DSM-G600, DNS-3xx and NSA-220 Hack Forum

Unfortunately no one can be told what fun_plug is - you have to see it for yourself.

You are not logged in.

Announcement

#1 2010-03-02 15:13:05

heazlewood
Member
Registered: 2008-05-22
Posts: 11

Domain credentials and public accees questions

hi

I'm having some difficulties getting security to work correctly with windows and a DNS 323.

I have a windows 2008 AD domain of which all my PC's are a member.
A DNS 323 with Firmware Version 1.08 (Firmware Date: 08/05/2009).
Most of my PC's are server 2008, Server 2008 R2 or windows 7.

I want I would like to do is:
have one drive set as public access, accessible by all with out the need to enter credentials.
The second I would like to limit to admins only.

If any user tries to access the second drive and the domain username and password matches a username and password of a user on the DNS323 that is in the admin group i would like them to get access to the drive with out the need to enter credentials.

I set up drive 1 giving "all accounts" read write access, and added the public account to the users group.
I set up the second drive by granted that group read write access for the admin Group.
I added account "myAdminAccount" to the DNS and made it a member of the admin group.
In my AD domain I have the user domain\myAdminAccount, the password matches the myAdminAccount on the DNS.


With FW 1.06 drive one would work, drive 2 would not, If i was logged on to the domain i would not need credentials to access the frist drive, but even when logged on as "domain\myAdminAccount", i could not access the second drive with out entereing credentials with the username "\myAdminAccount".

I decide to try FW 1.08
now accessing both drives requires a username and password.

I'm a bit confused as to how the credential are supposed to work.

I was hoping someone here might know how I can achieve the desired configuration?
And if there are any new issues with FW 1.08?

Any information would be greatly appreciated.

thanks

Offline

 

#2 2010-03-03 01:16:11

heazlewood
Member
Registered: 2008-05-22
Posts: 11

Re: Domain credentials and public accees questions

I have tried a couple of things with no luck.

I have upgraded to a later version of 1.08 (the link on the Dlink support page goes to a beta)
I now have Firmware Version : 1.08 (Firmware Date : 12/18/2009)

I tried loading up secpol.msc on a windows PC and setting
Network security: LAN manager authentication level to - send LM & NTLM - use NTLMv2 session security when negotiated

Still, even with public account enabled and added to the users group, when i try to connect to the dns323 i am asked for a username password.
This did not happen in FW 1.06.

Again any help here would be greatly appreciated.

Cheers

Offline

 

#3 2010-03-03 01:35:27

fordem
Member
Registered: 2007-01-26
Posts: 1938

Re: Domain credentials and public accees questions

I don't know if you're aware of it - I'm guessing not - but the DNS-323 does not support active directory.

Offline

 

#4 2010-03-03 01:47:30

heazlewood
Member
Registered: 2008-05-22
Posts: 11

Re: Domain credentials and public accees questions

Hey fordem
I did realise that.

However I thought that if "all accounts" were given access to a share, any device connecting to the DNS323 should require a username and pass to connect. This was working with FW 1.6, however now i need to authenticate to get access.

I had also assumed that if I created a user on the DNS323 that matched (same username and password) a domain account that domain account would not need to authenticate with the DNS to get elevated privileges, if i added the accoung to the admin group.

Should these senarios be working?
Maybe i should go back to FW 1.6 is that possible (i should atleast get the annon access back then)?

I see that FW 1.8 has support for NFS, would this solve some some of my problems?


Thanks

Edit - some changes were lost (i think cos of Firefox plugin 'after the deadline')

Last edited by heazlewood (2010-03-03 01:55:15)

Offline

 

Board footer

Powered by PunBB
© Copyright 2002–2010 PunBB