Re: Assign Domain Security Policy/Manage remote computer

From: Steven L Umbach (sumbach@ameritech.net)
Date: 03/29/03


From: "Steven L Umbach" <sumbach@ameritech.net>
Date: Sat, 29 Mar 2003 16:28:21 GMT


      I would recommend running netdiag and dcdiag on your domain controller
to see if it is set up properly, especially with regards to dns zone
creation and dns srv records. The dc needs to be pointing to itself, by it's
assinged ip address, as it's primary dns server. The clients need to point
to the dc as their dns server. Run netdiag on the client computers to see if
they are correctly configured. As far as ipsec policy. I recommend that you
assignd the "request" (not require) policy to the domain controllers via
domain controllers group/security policy if you need to include them. Then
assign whatever you require to the rest of the domain computers - usually
client (respond only) to workstations and request/require to servers based
on their security needs. Computers of course will need to be in domain/OU
where policy is implemented. Only W2K/XP computers can implement ipsec, so
if you have any W9X or NT4.0 computers they will not be able to communicate
with any computers requiring ipsec. Use ipsecmon to monitor and
troubleshoot ipsec security associations. If you do implement ipsec on the
domain controllers you may want to create a policy exempting dns traffic to
keep network communications responsive. --- Steve

"Martin" <x@y.z> wrote in message
news:eHQYN4S9CHA.3412@TK2MSFTNGP11.phx.gbl...
> Hi,
>
> I've just setup active direcotry, and added other computers to the new
> domain - maintained backwards compatibility with domains, though I did not
> have a domain before.
>
> From my AD server, I can see the other computers and they can also see
each
> other.
>
> I have defined an ISPec policy that I want all computers in the domain to
> adopt. I defined it in the Domain Security Policy section on my AD
server.
> How do I apply it to the other computers in my domain? Simply doing
assign
> by the new policy doesn't seem to work - though there may be an error in
my
> policy settings.
> Roughly the policy has IP filter source My Address, dest Any IP Address,
All
> protocols, and mirror. I had previously used a similar policy explictly
> setup on two separate computers to secure traffic between the two. Now I
> want to have a policy that is administered from AD.
>
> I believe I don't need to define this policy anway else, but each computer
> in my domain needs to adopt it - how do I make that happen?
>
> I tried to do Computer Management on one of the domain members, from my AD
> server, but although I can browse to it, and the shares fine, I can't do
> Computer Management of it from my AD server. I can see the name when I'm
> asked what computer to manage, but it then says "Computer \\mc1.domain.com
> cannot be managed. The network path was not found."
>
> Help!
>
> Thanks
> Martin
>
>



Relevant Pages

  • Re: No DC in Active Directory
    ... I still show no computers or DCs in AD Computers and Users on Srvr1 and they ... The primary DC points to itself as the DNS. ... The second server ... the first server now shows no DCs in the Active Directory ...
    (microsoft.public.windows.server.active_directory)
  • Re: Client computer internet connection problems
    ... subnet, Default Gateway, correct DNS entry/ies). ... his TCP/IP Configuration settings then he is not going to be able to join ... O*N*L*Y the internal DNS Server IP Address..... ... join the computers to my server domain. ...
    (microsoft.public.windows.server.sbs)
  • Re: Sharing a drive on my computer with others
    ... SBS 2003 needs to manage DNS and really likes to manage DHCP, ... You need to use the wizards on the SBS server to get it all working properly. ... I can't ping any of the computers within the domain. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Replacing Win2000 Domain controllers
    ... Normally you can rename a computer in the domain without any problem, maybe the account did not have the correct rights in AD. ... If you remove it give time for replication and also check that all entries from the DNS management console are deleted and also from the DNS zone properties under the Name server tabs, if it was a DNS server. ... I've tried renaming computers in the domain before and ...
    (microsoft.public.windows.server.migration)
  • Re: Error adding computers to domain
    ... > add Windows 2000 computers to a domain. ... > all because that function isn't necessary on that server. ... While not required by the server, the clients would certainly see a benefit. ... ever use an ISP's DNS server. ...
    (microsoft.public.win2000.advanced_server)