Click here to get back home

RPC Local Security Windows 2003 Trust Issue

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
RPC Local Security Windows 2003 Trust Issue Brinda 02-02-2006
Posted by Brinda on February 2, 2006, 9:02 am
Please log in for more thread options
We are receiving the following error while trusting a server in a different
forest and domain. The error is the Local Security Policy is unable to
obtain an RPC connection to the server. Both servers are Windows 2003 native
mode. We have 2 other locations that are trusted and working correctly. We
have checked ports 135, 139, and 389 which are open between the VPN sites.
The trust did create a one way trust. Their server is trusted to us. So
they can see us but we can't see them. We can ping the server by name. We
thought perhaps the RPC cannot use the higher ports. Has anyone else had
this issue?

B Whitaker



Posted by Steven L Umbach on February 2, 2006, 1:08 pm
Please log in for more thread options
First you need to make sure that you have proper name resolution between the
domains. In Windows 2003 that can be done with conditional forwarding, dns
stub zones, or creating secondary zones for the other domain in each
domain's dns servers [most likely domain controllers]. From each domain you
should be able to use nslookup and enter the name of the other domain and
get results that show the domain controllers of the other domain. If dns
seems OK you may have a problem with other needed network traffic being
blocked. See the link below which shows what ports/protocols are needed for
Active Directory trusts/replication. --- Steve

http://www.microsoft.com/technet/prodtechnol/windows2000serv/technologies/activedirectory/deploy/confeat/adrepfir.mspx

> We are receiving the following error while trusting a server in a
> different
> forest and domain. The error is the Local Security Policy is unable to
> obtain an RPC connection to the server. Both servers are Windows 2003
> native
> mode. We have 2 other locations that are trusted and working correctly.
> We
> have checked ports 135, 139, and 389 which are open between the VPN sites.
> The trust did create a one way trust. Their server is trusted to us. So
> they can see us but we can't see them. We can ping the server by name. We
> thought perhaps the RPC cannot use the higher ports. Has anyone else had
> this issue?
>
> B Whitaker
>
>



Posted by Roger Abell [MVP] on February 4, 2006, 12:24 pm
Please log in for more thread options
Also, poster did not mention GC ldap ports, not secure DC ldap port (if in
use).
More info is needed IMO on this trust - "trusted to us" is not clear to me,
but
I am guessing this is meaning not a forest trust but a one-way (which way?)
that needs NTLM support, but if not then Kerberos comes into it (poster did
say W2k3 native, but not whether only domain or also forest native).

> First you need to make sure that you have proper name resolution between
> the domains. In Windows 2003 that can be done with conditional forwarding,
> dns stub zones, or creating secondary zones for the other domain in each
> domain's dns servers [most likely domain controllers]. From each domain
> you should be able to use nslookup and enter the name of the other domain
> and get results that show the domain controllers of the other domain. If
> dns seems OK you may have a problem with other needed network traffic
> being blocked. See the link below which shows what ports/protocols are
> needed for Active Directory trusts/replication. --- Steve
>
>
http://www.microsoft.com/technet/prodtechnol/windows2000serv/technologies/activedirectory/deploy/confeat/adrepfir.mspx
>
>> We are receiving the following error while trusting a server in a
>> different
>> forest and domain. The error is the Local Security Policy is unable to
>> obtain an RPC connection to the server. Both servers are Windows 2003
>> native
>> mode. We have 2 other locations that are trusted and working correctly.
>> We
>> have checked ports 135, 139, and 389 which are open between the VPN
>> sites.
>> The trust did create a one way trust. Their server is trusted to us. So
>> they can see us but we can't see them. We can ping the server by name.
>> We
>> thought perhaps the RPC cannot use the higher ports. Has anyone else had
>> this issue?
>>
>> B Whitaker
>>
>>
>
>



Similar ThreadsPosted
Windows 2003 security issue January 25, 2006, 3:50 am
Re: Ntbackup Windows 2003 SP1 issue (VSS/Security) June 13, 2005, 6:37 pm
Re: Ntbackup Windows 2003 SP1 issue (VSS/Security) May 13, 2007, 5:47 pm
local security policy on windows 2003 server April 16, 2007, 10:28 am
Local Security Policy MMC secpol.msc error on Windows Server 2003 March 9, 2007, 10:01 am
Windows 2008 CA can't issue to Windows 2003 server June 25, 2008, 11:53 am
Windows Server 2003 sharing issue July 7, 2005, 2:12 pm
Windows Server 2003 - Services Permissions Issue August 29, 2005, 1:28 pm
IIS or directory security issue on 2003 E server January 12, 2007, 9:56 pm
Local authentication errors on Windows 2003 Server February 23, 2006, 4:56 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap