Networking Forums

Networking Forums > Computer Networking > Windows Networking > Cannot join domain or change passwords through firewall

Reply
Thread Tools Display Modes

Cannot join domain or change passwords through firewall

 
 
Cires
Guest
Posts: n/a

 
      08-02-2005, 07:32 PM
Hi All,

Bit of a weird problem. We have some NT clients on the outside of our pix
firewall. They can log onto the domain, pick up e-mail (exchange) and map
network drives, but the users cannot change their passwords or join a pc to
the domain.

Also can't use user manager, server manager etc. They get error messages
like "domain xxxxx is not available" etc.

When we try to join a machine to the domain, we get prompted for
credentials etc, but after that it fails.

Any other ports that may have been missed? We've opened 137, 138, 139.

HELP!
Cires
 
Reply With Quote
 
 
 
 
Michael Giorgio - MS MVP
Guest
Posts: n/a

 
      08-02-2005, 08:08 PM
Can we assume they also some form of name resolution
e.g., WINS or lmhosts? If not the clients may not be able
to find the PDC and setup a secure channel. In NT 4.0
the PDC holds the only modifiable copy of the SAM therefore
it must be contacted when making any domain wide changes.
Immediately after a failed password change attempt open a
dos prompt and run nbtstat -c. What do you see? You should
at least see computer names 00, 20., 03, domain names 1b
and 1c also pointing towards the PDC of the domain.

"Cires" <(E-Mail Removed)> wrote in message news:
> Bit of a weird problem. We have some NT clients on the outside of our pix
> firewall. They can log onto the domain, pick up e-mail (exchange) and map
> network drives, but the users cannot change their passwords or join a pc
> to
> the domain.
>
> Also can't use user manager, server manager etc. They get error messages
> like "domain xxxxx is not available" etc.
>
> When we try to join a machine to the domain, we get prompted for
> credentials etc, but after that it fails.
>
> Any other ports that may have been missed? We've opened 137, 138, 139.
>



 
Reply With Quote
 
Cires
Guest
Posts: n/a

 
      08-02-2005, 10:21 PM
Hi there,

We were using WINS and when that didn't work we tried hosts/lmhosts files.
Still no joy.
I'll try the nbtstat -c tomorrow, thanks.

Cires


"Michael Giorgio - MS MVP" <(E-Mail Removed)> wrote
in news:(E-Mail Removed):

> Can we assume they also some form of name resolution
> e.g., WINS or lmhosts? If not the clients may not be able
> to find the PDC and setup a secure channel. In NT 4.0
> the PDC holds the only modifiable copy of the SAM therefore
> it must be contacted when making any domain wide changes.
> Immediately after a failed password change attempt open a
> dos prompt and run nbtstat -c. What do you see? You should
> at least see computer names 00, 20., 03, domain names 1b
> and 1c also pointing towards the PDC of the domain.

 
Reply With Quote
 
Cires
Guest
Posts: n/a

 
      08-05-2005, 06:52 PM
Cires <(E-Mail Removed)> wrote in
news:Xns96A6D1087F157stan110nospamhotmail@216.196. 109.145:

Hello People,

If I run nbtstat -c from a pc on site I get (00) (1c) and (20)
If I search for the PDC server I can see it OK, and can open the netlogon
share. I can do a "Net Use" and map a drive.
However, from My Network places I can only see the other PCs on the same
site.

Any thoughts?

Cires




> Hi All,
>
> Bit of a weird problem. We have some NT clients on the outside of our
> pix firewall. They can log onto the domain, pick up e-mail (exchange)
> and map network drives, but the users cannot change their passwords or
> join a pc to the domain.
>
> Also can't use user manager, server manager etc. They get error
> messages like "domain xxxxx is not available" etc.
>
> When we try to join a machine to the domain, we get prompted for
> credentials etc, but after that it fails.
>
> Any other ports that may have been missed? We've opened 137, 138, 139.
>
> HELP!
> Cires
>


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Server 2008 with Hyper-V - domain controller - Firewall GUI's show firewall ON, but netsh reports firewall OFF Bruce Sanderson Windows Networking 7 10-07-2008 09:57 AM
Clients can't join domain-new Primary Domain Controller installed blinton25 Windows Networking 7 06-23-2008 09:58 PM
FTP - Let local users change their passwords Dan Windows Networking 0 02-25-2007 07:56 PM
Change password with 802.1x WinXP and cached Passwords. Michael King Wireless Networks 0 04-25-2005 02:03 PM
Win98 Users cannot change their Domain Passwords Tim Windows Networking 0 07-16-2003 09:07 PM



1 2 3 4 5 6 7 8 9 10 11