and infrastructure on a dektop which is not in network

    hi
    my question is can i install both oracle 9ias and 9i database on a single desktop machine which is not in network, if YES , Please let me know how to do it?
    thankx

    William,
    It is not possible to install BusinessObjects Enterprise XI Release 2 alongside of Crystal Enterprise 10.  You will have to upgrade the servers in place.  Although speaking through my experience this process is fairly seemless and hardly ever has issue.  If you are looking to do side by side installs and saving costs for your customer base I would recommend looking at using a virtualization product like VMware Server or Workstation as a temporary bridge to get both products installed side by side.  Also one other thing you mentioned you are a progress shop, but you should know that the CMS repository database that runs the application can not be hosted on progress.  MySQL, SQL Server, Oracle, UDB DB2 and Sybase your only options for the CMS.  For reporting you can use a wider range of products.

  • Only contact Domain Controller when on a particular network

    As per subject, I have a laptop joined to a domain and logging on is slow when outside the network. Obviously it is trying to contact the domain contoller but fails. Can we set it to immediately use the last saved password when not within the network?

    That might be the reason.
    but as you could logon it, the cached info is worked here. the logon is slow might caused by the mapped drives. and disable the always wait ..policy should fit this, which is not recommended when mapped drive is in use.
    Run Xperf to take a check with the slow logon process.
    http://blogs.technet.com/b/yongrhee/archive/2013/10/15/tool-windows-performance-toolkit-xperf-wprui-and-wpr-updated-version-as-of-aug-2013.aspx
    Rgds

  • 2nd domain controller added does not process logins

    This probably a very simple answer, but have search wide/far and still can't fix my issue; I'm hoping someone here can point me in the correct direction. I'm just not a wiz with DNS/AD as I used to.
    I am building a test domain in my VM environment and when I take down the #1 DC, (the one I built first), my test Win7 machine can NOT connect to the domain.  I'm more than certain this is a DNS issue, but do not know how to fix it.  This is an
    AD integrated DNS, both DC's are GC's, both are running DNS and each point to themselves.  I'm using a Win7 machine that has static IP address - machine is a member of the test domain.
    In order to "simulate" DC1 going down, I simply disable the NIC.
    DC1: IP = 10.10.1.5
    DC2: IP = 10.10.1.10
    win7 Host: IP =10.10.2.10 (static assigned, so not AD integrated DHCP)
    From the host, here is the IPCONFIG/all
    C:\>ipconfig /all
    Windows IP Configuration
       Host Name . . . . . . . . . . . . : WIN7-ESX-PC
       Primary Dns Suffix  . . . . . . . : doghouse.local
       Node Type . . . . . . . . . . . . : Hybrid
       IP Routing Enabled. . . . . . . . : No
       WINS Proxy Enabled. . . . . . . . : No
       DNS Suffix Search List. . . . . . : doghouse.local
    Ethernet adapter Local Area Connection:
       Connection-specific DNS Suffix  . :
       Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network Connection
       Physical Address. . . . . . . . . : 00-0C-29-19-16-C4
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
       IPv4 Address. . . . . . . . . . . : 10.10.2.10(Preferred)
       Subnet Mask . . . . . . . . . . . : 255.255.0.0
       Default Gateway . . . . . . . . . :
       DNS Servers . . . . . . . . . . . : 10.10.1.5
                                           10.10.1.10
       NetBIOS over Tcpip. . . . . . . . : Enabled
    Also, when the NIC is UP on DC1, I see the following output on NSLOOKUP
    C:\>nslookup
    DNS request timed out.
        timeout was 2 seconds.
    Default Server:  UnKnown
    Address:  10.10.1.5
    > set type=all
    > _ldap._tcp.dc._msdcs.doghouse.local
    Server:  UnKnown
    Address:  10.10.1.5
    _ldap._tcp.dc._msdcs.doghouse.local     SRV service location:
              priority       = 0
              weight         = 100
              port           = 389
              svr hostname   = doghouse-dc2-srv.doghouse.local
    _ldap._tcp.dc._msdcs.doghouse.local     SRV service location:
              priority       = 0
              weight         = 100
              port           = 389
              svr hostname   = doghouse-dc1-srv.doghouse.local
    doghouse-dc2-srv.doghouse.local internet address = 10.10.1.10
    doghouse-dc1-srv.doghouse.local internet address = 10.10.1.5
    when the NIC is down I get this, as well as if I reboot the machine and try to login, it says "no domain services available
    > _ldap._tcp.dc._msdcs.doghouse.local
    Server:  UnKnown
    Address:  10.10.1.5
    DNS request timed out.
        timeout was 2 seconds.
    DNS request timed out.
        timeout was 2 seconds.
    *** Request to UnKnown timed-out
    Any help would be appreciated!

