Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Trust Issues, Please Help (VPN)

Reply
Thread Tools Display Modes

Trust Issues, Please Help (VPN)

 
 
Sam Manzella
Guest
Posts: n/a

 
      05-20-2005
Hi, I'm having some difficulties getting users from a different location to
access files on one of our Servers. Here is the situations:

Server1 = Windows 2000 Server
Server2 = Windows 2003 Server

(VPN here)

Server3 = Windows 2000 Server

Server1 & Server2 are both domain controllers at location "A". Same Domain
name. Server2 was brought up as a replica to Server1, and then the Roles
were moved to it. Server3 is also a Domain controller (different Domain
name) at location "B" and communicates with our location "A" servers via a
VPN (firewall configured)

Users from Server1 & Server2 (same users since same domain) can access
shares on Server3 without any problems.

Users from Server3 can access shares on Server1 without any problems, but
cannot access shares on Server2. They are not even prompt to logon or
anything.

This issue is driving me a little insane, as I plan on removing Server1...
but if I do that, then I've lost my only communication path for Server3 to
our "A" location.

Please help.

Thanks,
Sam



 
Reply With Quote
 
 
 
 
Todd J Heron
Guest
Posts: n/a

 
      05-21-2005
Please review your post. While you tell us "Server3 is a differnet domain
name" then how can "users from Server1 & Server2 (same users since same
domain) can access shares on Server3 without any problems."?

--
Todd J Heron, MCSE
Windows Server 2003/2000/NT; CCA
----------------------------------------------------------------------------
This posting is provided "as is" with no warranties and confers no rights

 
Reply With Quote
 
Sam Manzella
Guest
Posts: n/a

 
      05-23-2005
Hi Todd,

Thanks for the reply. What I wrote is correct, but may not be clear though.

The three servers all servers have some shared folders.

All users from Server1 and Server2 (both domain controllers on same Domain
name at Location "A") can access the shared folders on Server3 at Location
"B" (which is a different Domain name).

Users from Server3 at Location "B" can access shares on Server1 (at location
A), but cannot access shares on Server2 (this is the Windows2003 Server).

Server1 and Server2 are on a 192.168.0.X network, and Server3 is on a
192.168.5.X network.

Hope that clarifies the configuration a little.

Thanks again.




"Todd J Heron" <> wrote in message
news:%...
> Please review your post. While you tell us "Server3 is a differnet domain
> name" then how can "users from Server1 & Server2 (same users since same
> domain) can access shares on Server3 without any problems."?
>
> --
> Todd J Heron, MCSE
> Windows Server 2003/2000/NT; CCA
> ----------------------------------------------------------------------------
> This posting is provided "as is" with no warranties and confers no rights
>



 
Reply With Quote
 
Sam Manzella
Guest
Posts: n/a

 
      05-23-2005
I guess to answer your question.... Two-Way Trusts are allowing Users from
each domain to access shared folders on the other domain. I've tried to
verify and/or recreate the Trusts between the domains, but it doesn't let me
(however, the Trust between the two domains is still in place??)

Anyway, over my head... which is why I'm asking for some help here.

Thanks,
Sam





"Sam Manzella" <> wrote in message
news:...
> Hi Todd,
>
> Thanks for the reply. What I wrote is correct, but may not be clear
> though.
>
> The three servers all servers have some shared folders.
>
> All users from Server1 and Server2 (both domain controllers on same Domain
> name at Location "A") can access the shared folders on Server3 at Location
> "B" (which is a different Domain name).
>
> Users from Server3 at Location "B" can access shares on Server1 (at
> location A), but cannot access shares on Server2 (this is the Windows2003
> Server).
>
> Server1 and Server2 are on a 192.168.0.X network, and Server3 is on a
> 192.168.5.X network.
>
> Hope that clarifies the configuration a little.
>
> Thanks again.
>
>
>
>
> "Todd J Heron" <> wrote in message
> news:%...
>> Please review your post. While you tell us "Server3 is a differnet domain
>> name" then how can "users from Server1 & Server2 (same users since same
>> domain) can access shares on Server3 without any problems."?
>>
>> --
>> Todd J Heron, MCSE
>> Windows Server 2003/2000/NT; CCA
>> ----------------------------------------------------------------------------
>> This posting is provided "as is" with no warranties and confers no rights
>>

>
>



 
Reply With Quote
 
Todd J Heron
Guest
Posts: n/a

 
      05-23-2005
Your trusts are working fine based on your description. Guessing here now,
but it may be an SMB-signing issue on the 2003 server. You may need to
relax the security a little bit to allow access.

On the server, open up Group Policy snap-in and browse to:

Security Settings\Local Policies\Security Options

Disable the following settings:

Microsoft network server: Digitally sign communications (always)
Microsoft network client: Digitally sign communications (always)

--
Todd J Heron, MCSE
Windows Server 2003/2000/NT; CCA
----------------------------------------------------------------------------
This posting is provided "as is" with no warranties and confers no rights

 
Reply With Quote
 
Sam Manzella
Guest
Posts: n/a

 
      05-23-2005
Thanks Todd. I just disabled both those settings from:

"Default Domain Controller Security Settings" and "Default Domain Security
Settings"

I logged off and logged back on (Server2).

At that point, I asked a user from Location B to access the share (I sent
them a link to a shared folder on Server2), but it still didn't work. I had
that user Logoff and log back on to make sure, but still no luck.

The user gets an error that says "Cannot find file (sharename). Make sure
path or internet address is correct" << wording may not be exact, but it's
along those lines.

I also included a link to a share on Server1, and as before, that worked
fine.

???????








"Todd J Heron" <> wrote in message
news:%...
> Your trusts are working fine based on your description. Guessing here
> now,
> but it may be an SMB-signing issue on the 2003 server. You may need to
> relax the security a little bit to allow access.
>
> On the server, open up Group Policy snap-in and browse to:
>
> Security Settings\Local Policies\Security Options
>
> Disable the following settings:
>
> Microsoft network server: Digitally sign communications (always)
> Microsoft network client: Digitally sign communications (always)
>
> --
> Todd J Heron, MCSE
> Windows Server 2003/2000/NT; CCA
> ----------------------------------------------------------------------------
> This posting is provided "as is" with no warranties and confers no rights
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: Unable to Establish 2003/NT4 Trust Relationship andre.nadeau Windows Server 1 04-20-2005 01:00 AM
Openldap and Active Directory trust relationship david carvalho Windows Server 0 11-23-2004 03:47 PM
Secure Channel Verification Failure When Verifying A Trust Relatio Jay Windows Server 0 11-17-2004 09:24 PM
Trust relationship 2003 Domain with NT4 Domain Kevan Windows Server 0 09-17-2004 10:03 AM
2003 Domain Trust with NT4 Domain Kevan Windows Server 0 09-16-2004 04:17 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59