i had this issue a couple of weeks back & this is certainly achievable, but most of the heavy lifting to be done is actually on the w2k3 side.
using two Windows 2003 Enterprise servers in two different forests & domains, you can map groupA from domainA in forestA to ACS Group1 & groupB from domainB in forestB to ACS Group2. the key is to have a full 2-way transitive trust [I tested using forest-wide trust] between the two domains for the ACS to be able to enumerate windows groups from both domains.
you also need to ensure that the CS__ services run as a domain user's a/c, rather than Local Service. i created a dummy usr in AD & granted it the appropriate privileges in both domains. a reboot or two later [to force the group policies to update], and the 2 way trust validated, i stopped getting the 'failed to enumerate windows groups'.
i don't have my notes on me, but this is just to let you know this's possible. caveats: i tested using acs4, but i'm pretty on the sure side that this can also be done using acs3.3 since they the AD db query driver still functions similarly across domains [again, because this is a windows thing, not acs as much].
Thanks for your kindly help. Actually, i have done according to what you said, but it is still not work fine. I wonder whether i should install acs on domain controller server?(Now, acs is installed on a member server.)
BenefitsDocumentationPrerequisiteImage Download LinksLimitationsSupported PlatformsLicense RequirementsTopologyStep-By-Step ConfigurationConfigure Virtual ServiceActivate the virtual service and configure guest IPsConfiguring UTD (Service Plane)Configurin...
Login to the FXOS chassis manager.
Direct your browser to https://hostname/, and log-in using the user-name and password.
Go to Help > About and check the current version:
Check the current version availa...
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...