1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Windows 2000 and VPN

Discussion in 'Legacy Windows' started by jcrompton, 2002/11/11.

Thread Status:
Not open for further replies.
  1. 2002/11/11
    jcrompton

    jcrompton Inactive Thread Starter

    Joined:
    2002/11/11
    Messages:
    3
    Likes Received:
    0
    I have a number of notebook users accessing my network using a VPN connection with Checkpoint Firewall 1 and Checkpoint SecuRemote client software. Everything works well for Windows NT 4 based notebooks but Windows 2000 clients cannot map or browse network drives unless they have the allow dialin flag set on their user accounts AND they are part of the domain administrators group. The W2K clients can do everything else (ping machines on the network, net view and list machines on the network, view machines on the network using network neighborhood etc).

    I am running a mixed mode W2K domain.

    Can anyone tell me what permissions these W2K clients need and how I can get these permissions assigned to a dial-in users group?
     
  2. 2002/11/11
    mflynn

    mflynn Inactive

    Joined:
    2002/08/14
    Messages:
    4,141
    Likes Received:
    9
    jcrompton

    What OS are the remotes calling into? NT or W2K?

    If it is W2K and probably NT you should install the NETBEUI protocol on both ends! This will allow browsing of the network!

    Mike
     

  3. to hide this advert.

  4. 2002/11/11
    Hulka

    Hulka Inactive

    Joined:
    2002/01/07
    Messages:
    330
    Likes Received:
    0
    If they're dialing into a Windows 2000 server running RRAS check out your Remote Access Policy. You may be limiting your users' abilities in the policy. This would only affect Windows 2000/XP users.
     
  5. 2002/11/12
    jcrompton

    jcrompton Inactive Thread Starter

    Joined:
    2002/11/11
    Messages:
    3
    Likes Received:
    0
    Thanks for the input. Some clarification on the situation:

    1. We are running a mixed mode Windows 2000 and NT domain as a child of a W2K root domain. The PDC emulator is a W2K DC.

    2. W2K remote clients can access the network, see all the PCs and servers on the network, access the intranet server with a web browser but they cannot map network drives or access mapped network drives UNLESS they are in the domain administrators group (not good).

    3. NT remote clients have no problem accessing or mapping network drives.

    4. The hosts and lmhosts files on all remote clients are identical.

    5. We are not running NETBEUI but I will give it a go

    6. We do not run any RAS server or VPN server so I am not convinced that remote access policies apply here.

    J
     
  6. 2002/11/12
    Hulka

    Hulka Inactive

    Joined:
    2002/01/07
    Messages:
    330
    Likes Received:
    0
    Ok, my bad...I re-read your original post where you stated using Checkpoint VPN software. I was thinking for some reason you were utilizing the Microsoft implementation of VPN connectivity. I'm not familiar with Checkpoint's products but on their site it looks as if there are access policies defined in their products so I wouldn't rule that out.

    Since adding the users to the Domain Admins groups grants them access, this tells me the problem may lie more in the users accounts rather than the OS. Perhaps these users simply don't have the appropriate permissions to these shares defined at the user and/or group account level.
     
  7. 2002/11/12
    jcrompton

    jcrompton Inactive Thread Starter

    Joined:
    2002/11/11
    Messages:
    3
    Likes Received:
    0
    Mmmmmmm

    Doesn't explain why the same user on Windows NT can browse mapped drives OK and when using W2K cannot access the self same mapped drives.

    It has to be a permissions thing but I cannot for the life of me see where.

    J :confused:
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.