    Hi all - sorry for the delay in responding (work happens).
    So yes, the SVR records were properly listed in both DNS servers and I did multiple reboots; rebuilt the SVR records from scratch - just about everything under the sun -- I think added 2 more DC's to the mix, and moved FSMO roles over to one of them, then
    began to demote the other 2 DCs to see if it was something in their build--in the end though I was never able to remove the original DC1 out of the domain - gave me odd messages about not being able to contact the domain to have it remove.  (this is after
    FSMO roles were moved off) -
    Long story short, I blew the configuration away and yet again started from scratch and it is working now as I'd expect.  Although when I do disabled the NIC from DC1 to simulate failure, it still takes about 10-15 sec for the machines to login to the
    domain - when I type: echo %logonserver% it does confirm it hits DC2 when DC1 is down, but still a little delay.  I think the difference in the new configuration is that I set DC2's primary dns server to DC1.  I also installed DFS and the NETLOGON
    shares are replicating, (not sure if that made a difference)
    I guess for now we can consider this answered although I'm not sure who to give points to...I do appreciate everyone's time in reading and trying to help -- I bet this wont' be the last time I post here.

  • If i open same url in same browser without making signout in SharePoint FBA site, it login user again automatically which should not happened

    Hi All.
    I have SharePoint 2010 FBA site, and when user close there browser without logout button and if they enter same url in browser then it allow user to login on application which is security risk.
    So can you please help me to solve this problem.
    Thanks
    Ajit Shinde

    Hi Ajit,
    See this similar thread (with answers):
    https://social.technet.microsoft.com/Forums/en-US/5bf1dfdf-cc1c-422c-9c25-094fc7aaad61/user-details-retained-if-user-does-not-signout-and-closes-the-browser-and-opens-page-again?forum=sharepointgeneralprevious
    Nico Martens
    SharePoint/Office365/Azure Consultant

  • HT4102 Login screen uses language which is not the system's default (English)

    My login screen seems to use the last chosen language on the system, not the default language (English), what makes my password be written in a different language.
    In my case it's enough if I hit caps-lock (when it's hit in the other language, it changes to lowercase english), so I'm good.
    But it's really annoying.
    How can I just have the langage selector in the login screen?

    System prefs> users & groups> login options> show input menu in login window

  • What is the effect of stopping the EFS service on a 2012 Domain Controller?

    Hello,
    The Encrypting File System service was started and is running on a production 2012 Domain Controller, which is not a standard in our shop.  What is the potential impact if I stop the service? 
    Thanks for your help! SdeDot

    Hi,
    Have you already encrypted files or folders using EFS service in your domain?
    If not, and you are not planning to use it to encrypt files or folders in the future, then it is OK to disable it.
    If you have encrypted files with EFS service, make sure that they are all decrypted before disabling the service, otherwise no users will be able to access them.
    More information for you:
    How to Disable or Enabled EFS Encryption in Vista, Windows 7, and Windows 8
    http://www.vistax64.com/tutorials/102501-encryption-disable-enable.html
    How to: Disable Encrypted File System (EFS) on Windows 2008 R2
    http://markswinkels.nl/2012/06/how-to-disable-encrypted-file-system-efs-on-windows-2008-r2/
    Please Note: Since these web sites are not hosted by Microsoft, these links may change without notice. Microsoft does not guarantee the accuracy of this information.
    Best Regards,
    Amy Wang

  • Need to delete Transport system , which is not domain controller

    I need to delete transport system on machine which is not domain controller .
    our domain controller system is not avalible now .
    how can i delete the transport system on my machine as domain controller system is not avaliable .
    Please let me know what can i do ??
    Thanks,
    Asc

    Hi,
    Logon to any system which is in your transport path in client 000. Then in stms, go to Overview ---> Systems. Here you can find all the systems in your transport path. You can also find the domain controller which you have configured as before.
    Now, goto Extras----> Delete TMS Configuration.
    After deleting, logon to system which you want to make as domain controller in client 000. when you execute stms, now it will ask for new stms setup, which you might be aware of.
    If you need more guidance, let me know.
    Thanks,
    Sailesh K

  • Version number for GPO's not in sync with the version number for GPO's on the Baseline domain controller

    Hi
    I accidentally removed one of our domain controller's hyper-v image (DC-02) from the hyper-v manager and to bring it back online launched a new virtual machine using the same virtual hard drive. This brought back the domain controller machine and I set the
    original IP address to the same assuming that everything would just working fine.
    Sadly, that wasn't the case as when I tried to open the group policy manager on that machine I started getting "Access is denied" error. I was then presented with an option to open the group policy manager with the first available DC which I did
    and was able to open it with showing the same machine as the baseline domain controller under the status tab (DC-01 is actually the baseline DC). I then clicked Detect now and noticed it was showing 1 DC under replication in progress with problems in GPO version.
    I then did the same thing on the primary DC (DC-01) and even there it was showing this only (images attached).
    So I started exploring over the internet going through various articles but couldn't find a solution which I could apply without worrying about corrupting something somewhere. I also went to the SYSVOL folder on both the DC's to check the version number
    in GPT.ini files which are mentioned below:
    \\CC-DC01\sysvol\cloudchowk.lab\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}
    [General]
    Version=3
    \\CC-DC01\sysvol\cloudchowk.lab\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}
    [General]
    Version=5439513
    \\cc-dc02\SYSVOL\cloudchowk.lab\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}
    [General]
    Version=3
    \\cc-dc02\SYSVOL\cloudchowk.lab\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}
    [General]
    Version=5308439
    Could anyone please help me sort this out? I am no system admin and whatever knowledge I have of setting up DC, AD etc is from following one article or the other over the internet.
    Regards
    Sajat Jain

