Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

FTP Permission Question

Status
Not open for further replies.

SFSRJSTW

Technical User
Jan 2, 2004
82
US
I am running Server 2003 Standard with all patches up to today. I have a NetApp Filer as network attached storage with a default share setup. I have set Server 2K3 to use that share as the default FTP directory. Permissions on sub folders are all properly set. All standard users are able to access the NAS unit via FTP and only get into their folder, etc. However, no Domain Admins are able to log in. When using WS_FTP, the error message I get is 503: User <user name> cannot log in, home directory inaccessible. All documentation I can find says to make sure that read/write is set for the FTP site. It is...and everything works fine for standard users. It's only Domain Admins who have problems. Any ideas would be wonderfully appreciated as I'm banging my head on this one!

~Thanks
 
SFSRJSTW,

Is the Domain Admins group a member of the Users group?
Did you deny full control to Domain Admins?

Wishdiak
A+, Network+, Security+, MCSA: Security 2003
 
Domain Admins are in the Users group, and they have full control to the FTP Root and sub folders.
 
SFSRJSTW,

If that's the case, then check the home directory mapping for Domain Admin accounts. The error seems to indicate that the home directory mapping is the problem.

Wishdiak
A+, Network+, Security+, MCSA: Security 2003
 
Sorry for the delay in an update...have been on vacation and at some conferences.

The home directory for the FTP root seems to be okay as far as I can tell. And to make things a little more odd is the fact that if I set up FTP on Win 2K Server pointing to the same network attached storage folder for the FTP root and keeping authentication based on a users domain account, everything works fine...including access by Domain Admins.

This seems to me to indicate that it has something to do with Domain Admins in Win 2K3, but I'm starting to run out of ideas.

Thanks for your help so far. Any other ideas would be greately appreciated!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top