Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Domain validation through VPN

Status
Not open for further replies.

pcunix

MIS
Dec 16, 2001
868
US
NT server 4.0 and ipsec VPN.

Windows 98 machine (remote) has this in LMHOSTS

10.1.1.1 NTSERV1 #PRE #DOM:IMAGETECH
10.1.1.1 "NAMISTECH \0x1b" #PRE

(and may not showw up right here but that is a 16 character name)

nbstat -c says:

Node IpAddress: [192.168.2.2] Scope Id: []
NetBIOS Remote Cache Name Table

Name Type Host Address Life [sec]
------------------------------------------------------------
NTSERV1 <03> UNIQUE 10.1.1.1 -1
NTSERV1 <00> UNIQUE 10.1.1.1 -1
NTSERV1 <20> UNIQUE 10.1.1.1 -1
NAMISTECH <1C> GROUP 0.0.0.0 120
NAMISTECH <1B> UNIQUE 10.1.1.1 -1

VPN is working, I can ping 10.1.1.1, telnet to Unix machines at 10.1.1.91 etc.


Windows machine is configured to logon to domain NAMISTECH

I also set its workgroup to NAMISTECH (read somewhere that might be necessary too)


According to MSOFT article
I had the impression that this would work. But it doesn't- I always get the message that my login is incorrect or wasa refused- note it doesn't say that it can't find the PDC- it says it was refused- I must be missing something..

Tony Lawrence
SCO Unix/Linux Resources tony@pcunix.com
 
Does the lack of response to this indicate that it should work as shown above and it's just that no one has a clue why it doesn't, or that folks reading here have no experience applicable??

Tony Lawrence
SCO Unix/Linux Resources tony@pcunix.com
 
OK- turned out I was using an incorrect password :)

So the VPN works, and I can authenticate to the PDC using just the LMHOSTS file.

Great.

Now, a surprise: I didn't expect to see machines from the other side of the VPN pop up in Network Neighborhood. My expectation was that I'd have to call for them explicitly like Start->Run \\whatever or map a network drive to them.

Yet there they were, unbidden.

This is welcome, but unexpected- netbios name broadcasts shouldn't route, right? I don't specifically have the machines using Wins either, so either NT automagically tells these clients to come get Wins from it, or the VPN is routing these packets..

Anyone shed any light on that?

Tony Lawrence
SCO Unix/Linux Resources tony@pcunix.com
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top