On Premise domain prerequisites:
You must configure your on-premises firewall so that the ports below are open to the CIDRs for all subnets used by the VPC that contains your AWS Managed Microsoft AD
TCP/UDP 53 - DNS
TCP/UDP 88 - Kerberos authentication
TCP/UDP 389 - LDAP
TCP 445 - SMB
On your on-premises domain controller, open Server Manager.
On the Tools menu, choose Active Directory Users and Computers.
Choose the Users folder and open the context (right-click) menu. Select any random user account listed in the right pane. Choose Properties.
Choose the Account tab. In the Account options list, scroll down and ensure that Do not require Kerberos preauthentication is not checked.
AWS Prerequisites
Configure the trust
To configure the trust in your on-premises AD
Open Server Manager and on the Tools menu, choose Active Directory Domains and Trusts.
Open the context (right-click) menu of your domain and choose Properties.
Choose the Trusts tab and choose New trust. Type the name of your AWS Managed Microsoft AD and choose Next.
Choose Forest trust. Choose Next.
Choose Two-way. Choose Next.
Choose This domain only. Choose Next.
Choose Forest-wide authentication. Choose Next.
Type a Trust password. Make sure to remember this password as you will need it when setting up the trust for your AWS Managed Microsoft AD.
In the next dialog box, confirm your settings and choose Next. Confirm that the trust was created successfully and again choose Next.
Choose No, do not confirm the outgoing trust. Choose Next.
Choose No, do not confirm the incoming trust. Choose Next.
To configure the trust in your AWS Managed Microsoft AD directory
In the Directory Service console on the Directories page, choose your AWS Managed Microsoft AD.
On the Directory details page, select the Networking & security tab.
In the Trust relationships section, choose Actions, and then select Add trust relationship.
On the Add a trust relationship page, Type the FQDN of your on-premises domain (domainname.local or whatever your domain is called). Type the same trust password that you used when creating the trust on your on-premises domain. Specify the direction. In this case we choose Two-way.
In the Conditional forwarder field, enter the IP address of your on-premises DNS servers.You can add another IP address and enter a second IP address for your on-premises DNS server. You can specify up to a total of four DNS servers.
Choose Add.
No comments:
Post a Comment