    Hi
    Apologies for responding late. I followed through all the points mentioned by Frank and even did a non-authoritative restore synchronization but still no luck.
    I am attaching the output from the dcdiag /q and the from the event viewer after doing to non-authoritative restore synchronization.
    DCDIAG /Q
    There are warning or error events within the last 24 hours after the
    SYSVOL has been shared. Failing SYSVOL replication problems may cause
    Group Policy problems.
    ......................... CC-DC03 failed test DFSREvent
    Unable to connect to the NETLOGON share! (\\CC-DC03\netlogon)
    [CC-DC03] An net use or LsaPolicy operation failed with error 67,
    The network name cannot be found..
    ......................... CC-DC03 failed test NetLogons
    An error event occurred. EventID: 0x0000164A
    Time Generated: 01/18/2015 17:52:17
    Event String:
    The Netlogon service could not create server share C:\Windows\SYSVOL\sysvol\cloudchowk.lab\SCRIPTS. The following error occurred:
    An error event occurred. EventID: 0x0000164A
    Time Generated: 01/18/2015 17:54:12
    Event String:
    The Netlogon service could not create server share C:\Windows\SYSVOL\sysvol\cloudchowk.lab\SCRIPTS. The following error occurred:
    An error event occurred. EventID: 0x00000422
    Time Generated: 01/18/2015 17:54:41
    Event String:
    The processing of Group Policy failed. Windows attempted to read the file \\cloudchowk.lab\sysvol\cloudchowk.lab\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following:
    An error event occurred. EventID: 0x00000422
    Time Generated: 01/18/2015 17:55:42
    Event String:
    The processing of Group Policy failed. Windows attempted to read the file \\cloudchowk.lab\sysvol\cloudchowk.lab\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following:
    An error event occurred. EventID: 0x00000422
    Time Generated: 01/18/2015 17:59:41
    Event String:
    The processing of Group Policy failed. Windows attempted to read the file \\cloudchowk.lab\sysvol\cloudchowk.lab\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following:
    An error event occurred. EventID: 0x00000422
    Time Generated: 01/18/2015 18:04:42
    Event String:
    The processing of Group Policy failed. Windows attempted to read the file \\cloudchowk.lab\sysvol\cloudchowk.lab\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following:
    An error event occurred. EventID: 0x0000164A
    Time Generated: 01/18/2015 18:05:10
    Event String:
    The Netlogon service could not create server share C:\Windows\SYSVOL\sysvol\cloudchowk.lab\SCRIPTS. The following error occurred:
    An error event occurred. EventID: 0x00000422
    Time Generated: 01/18/2015 18:09:42
    Event String:
    The processing of Group Policy failed. Windows attempted to read the file \\cloudchowk.lab\sysvol\cloudchowk.lab\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following:
    An error event occurred. EventID: 0x00000422
    Time Generated: 01/18/2015 18:14:42
    Event String:
    The processing of Group Policy failed. Windows attempted to read the file \\cloudchowk.lab\sysvol\cloudchowk.lab\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following:
    An error event occurred. EventID: 0x00000422
    Time Generated: 01/18/2015 18:19:43
    Event String:
    The processing of Group Policy failed. Windows attempted to read the file \\cloudchowk.lab\sysvol\cloudchowk.lab\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following:
    An error event occurred. EventID: 0x00000422
    Time Generated: 01/18/2015 18:24:43
    Event String:
    The processing of Group Policy failed. Windows attempted to read the file \\cloudchowk.lab\sysvol\cloudchowk.lab\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following:
    ......................... CC-DC03 failed test SystemLog
    EVENT VIEWER LOGS
    The DFS Replication service initialized SYSVOL at local path C:\Windows\SYSVOL\domain and is waiting to perform initial replication. The replicated folder will remain in the initial synchronization state until it has replicated with its partner CC-DC01.cloudchowk.lab. If the server was in the process of being promoted to a domain controller, the domain controller will not advertize and function as a domain controller until this issue is resolved. This can occur if the specified partner is also in the initial synchronization state, or if sharing violations are encountered on this server or the synchronization partner. If this event occurred during the migration of SYSVOL from File Replication service (FRS) to DFS Replication, changes will not replicate out until this issue is resolved. This can cause the SYSVOL folder on this server to become out of sync with other domain controllers.
    Additional Information:
    Replicated Folder Name: SYSVOL Share
    Replicated Folder ID: 4689406D-D6D8-49E0-8079-2B1D4AE61BC6
    Replication Group Name: Domain System Volume
    Replication Group ID: 6B162096-2EFA-4D4C-BF13-62CC5B112B97
    Member ID: 566943F9-D2FB-4304-823D-10DC972F831A
    Read-Only: 0
    Should I just start over again by removing DC03 and setting up another DC?
    Regards
    Sajat Jain

  • How to reset Windows 2008 R2 Domain Controller "Administrator" password?

    Hello Everyone,
    I have lost Administrator password for the following system:
    Windows 2008 R2
    Domain Controller setup on same machine
    Stand alone server - no workstations or other servers invovled
    I still have the "Directory Service Restore Password" but I don't think that helps me for lost Administrator password. I beleive I need to boot from an .iso file to gain access. I already tried "Offline NT Password & Registery Editor" and it has set
    Administrator password to (blank) but that is not allowing me access as it seems that I have to login to domain controller Administrator. So, how can I reset that password?
    Thanks

    It wasn't difficult to reset the domain password and I think Microsoft's policy of not providing an easy forward way is to create an
    illusion of security which is not there. Linux systems that are much more secure that MSFT software allow easy password reset when physical access is there so why not include the same tools in System Repair tools or using F8?
    Anyhow, this guide helped me reset the password in 5 minutes. Read the bottom of it to find the scripted / automatic version of the process:
    http://www.petri.co.il/reset_domain_admin_password_in_windows_server_2003_ad.htm
    Thanks,

  • Create a VMware snapshot before promoting domain controller

    Dear expert,
    I have created a new guest OS in VMware ESXi 4.1 according to the following procedures:-
    1. Install windows 2008 R2 standard
    2. Configure network information
    3. Join the server to the domain
    4. Run windows update
    As I will promote the member server to domain controller.  Therefore, I have taken the snapshot for the member server before running dcpromo.  The aim of the snapshot is to make it easier to fall back if the promotion screws up.
    When the promotion screws up, I will perform the following steps to re-promote the member server to domain controller.
    1. Restore snapshot for the member server
    2. May need to execute metadata clean up for the member server on existing domain controllers
    3. Re-run dcpromo to re-promote the member server to domain controller.
    I would like to know if the above procedures are correct when the promotion screws up.
    Thank you for your kind assistance.

