LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-01-2009, 12:24 PM   #1
chris71mach1
LQ Newbie
 
Registered: Apr 2005
Location: DFW
Distribution: Debian
Posts: 21

Rep: Reputation: 1
Off-base domain authentication over VPN problem


so i guess this is kind of a strange, and seemingly complicated problem. I have a DMVPN (for arguments sake, lets just say its a site-to-site, as the functionality seems the same so far) set up between 2 cisco routers between our corp HQ and a branch office. as far as the vpn tunnel goes, everything seems to be working fantastic. traffic flows fine in both directions, i can ssh, vnc, and seemingly use (almost) any protocol i need to from one side to the other.

oh the HQ end of the vpn tunnel, we have a samba domain controller set up on a debian etch machine, with samba handing out various network shares to the users. on the branch office end, we will have nothing but windows users that need to log into this domain and map those shares to be able to function from one day to the next. now the problem that we're having thus far is that the windows clients on the branch end cannot even SEE the domain on the HQ end of the vpn tunnel, regardless of what ive tried thus far.

So far, ive tried to use a lmhosts file on the client machines to point them to the domain controller, to no avail, setting the IP of the domain controller in the client machine's dns did nothing, and i even found this link: http://support.microsoft.com/kb/244474 that made me wonder if the issue could be caused by UDP packet fragmentation due to the vpn tunnel, but that registry hack didnt work either.

at this point, im kind of at the end of my rope wondering why in the world my clients cant see the domain at all from the other end of a vpn tunnel, when those same machines work just fine when theyre on the local LAN. im open to suggestions folks, any help would be GREATLY appreciated.
 
Old 09-02-2009, 05:10 PM   #2
chris71mach1
LQ Newbie
 
Registered: Apr 2005
Location: DFW
Distribution: Debian
Posts: 21

Original Poster
Rep: Reputation: 1
well we finally nailed down the solution to this problem, and it seemed to be 3 fold. im going to go ahead and post the solution(s) here just in case anybody else has a similar problem and in hopes that this post may be helpful in the future.

(1) the smb.conf file on the domain controller needed the remote subnet added to allow clients on the remote end of the VPN tunnel to authenticate to the domain controller.

(2) added port forwarding to the router on the remote end of the tunnel to forward netbios traffic bound for the router (on the remote end) to the domain controller on the server (local) end of the tunnel.

(3) removed remote client from the domain and then re-join the remote client to the domain, while the remote client has an IP from the remote end's dhcp server.

after fiddling with the remote client and rebooting the XP box a couple of times (yea, we all know how the reset button on a windows machine can be the universal "fix everything" button) we were finally able to get the remote client to not only authenticate to the domain, but also map the network share drives with full functionality.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Domain Authentication Problem lazaroonie Linux - Server 1 06-11-2009 08:03 AM
authentication problem with samba 3 and child domain in ads mode avenger756 Linux - Server 0 06-10-2008 02:52 PM
Problem with connecting to MS Domain(WIN NT 4.0) thru Linux VPN!! deid Linux - Networking 1 03-20-2006 05:52 AM
How to install VPN server base on fedora core 2 happyskyzl Linux - Networking 0 10-03-2004 09:35 PM
How to resolve base domain name using bind/named? qidwai Linux - Networking 2 05-08-2004 10:46 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 01:50 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration