A
AJ
Hi Guys
I have a trust linking two forests together (Windows 2003 and Windows
2008R2). I want the trust to only ever create its secure channel with
two specific domain controllers in one of the forests, so if one fails
the other DC is used as the endpoint. Basically we want to limit the
machines that one of the forests communicates with for authentication
requests. I know you can reset the secure channel using NLTEST etc but
we need to be able to restrcit the trust from jumping to other DCs in
the forest, how can we do this? I dont think creating an additional
site in the forest and installing the domain controllers we want to
handle the auth requests would help, becuase I dont beleive trusts are
site aware and it would ignore the site boundary. Is this possible?
TIA
AJ
I have a trust linking two forests together (Windows 2003 and Windows
2008R2). I want the trust to only ever create its secure channel with
two specific domain controllers in one of the forests, so if one fails
the other DC is used as the endpoint. Basically we want to limit the
machines that one of the forests communicates with for authentication
requests. I know you can reset the secure channel using NLTEST etc but
we need to be able to restrcit the trust from jumping to other DCs in
the forest, how can we do this? I dont think creating an additional
site in the forest and installing the domain controllers we want to
handle the auth requests would help, becuase I dont beleive trusts are
site aware and it would ignore the site boundary. Is this possible?
TIA
AJ