Re: I need a method a way to ONLY allow computers in domain to login

From: Herb Martin (news_at_LearnQuick.com)
Date: 08/11/03


Date: Mon, 11 Aug 2003 12:50:05 -0500


Hmmm, that doesn't jibe with my experience or the general
documentation. DCs connect just fine and the clients do to.

If you run into that KB, please post it or send me the #.

As long as both are at least Request (or Require).

The problems I have seen are timeouts by the time a
client has to "respond" client, find out about the Require,
negotiates IPSec, then re-submits the original request.



Relevant Pages

  • Re: PINGing the Active Directory Domain
    ... If no DC are in that AD Site, the DCs in the nearest AD site will cover that AD site by registering their records in the DC-less AD site. ... If a client does not know in what site it is in it will ask for a DC in that same domain by querying DNS with: ... By default all DCs in AD domain will register that DNS SRV record. ... It can be really annoying when some client in branch office X is authenticating to a DC in branch office Y, while then WAN links between both branch offices and the datacenter are not that fast. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Calling David Copeland regarding .local convention
    ... the clients who are least willing to pay for documentation ... > the first consultant should've been nailed for not documenting their work. ... If I was told this by the client I'd ... > People have a tendency to blame others before blaming themselves - that's ...
    (microsoft.public.windows.server.sbs)
  • RE: Re: pentest documentation
    ... Also with this type of documentation make sure that the client has given ... capture the output of any scanning tools you use. ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • Re: Calling David Copeland regarding .local convention
    ... He's going to learn the hard way, or hopefully hire a new consultant. ... If I was told this by the client I'd no ... documentation I wrote demonstrating that I'm not an idiot. ... GOD BLESS AMER, er, THE INTERNET. ...
    (microsoft.public.windows.server.sbs)
  • Re: DC replacement
    ... Yes there are two DCs and we only need to replace one. ... that server will error instead of just finding the other DC. ... Even under NT the client ... [phone number on web site] ...
    (microsoft.public.windows.server.active_directory)