RE: Connection problem with 98 station on 2003 AD domain



Hello,

Thanks for your response and give me a right direction.

First, I want to know if you created a new 2k3 domain and rejoin all
clients to the new domain manually.

If so, I think the root cause is that those 98 clients do not have SMB
packet signing enabled and cannot authenticate to a Windows Server 2003
domain controller.

For more information about it, please check the following KB article:
How to enable Windows 98/ME/NT clients to logon to Windows 2003 based
Domains
http://support.microsoft.com/default.aspx?scid=kb;en-us;555038

For your convenience, I pasted the detailed content regarding the 98
clients as following:

Client side:

Windows 98/ME

1. Install Internet Explorer 6 with Service Pack 1 or higher.

2. Install DSCLIENT utility from Windows 2000 Server installation disk or
from

http://support.microsoft.com/default.aspx?scid=kb;en-us;288358

Note: Please review the knowlagebase: "Directory Services Client Update for
Windows 98" 323455:

http://support.microsoft.com/default.aspx?scid=kb;en-us;323455

3. Enable NTLM 2 Authentication (please see "More Information" section for
details).

4. Enable SMB Signing (please see "More Information" section for details).

5. Configure the workstation to use local WINS server.

6. Consider installing the hotfixes that descrive in:

Service Packs and Hotfixes That Are Available to Resolve Account
Lockout Issues

http://support.microsoft.com/default.aspx?scid=kb;en-us;817701

7. Configure the local DNS domain as DNS under TCP/IP properties.


Note: If you are using Windows 95, please follow the knowlagebase bellow:
http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;811497

Note: If the logon problem is'nt resolved, please review the following
knowlagebase:

Problems logging on to a Windows 2000-based server or a Windows 2003-based
server
http://support.microsoft.com/default.aspx?kbid=272594

Server side:

1. Configure each server in the domain to use local WINS server.

2. If you are using Windows 2000 or higher DHCP server, make sure that the
DHCP can register old clients.

3. Review: KB 898060

http://support.microsoft.com/default.aspx/kb/898060

Note: Some articles recommend to disable SMB sign in the domain controller
OU. Please avoid changing domain
controllers policy, and specialy dont disable SMB sign.

Note: Windows 98/ME clients have problem with computer names largers then
eight characters. Please avoid
using long computer names.

HTH! If there is any process, please feel free to let me know.

Thanks & Regards

Amanda Wang [MSFT]

Microsoft Online Partner Support

Get Secure! - www.microsoft.com/security

====================================================================

When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.

=====================================================================

--------------------
>Thread-Topic: Connection problem with 98 station on 2003 AD domain
>thread-index: AcVaNEpSCIJGHS2cTjiU1quOTayBJQ==
>X-WBNR-Posting-Host: 82.64.237.59
>From: "=?Utf-8?B?SmVhbi1FbW1hbnVlbCBmcm9tIEZyYW5jZQ==?=" <Jean-Emmanuel
from France@xxxxxxxxxxxxxxxxxxxxxxxxx>
>References: <05E731D3-FA49-42A5-B937-DBFF329180A9@xxxxxxxxxxxxx>
<m$9Xo0gWFHA.3336@xxxxxxxxxxxxxxxxxxxxx>
>Subject: RE: Connection problem with 98 station on 2003 AD domain
>Date: Mon, 16 May 2005 09:28:28 -0700
>Lines: 19
>Message-ID: <C4D66E6F-4356-4C4F-9774-0A931DD0AE79@xxxxxxxxxxxxx>
>MIME-Version: 1.0
>Content-Type: text/plain;
> charset="Utf-8"
>Content-Transfer-Encoding: 7bit
>X-Newsreader: Microsoft CDO for Windows 2000
>Content-Class: urn:content-classes:message
>Importance: normal
>Priority: normal
>X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.0
>Newsgroups: microsoft.public.windows.server.migration
>NNTP-Posting-Host: TK2MSFTNGXA03.phx.gbl 10.40.2.250
>Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGXA03.phx.gbl
>Xref: TK2MSFTNGXA01.phx.gbl microsoft.public.windows.server.migration:10201
>X-Tomcat-NG: microsoft.public.windows.server.migration
>
>
>Thanks a lot for your response even if I managed to solve the problem.
>To answer tour questions :
> - Yes, I can ping the W2k3 server, by IP address but not the name of the
>server. THIS put me on the right way to solve my problem.
> - No, for the moment there isn't any BDC on the domain, but soon a w2k
>server.
> - Yes, none of them. That's why I was so amazed...
> - For the IP, I use a gateway (in fact, simply a switch with 2
addresses),
>for NetBios, I use a standalone NT WINS server : seems to work.
> - THAT was the point!!!
> - No, except that it said : "Can't reach any DC for this domain".
>
>Thanks again for your quick answer.
>
>Jean-Emmanuel from France.
>
>
>
>

.



Relevant Pages

  • Re: Users Cant Access Documents on Server
    ... my computer to the network on the server. ... Connection Wizard none of the computers were listed. ... The Mac clients can not communicate with the server box. ... > Error Messages When You Open or Copy Network Files on Windows XP SP1 ...
    (microsoft.public.windows.server.sbs)
  • Re: Group Policy Results Wizard
    ... I guess we can rule out Windows ... If you can't reach the WMI from the server you will want to try to reach it ... switching off the Windows Firewall on one of the clients, ... Business Server Windows Firewall" (not Small Business Server ...
    (microsoft.public.windows.server.sbs)
  • Re: Cannot join Windows 2003 Server to SBS 2000 Domain
    ... this on all client computers at this remote office. ... All the clients but one at the main office are Windows XP Pro. ... > 'adprep' commands on the SBS 2000 server. ...
    (microsoft.public.windows.server.sbs)
  • Re: Users Cant Access Documents on Server
    ... > then add my computer to the network on the server. ... Did you not see the computers in the Server Management taskpad section? ... The Mac clients can not communicate with the server box. ... >> Error Messages When You Open or Copy Network Files on Windows XP SP1 ...
    (microsoft.public.windows.server.sbs)
  • Re: EAP-TLS with windows CE
    ... Thanks for the quick response. ... Windows CE then prompts the wireless user for the ... to the AP which gets passed on to an authentication server (RADIUS or ... nothing to do with the contents of the certificate at all. ...
    (microsoft.public.windowsce.platbuilder)