Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Multiple Windows 2000 Domains

Status
Not open for further replies.

halewood

IS-IT--Management
Jan 8, 2004
2
GB
I work in a School and we have two seperate LANs, 1 is for the students to access and the other is for the administration staff. These networks are completely seperate, is there any way of being able to have the choice of both domains in my drop down box of the logon screen? Both are Windows 2000 domains running AD in native mode with all clients being Windows 2k. I have tried setting up hardware profiles in windows 2k but everytime i join the other domain it removes me from the original.
 
Hi,

You must create trust relationship between the two domains in order to access one another.

But i think it is not possible to have more than one domain in your dropdown box because

Workstations cannot trust (or be a member of) more than one domain.
However, a workstation that is a member of a domain, will implicitly trust any domains that its home domain trusts.





 
you are using two domains. they should be trees in a forest. Example:

School.com
student.school.com
faculty.school.com

At the student level, set up a one way trust where student.school.com trusts faculty.school.com

Remeber that by default all trusts are two-way transitive and will allow students to see things theys shouldn't. Ensure it's converted to a one way trust. Add faculty user accounts to 'Global Groups that are members of the students Domain Local Admin Groups

with the trust in place and authority on the accounts, the teachers and staff could use the student network for anything (based on permissions assigned) and the teachers clients will be able to drop down to any of the domains. A user account in the domain will be required to log on to it.

I've deployed this with five trusts and all domains are in the dropdown box. Sorry I can't post screenshots, but you can do it.

It will require Active Directory and Domains and Trusts knowledge.

 
One more thing, you can greatly improve your security and access through the network with switches and VLANs.

I'll be watching this thread, I'm curious of your progress

Scotty
MPC, MCSA, MCSE, CCNA, CCDA
 
One more thing. You can verify the client knows all of the domains by checking the registry key at the following for the domains and the REG_SZ files for the FQDN.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\windows NT\CurrentVersion\winlogon\DomainCache

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top