Re: Restrict access to Share to combination of User + Computer



"Hans Hinnekint" <hans.hinnekint@xxxxxxxxx> wrote in message
news:0DB1E758-62ED-4163-8F91-F191EE609C4D@xxxxxxxxxxxxxxxx
Hello,

I would like to restrict the access to some shares to a combination of
User + Computer, so that this share can only be accessed when the user
logs in on a specific set of computers.

I have static VLANs in place.

What is the best way to handle this?
- EFS
- IPSEC server/computer isolation
- NAP

Any help would be appreciated,

Hans Hinnekint

Hi Hans,

There is no direct way to meet those requirements.

If however you can say that all resources on the sharing machine
should only be accessed from a specific set of machines, then one
can use IPsec to enforce the access only "from these computers"
part and use NTFS/share-level permissions to enforce the access
only "by these users" part. Also, if you want to it is possible to
loosen the "all resources on the sharing machine" by having the
IPsec rules govern only the ports needed for filesharing, leaving
other accesses open to more machines.

I have seen a number of people attempt to meet reqs of your
scenario and the above is about as close as you can get with
the current off-the-shelf Windows.

Roger



.



Relevant Pages

  • Re: Isolate systems
    ... If you have access to the firewall, you might be able to configure what IP ... filtering policy on your computers which is a policy that uses rules with ... Ipsec policies are best when trying to configure for a subnet ... network layout you may be able to implement ...
    (microsoft.public.win2000.security)
  • Re: Isolate systems
    ... You also may want to download the " Securing Windows 2000 Server Security ... to use ipsec "filtering" policies to secure domain controllers and other ... >> filtering policy on your computers which is a policy that uses rules with ...
    (microsoft.public.win2000.security)
  • Re: Green Admin - Brute Force Attack - Pls Help
    ... Ipsec configuration is very similar [if ... specifics on how to use ipsec "filtering" policy to protect computers. ... is managing a network - particularly one in a hostile environment. ...
    (microsoft.public.security)
  • Re: Preventing PCs from accessing the network
    ... Ipsec policies can be used to prevent non domain computers from accessing domain ... resources if the resource computer has a "ipsec require" policy. ... or port isolation. ...
    (microsoft.public.win2000.networking)
  • Re: Prevent logon without certificate
    ... "Mark Gamache" wrote in message ... You can't really use IPSec between ... >> computers to domain, but if you change the policy only domain ... We're messing about with certificate services on a test windows 2003 ...
    (microsoft.public.windows.server.security)