Click here to get back home

Unable to access DFS share via DMZ

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Unable to access DFS share via DMZ sekhar 12-13-2006
Posted by sekhar on December 13, 2006, 3:48 am
Please log in for more thread options
Hi,

Can someone help?

Our organisation has one root (forest) “Domain A” and three sub domains
“Domain B” “Domain C”, and “Domain D”. DFS is hosted on Domain B and
Domain
C. We have shared one of the folders from Domain D and have published in DFS.

We are able to access the DFS share via our LAN, however we are not able to
access the same DFS share via one of the DMZ server. This server is member of
Domain B. I am able to browse through the DFS share, but when it comes to
that particular folder it say no netlogon server available to services this
request.

We have firewall between DMZ and our local LAN, however this is no change
done on the firewall.

I am able to resolve all the DCs of each domain from the DMZ server. Tried
recycling Netlogon and DFS on the DMZ server. No luck.


Posted by Roger Abell [MVP] on December 13, 2006, 9:33 am
Please log in for more thread options
The account used is able otherwise to be authorized by the
forest when used in the DMZ? (i.e are needed account domain
DCs accessible?)
Can is directly access the share, avoiding the DFS? (i.e. is
the DFS referral bad, is issue in connecting to the share?)

I find that this use case makes the idea that you do have a
DMZ that protects the "internal" forest questionable.

> Hi,
>
> Can someone help?
>
> Our organisation has one root (forest) "Domain A" and three sub domains
> "Domain B" "Domain C", and "Domain D". DFS is hosted on Domain B and
> Domain
> C. We have shared one of the folders from Domain D and have published in
> DFS.
>
> We are able to access the DFS share via our LAN, however we are not able
> to
> access the same DFS share via one of the DMZ server. This server is member
> of
> Domain B. I am able to browse through the DFS share, but when it comes to
> that particular folder it say no netlogon server available to services
> this
> request.
>
> We have firewall between DMZ and our local LAN, however this is no change
> done on the firewall.
>
> I am able to resolve all the DCs of each domain from the DMZ server. Tried
> recycling Netlogon and DFS on the DMZ server. No luck.
>



Posted by sekhar on December 14, 2006, 5:42 am
Please log in for more thread options
Thank you. I have fixed the issue. Issue was with the Firewall. We opened the
affected port on the firewall and issue got fixed.

"Roger Abell [MVP]" wrote:

> The account used is able otherwise to be authorized by the
> forest when used in the DMZ? (i.e are needed account domain
> DCs accessible?)
> Can is directly access the share, avoiding the DFS? (i.e. is
> the DFS referral bad, is issue in connecting to the share?)
>
> I find that this use case makes the idea that you do have a
> DMZ that protects the "internal" forest questionable.
>
> > Hi,
> >
> > Can someone help?
> >
> > Our organisation has one root (forest) "Domain A" and three sub domains
> > "Domain B" "Domain C", and "Domain D". DFS is hosted on Domain B and
> > Domain
> > C. We have shared one of the folders from Domain D and have published in
> > DFS.
> >
> > We are able to access the DFS share via our LAN, however we are not able
> > to
> > access the same DFS share via one of the DMZ server. This server is member
> > of
> > Domain B. I am able to browse through the DFS share, but when it comes to
> > that particular folder it say no netlogon server available to services
> > this
> > request.
> >
> > We have firewall between DMZ and our local LAN, however this is no change
> > done on the firewall.
> >
> > I am able to resolve all the DCs of each domain from the DMZ server. Tried
> > recycling Netlogon and DFS on the DMZ server. No luck.
> >
>
>
>

Similar ThreadsPosted
Unable to register a dll - "Access is denied" February 1, 2008, 8:23 pm
Monitor Access To A Particular Share September 1, 2005, 8:25 am
Access share on one domain from another? September 12, 2005, 7:50 pm
Monitor Access To A Particular Share February 18, 2007, 6:07 pm
Grant access to a share via command-line? August 4, 2006, 8:49 am
Windows domain user is sometimes denied access to server share October 2, 2006, 5:07 am
There are currently no logon servers available to service the logon request - how to fix this error? i get it when trying to access a share one hop away. April 12, 2007, 6:03 pm
"The process is unable to access the file, because the file is used by another process." October 29, 2005, 5:17 pm
Unable to take ownership October 16, 2005, 4:09 pm
Unable to apply patches January 18, 2007, 6:20 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap