Go Back   TechArena Community > Technical Support > Computer Help > Windows 2000 > Windows 2000 Security
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: ,

Restrict access to Share to combination of User + Computer

Windows 2000 Security


Reply
 
Thread Tools Search this Thread
  #1  
Old 05-04-2008
Hans Hinnekint
 
Posts: n/a
Restrict access to Share to combination of User + Computer

Hello,

I would like to restrict the access to some shares to a combination of User
+ Computer, so that this share can only be accessed when the user logs in on
a specific set of computers.

I have static VLANs in place.

What is the best way to handle this?
- EFS
- IPSEC server/computer isolation
- NAP

Any help would be appreciated,

Hans Hinnekint


Reply With Quote
  #2  
Old 09-04-2008
Roger Abell [MVP]
 
Posts: n/a
Re: Restrict access to Share to combination of User + Computer

"Hans Hinnekint" <hans.hinnekint@gmail.com> wrote in message
news:0DB1E758-62ED-4163-8F91-F191EE609C4D@microsoft.com...
> Hello,
>
> I would like to restrict the access to some shares to a combination of
> User + Computer, so that this share can only be accessed when the user
> logs in on a specific set of computers.
>
> I have static VLANs in place.
>
> What is the best way to handle this?
> - EFS
> - IPSEC server/computer isolation
> - NAP
>
> Any help would be appreciated,
>
> Hans Hinnekint


Hi Hans,

There is no direct way to meet those requirements.

If however you can say that all resources on the sharing machine
should only be accessed from a specific set of machines, then one
can use IPsec to enforce the access only "from these computers"
part and use NTFS/share-level permissions to enforce the access
only "by these users" part. Also, if you want to it is possible to
loosen the "all resources on the sharing machine" by having the
IPsec rules govern only the ports needed for filesharing, leaving
other accesses open to more machines.

I have seen a number of people attempt to meet reqs of your
scenario and the above is about as close as you can get with
the current off-the-shelf Windows.

Roger




Reply With Quote
  #3  
Old 11-04-2008
Hans Hinnekint
 
Posts: n/a
Re: Restrict access to Share to combination of User + Computer

Hello Roger,

Thanks, I was afraid I was overlooking something obvious.

Currently we are solving it by putting the server, together with the
machines that need access to it on a separate VLAN and putting a firewal
between this specific VLAN and the regular VLAN on which the DC and regular
servers + computers are located.

But I will keep on looking for something more elegant and dynamical.

Hans
"Roger Abell [MVP]" <mvpNoSpam@asu.edu> wrote in message
news:OTxJl4jmIHA.2396@TK2MSFTNGP02.phx.gbl...
> "Hans Hinnekint" <hans.hinnekint@gmail.com> wrote in message
> news:0DB1E758-62ED-4163-8F91-F191EE609C4D@microsoft.com...
>> Hello,
>>
>> I would like to restrict the access to some shares to a combination of
>> User + Computer, so that this share can only be accessed when the user
>> logs in on a specific set of computers.
>>
>> I have static VLANs in place.
>>
>> What is the best way to handle this?
>> - EFS
>> - IPSEC server/computer isolation
>> - NAP
>>
>> Any help would be appreciated,
>>
>> Hans Hinnekint

>
> Hi Hans,
>
> There is no direct way to meet those requirements.
>
> If however you can say that all resources on the sharing machine
> should only be accessed from a specific set of machines, then one
> can use IPsec to enforce the access only "from these computers"
> part and use NTFS/share-level permissions to enforce the access
> only "by these users" part. Also, if you want to it is possible to
> loosen the "all resources on the sharing machine" by having the
> IPsec rules govern only the ports needed for filesharing, leaving
> other accesses open to more machines.
>
> I have seen a number of people attempt to meet reqs of your
> scenario and the above is about as close as you can get with
> the current off-the-shelf Windows.
>
> Roger
>
>
>



Reply With Quote
  #4  
Old 25-04-2008
Jordi Ribas
 
Posts: n/a
Re: Restrict access to Share to combination of User + Computer

Estimado amigo , no entiendo nada de lo que dice aqui
"Hans Hinnekint" <hans.hinnekint@gmail.com> escribió en el mensaje de
noticias news:0DB1E758-62ED-4163-8F91-F191EE609C4D@microsoft.com...
> Hello,
>
> I would like to restrict the access to some shares to a combination of
> User + Computer, so that this share can only be accessed when the user
> logs in on a specific set of computers.
>
> I have static VLANs in place.
>
> What is the best way to handle this?
> - EFS
> - IPSEC server/computer isolation
> - NAP
>
> Any help would be appreciated,
>
> Hans Hinnekint



Reply With Quote
  #5  
Old 02-12-2008
Member
 
Join Date: Dec 2008
Posts: 3
Re: Restrict access to Share to combination of User + Computer

The only way to surefire solve this issue is to segment the "trusted" computers and manage the traffic via some form of firewall/router.

Ipsec is the only elegant solution and can be administered via GP.

Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows 2000 > Windows 2000 Security


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads for: "Restrict access to Share to combination of User + Computer"
Thread Thread Starter Forum Replies Last Post
How to restrict access to drives in My Computer in Windows 7? Ekpah Operating Systems 5 30-12-2009 03:16 PM
Domain Users/Restrict to User Access Only. Andrew Staley Server Security 8 13-03-2009 09:23 PM
Restrict a user's access during certain times.. shawn Customize XP 2 20-01-2009 09:17 PM
How can I restrict internet access for one user? Maureen Windows Security 6 19-01-2008 03:55 PM
How to restrict user access to internet Joeb Active Directory 6 29-05-2007 01:35 AM


All times are GMT +5.5. The time now is 06:21 PM.