    Dear expert,
    I would like to know if the above procedures are correct when the promotion screws up.
    Thank you for your kind assistance.
    I can not represent a positive response to this procedure. When you join a computer to the domain, the computer establish a live connection with the domain controller which is called Secure Channel. Imaging and cloning is one of the things which break the
    secure channel. Since you are using 2008 R2, the imaging/cloning procedure will be problematic for you now or near future. So I do not recommend it.
    If you have 10 computers or so in your whole domain it may be possible to do so because troubleshooting 10 computers in a domain is not a difficult task.
    One thing to keep in mind is that promoting a domain controller is enough important which you should not do things like that about it. If everything goes bad during the promotion you may just need a metadata cleanup (rarely), so what is the point of cloning?
    At worst you do a re-install of Windows. I prefer it this way.
    Mahdi Tehrani   |  
      |  
    www.mahditehrani.ir
    Please click on Propose As Answer or to mark this post as
    and helpful for other people.
    This posting is provided AS-IS with no warranties, and confers no rights.
    How to query members of 'Local Administrators' group in all computers?

  • Replace WS2003 domain controller for WS2012 domain controller

    Hi, I think that is a common problem but I haven't found anythink exactly like this, only something similar, but I have a lot of doubts yet.
    The thing is that I have a network with two domain controllers:
    WS2003     - 192.168.0.1, who is the first domain controller I created and is also a file sharing server
    WS2008R2 - 192.168.0.8, who is a  new domain controller I added one year ago.
    Now, I want to replace the first one, keeping the second. One.
    I thinking of removing the first one and replace it with a new machine (WS2012) with the same IP and name host. I need the same host because clients are pointing to it to get the shared files.
    My main fear is that clients get some error related with trust relationship and I will have to rejoin them one by one to the domain.
    As I have another domain controller, Will the global catalog of the new machine be synchronized automaticly with the WS2008R2 domain controller?
    Do I need to demote the old domain controller before add the new one?
    Thanks a lot

    Hi Tomas,
    As pointed by Burakm you should have an additional file server and should avoid using a Domain controller which has priviledged access, to share files. This puts you at a security risk.
    Regarding the requirement of old host name:
    Here is something that would let you keep a different servername and IP, yet allow your users to connect to the old hostname and access the share. Use CNAME records of old server to point it to the new hostname.
    How to Configure Windows Machine to Allow File Sharing with DNS Alias
    You might also look for Distributed File System Shares.
    http://blogs.technet.com/b/josebda/archive/2009/06/26/how-many-dfs-n-namespaces-servers-do-you-need.aspx
    NOTE- You can't run in-place upgrade of a 2003 to 2012 DC.
    Regards,
    Satyajit
    Please “Vote As Helpful”
    if you find my contribution useful or “Mark As Answer” if it does answer your question. That will encourage me - and others - to take time out to help you.

  • DPM 2010 agent installation on Domain Controller

    Hello all, recently I tried to install the agent from my DPM 2010 server onto a Win2K8 Domain controller which failed (used a Domain Admin's credientials for the install, and on trusted domain). I remember in DPM 2007 you needed to install the agent through
    command line. Can someone post up the correct steps to get a DPM 2010 agent installed to a DC?

    Same issue here.
    Pushing a DPM 2010 agent to a Windows 2008 DC fails with the error:
    ============
    You cannot install the protection agent on SV-MGMT-03.xxxxxx.nl because access to the computer has been denied.
    ============
    The DPM 2010 agent software is installed but DPM doesn't add the server. With an attach i can add the server but DPM 2010 cannot communicate with it.
    ===============
    Protection agent version: 3.0.7696.0
    Error: Data Protection Manager Error ID: 270
     The agent operation failed on sv-mgmt-03.xxxxx.nl because DPM could not communicate with the DPM protection agent. The computer may be protected by another DPM server, or the protection agent may have been uninstalled on the protected computer.
    If sv-mgmt-03.xxxxxxx.nl is a workgroup server, the password for the DPM user account could have been changed or may have expired.
    Recommended action: Check the following to troubleshoot this issue:
    1) If the agent is not installed on sv-mgmt-03.xxxxxxxxx.nl, run DpmAgentInstaller.exe with this DPM computer as a parameter. For details, see the DPM Deployment Guide.
    2) To attach the computer correctly to this DPM server, run the SetDpmServer tool on the protected computer.
    3) If the computer is protected by another DPM server, or if the protection agent has been uninstalled, remove the protected data sources on this computer from active protection. Then, remove the entry of this computer from the Agents tab in the Management
    task area.
    4) If sv-mgmt-03.xxxxxxxxx.nl is a workgroup server, run SetDpmServer with the -UpdatePassword flag on the protected computer and Update-NonDomainServerInfo.ps1 on the DPM server to update the password.
    5) If the DPM server and the protected computer are not in the same domain, ensure that there is a two-way trust setup between the two domains.
     If the computer is protected by another DPM server, or if the protection agent has been uninstalled, you can remove the record of the computer from this DPM server.
    ==============
    Anyone a solution for this?

  • Forest trust unable to find Active Directory Domain Controller

    I have two domains with a two-way forest trust. We'll call them ForestA and ForestB. They're on seperate subnets. ForestA's DCs are in one physical location. ForestB's DCs are in two locations, one of which is shared with A.
    I'm unable to route traffic directly from the remote DC in ForestB to the subnet ForestA is on, so I created a new DC in ForestA that sits on the subnet ForestB uses (basically, I can't route between subnets via the wireless bridge between locations, but
    can within the same location).
    I found this: http://www.neomagick.net/zen/2008/11/30/using-dns-to-force-a-domain-trust-through-a-specific-domain-controller-dc/
    I followed the instructions to set the new DC in forest A to be the only one the remote DC in forest B was aware of.
    Nslookup ForestA.com resolves correctly to this DC, but I'm unable to validate the trust relationship, getting the error:
    "Windows cannot find an Active Directory Domain Controller for the ForestA.com domain. Verify that an AD DC is available and then try again."
    I'd appreciate any help.

    In the event viewer, have you found any event id's that corrospond with this error? Have you ensured all ports required are open? Windows firewall is correctly setup? NIC is properly configured?
    Statement below taken from: http://technet.microsoft.com/en-us/library/cc961803.aspx
    If you receive the following error, ERROR_NO_LOGON_SERVERS while using the Nltest tool to query the secure channel, this is usually indicative of the inability to find a domain controller for that domain. Run nltest /dsgetdc: < DomainName > : to verify
    whether you can locate a domain controller. If you are unable to find a domain controller examine DNS registrations and network connectivity.
    ADDS Ports:
    http://msdn.microsoft.com/en-us/library/dd772723(v=ws.10).aspx

  • Does Oracle 10G R2 support installation on Windows 2003 Domain Controller?

    Does Oracle 10g R2 support installation on Windows 2003 Domain Controller? I remember that 10g R1 had issues with the DC? Is it still the case. Does it work now?
    Any help is appreciated.
    Regards,
    Raghav

    We have Oracle 10g R2 running on a Windows 2003 domain controller. It was not a domain controller when Oracle was installed. The domain was created after installation. (I don't recommend that procedure. I spent a long day fixing the installation after they configured the domain.) If Oracle is unhappy with being on a domain controller, it has not shown it yet.

Maybe you are looking for

  • Sides of Keynote presentation cut off when exported to iDVD

    Hi, I have a keynote presentation with the slides set to 800X600 that I am trying to burn to a DVD. I am able to burn fine but when it plays on my DVD player and CRT Samsung TV, the sides of the slides are cut off so that the first and last letters o

  • HT2534 Why is the "None" option no longer available?

    Why can I no longer enter the iTunes store without a credit card?  My company has purchased 15 to 20 iPads and we were originally able to download free apps through our MDM without needing to enter a credit card on each device iTunes account.  Now al

  • Keeps crashing, it will nwelcome screen I ha

    I have the iPad app Ps touch and the app keeps crashing, it will not go past the welcome screen I have installed and uninstalled the app multiple times to no avail, please help!

  • Error in X11 (unable to start device PNG)

    Hello. I have a problem with running embedded R script. First script runs fine: begin sys.rqScriptCreate('Example1', 'function() { ID <- 1:10 res <- data.frame(ID = ID, RES = ID / 100) res}'); end; The second one is not so fine: select * from table(r

  • WLS 6.1 SP4 available ?

    I heard that there is now SP4 for WLS 6.1. Is this true and if so, when and where is it ?