Re: pls Help!! After Trust, cannot access from local to foreign do



Hi

Can you tell us how your dns configuration is set up on both domains?
Are the clients DNS properties pointing to their local server in their
domain?
Can you post here the results for ipconfig /all for both servers?
If you run dcdiag /v /c /e are you getting any errors?



--
I hop that helps

Good Luck
Jorge Silva
MCSA
Systems Administrator





"chua" <chua@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:06FD0E65-811C-49E7-BA73-96765B8CB5F6@xxxxxxxxxxxxxxxx
Hi Paul,
Thanks for replying.
Actually i doing migration for a customer. Their existing environment
structure is weird. They have 2 domains where both domains have users.
Fileserver is at source domain. Target domain users login to local domain
and
uses UNC method to access filesever in remote domain. When prompt for
authentication, they will use the source domain credentials to login.

1) at the fileserver shared folder, i have added the target domain users
in
the NTFS permission. but once they click the shared, they will get Access
Denied.
I can't possible redo the security permission on the fileserver as they
have
400 of users. i will be a pain to re-assign.

2) i have tried both method. Forest-wide and Selective Authentication.
Which is the better approach? Security is not an issues as both domain
users
from cross-forest should access one another resources.

3) once i remove the trust, the users wil get the prompt for
authentication
box again. Which this is what i want to retain after trust.

steve


"Paul Williams [MVP]" wrote:

But after trust, users at target domain cannot access
resources(fileserver) at source domain anymore..which they used to be
able
to.

They're now probably getting access denied. You need to grant
permissions
to a group to allow access. In the past, I assume the users were
providing
credentials for the local domain when prompted when accessing from the
remote domain?


Any workaround for this? where i can establish trust and users at
target
domain still able to use UNC path to access resources at source
domain??

You need to define access by settings permissions on the objects in
question -shared folders and NTFS permissions in your example.


Error after trust: "the machine you are logging onto is protected by an
authentication firewall."

What options did you choose when you defined the trust? Have you perhaps
enabled selective authentication? Check the trust properties.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net





.



Relevant Pages

  • Re: Remote Web Workplace Issues-Please help!
    ... Open the Server Management Console, ... client after Authentication" right. ... permissions, and Microsoft Windows user rights according to the KB 812614. ... Download the IIS Resource Kit tools from the following page: ...
    (microsoft.public.windows.server.sbs)
  • Re: CGI XPSP2 IIS5.1 - cant write a local file from CGI .exe
    ... operation in the CGI access to read/write in the appropriate folders. ... changes back to the original state before you really screw up the server. ... If Anonymous is not enabled and some other Authentication method is enabled, ... YOU, a third party, by means of either mutual trust in the same Active ...
    (microsoft.public.inetserver.iis)
  • RE: default for requiring authentication 2003
    ... Windows 2000 and earlier would allow access as I described and I ... default for requiring authentication 2003 ... resources that have permissions for Everyone unless you enable this setting. ... same username and password as a user on the domain or on the local server. ...
    (Focus-Microsoft)
  • Re: Help using impersonation - permission problems.
    ... if you use identity impersonate with nt authentication, permissions are only good on the iis server. ... My IIS is set to use Windows NT ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Remote Web Workplace Issues-Please help!
    ... Users cannot connect to remote desktops by using the Windows Small Business ... Server 2003 Remote Web Workplace ... but the user does not have NTFS permissions to the content requested. ... Verify that the correct authentication method is set. ...
    (microsoft.public.windows.server.sbs)

Loading