Hi everyone.
Got a problem that I think is NTLM related, but not sure.
Scenario. We have a Linux based firewall with 3 legs, WAN, LAN and DMZ - a
pretty standard set of rules apply, including LAN having full access to the
DMZ
LAN segment with W2K and W2003 servers, plus XP clients (servers and clients
in AD Domain)
DMZ segment with W2K and W2003 servers (all servers in workgroup DMZ)
What doesn't work - W2K and XP clients on the LAN cannot connect to shares
on the DMZ based W2003 server
What does work -
W2K and XP clients on the LAN can connect to shares on the DMZ based W2000
server.
W2003 Servers on the LAN can connect to shares on the DMZ based W2003
server.
W2000 Servers on the DMZ can connect to shares on the DMZ based W2003
server.
On the W2003 DMZ server, I modified the local security policy setting "LAN
Manager Authentication Level" from "send NTLMv2 response only" TO "send LM
and NTLM responses" thinking that this was the sort of problem I was having.
Unfortunately after restarting the server last night, I could still not
access shares on this box from my LAN based XP and W2K boxes.
Am I in the right ball-park or is there something else to look at. ?
Steve
|