May 2019
Intermediate to advanced
620 pages
21h 41m
English
To create a trust between two environments, make sure that the two environments know how to find each other. In DNS, create any necessary (conditional) forwarders or stub zones to point domain controllers from one environment to the domain controllers or Kerberos Key Distribution Centers (KDCs) of the other environment.
Additionally, take care of proper networking; the domain controller holding the PDCe FSMO role and at least one global catalog for each domain on the route of the trust should be reachable from the device that someone uses to access the resource. The following firewall ports should be opened:
|
Service |
Protocol |
Port |
|
Kerberos authentication |
TCP and UDP |
88 |
|
RPC endpoint mapper |
TCP |
135 |