Go Back   TechArena Community > Technical Support > Computer Help > Windows Security
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags:

Sponsored Links



Access denied on network share in an other domain

Windows Security


Reply
 
Thread Tools Search this Thread
  #1  
Old 10-06-2009
r14edge
 
Posts: n/a
Access denied on network share in an other domain

Hello,

I'm setting up a DMZ for my company and I'm facing a big problem. I
planned my DMZ on using a remote file storage located in my internal network
to host my web files. I've build my DMZ in a new domain and I have setup a
trust relationship between my internal domain and my DMZ domain. The trust is
one-way where the incoming trust is my internal domain and my outgoing trust
is my DMZ domain. On my remote file server, I'm able to see the account of my
DMZ domain. I've set up the ACL on my share to be use by a specific account
in the DMZ without any problem.

Now, from any server in my DMZ, I'm able to get on the root (\\10.0.0.0) of
my share but when I click on the share itself, I got a access denied message.
I notice in the security log of the remote server that any DMZ servers that
tries to go on the remote file server, are logged under NT
AUTHORITY\ANONYMOUS LOGON.

What am I missing here? I believe that computers in my DMZ should log under
their name in the logs files, right? When I switch the trust relationship,
it's working like a charm, but I'm exposing my internal Domain to my DMZ and
I don't want that.

What can I do to solve this problem?

Thank you for your replies,

Fred
Reply With Quote
  #2  
Old 11-06-2009
Peter Foldes
 
Posts: n/a
Re: Access denied on network share in an other domain

r14edge

Please post this over to the windows.server.security newsgroup where it belongs

On the web:
http://www.microsoft.com/communities...erver.security


--
Peter

Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.

"r14edge" <r14edge@discussions.microsoft.com> wrote in message
news:8265F20F-1B84-479B-B112-FC3B7B45502F@microsoft.com...
> Hello,
>
> I'm setting up a DMZ for my company and I'm facing a big problem. I
> planned my DMZ on using a remote file storage located in my internal network
> to host my web files. I've build my DMZ in a new domain and I have setup a
> trust relationship between my internal domain and my DMZ domain. The trust is
> one-way where the incoming trust is my internal domain and my outgoing trust
> is my DMZ domain. On my remote file server, I'm able to see the account of my
> DMZ domain. I've set up the ACL on my share to be use by a specific account
> in the DMZ without any problem.
>
> Now, from any server in my DMZ, I'm able to get on the root (\\10.0.0.0) of
> my share but when I click on the share itself, I got a access denied message.
> I notice in the security log of the remote server that any DMZ servers that
> tries to go on the remote file server, are logged under NT
> AUTHORITY\ANONYMOUS LOGON.
>
> What am I missing here? I believe that computers in my DMZ should log under
> their name in the logs files, right? When I switch the trust relationship,
> it's working like a charm, but I'm exposing my internal Domain to my DMZ and
> I don't want that.
>
> What can I do to solve this problem?
>
> Thank you for your replies,
>
> Fred


Reply With Quote
  #3  
Old 11-06-2009
r14edge
 
Posts: n/a
Re: Access denied on network share in an other domain

I just did.

Thank you for taking me at the right place.

"Peter Foldes" wrote:

> r14edge
>
> Please post this over to the windows.server.security newsgroup where it belongs
>
> On the web:
> http://www.microsoft.com/communities...erver.security
>
>
> --
> Peter
>
> Please Reply to Newsgroup for the benefit of others
> Requests for assistance by email can not and will not be acknowledged.
>
> "r14edge" <r14edge@discussions.microsoft.com> wrote in message
> news:8265F20F-1B84-479B-B112-FC3B7B45502F@microsoft.com...
> > Hello,
> >
> > I'm setting up a DMZ for my company and I'm facing a big problem. I
> > planned my DMZ on using a remote file storage located in my internal network
> > to host my web files. I've build my DMZ in a new domain and I have setup a
> > trust relationship between my internal domain and my DMZ domain. The trust is
> > one-way where the incoming trust is my internal domain and my outgoing trust
> > is my DMZ domain. On my remote file server, I'm able to see the account of my
> > DMZ domain. I've set up the ACL on my share to be use by a specific account
> > in the DMZ without any problem.
> >
> > Now, from any server in my DMZ, I'm able to get on the root (\\10.0.0.0) of
> > my share but when I click on the share itself, I got a access denied message.
> > I notice in the security log of the remote server that any DMZ servers that
> > tries to go on the remote file server, are logged under NT
> > AUTHORITY\ANONYMOUS LOGON.
> >
> > What am I missing here? I believe that computers in my DMZ should log under
> > their name in the logs files, right? When I switch the trust relationship,
> > it's working like a charm, but I'm exposing my internal Domain to my DMZ and
> > I don't want that.
> >
> > What can I do to solve this problem?
> >
> > Thank you for your replies,
> >
> > Fred

>
>

Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Security


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Access denied on network share in an other domain"
Thread Thread Starter Forum Replies Last Post
After changing Share permissions, Even admin is access denied to format Richiedj Small Business Server 10 15-07-2009 07:07 AM
Access denied: Is there a trick to connecting to an XP SP3 share from Vista? Milhouse Van Houten Windows Vista Network 4 12-12-2008 08:40 PM
Access Denied on Network Share Files jjgriss Windows Vista Network 0 17-11-2007 02:10 AM
File server denied access by Domain Controller: Access is denied because of failure to authenticate Jim Windows Server Help 2 24-05-2007 10:46 AM
Vista "Access Is Denied" Trying to Access Network Share justin.richert@gmail.com Windows Vista Network 2 26-03-2007 06:48 PM


All times are GMT +5.5. The time now is 08:02 AM.