Skip to main content

Trust between two forests (Using DNS stub zone)

Nota

Please note that these steps were tried between two forests with root domain in Windows 2012R2 DC and the Forest functional level used is 2012.

For reference, the forests are named as Forest A and Forest B.

Configure the source DNS server to allow for zone transfers

These steps will be accomplished on both DNS Servers.

To forward lookup zone properties,

  1. Launch the DNS console.

  2. Click on the Forward Look Zone that you desire so configure.

  3. Click on Properties.

    image1.png
  4. Select the Zone Transfers tab.

    image2.png
  5. Select Only to the following servers.

    image3.png
  6. Click on Automatically notify and add the IP of the Forest B. Make sure the IP is resolved and the green check mark appears.

  7. Click OK.

    image4.png

Configure a Stub Zone

These steps will be accomplished in both DNS servers.

To create a new forward lookup zone for Forest B in Forest A,

  1. Launch the DNS Console.

  2. Click on Forward Lookup Zone and choose New Zone.

  3. In the Welcome to the New Zone Wizard, click Next.

    image5.png
  4. Click on Next and select the Zone type.

    image6.png
  5. In the next step, select To all DNS servers running on domain controller in this forest.

    image7.png
  6. On the Zone Name page, enter the desired zone to transfer from, click Next.

    image8.png
  7. Add the IP of Forest B DC and hit Enter. Make sure the IP is resolved.

    image9.png
  8. Click Finish and perform the same steps in Forest B DNS for Forest A.

    image10.png

Nota

nslookup should work from Forest A to Forest B and vice-versa without adding IPs of the domain in Host file.

Create a cross-forest trust 

For Active directory domains and trust,

  1. Go to property of root domain in Forest A. Navigate to Trusts tab and add a new trust.

    image11.png
  2. Enter NetBIOS name of Forest B, on the next screen and enter the admin credentials for Forest B.

    image12.png
  3. Select the Forest trust for trust type.

    image13.png
  4. Select the Two-way direction for this trust.

    image14.png
  5. For Outgoing Trust Authentication Level, select Domain-wide authentication.

    image15.png
  6. Provide a trust password. This is required for creating the trust in Forest B.

  7. Proceed with the wizard and complete it.

    image16.png