Question

DFS share works fine over site-to-site link but not VPN

Asked by: doowell

I have DFS working fine between two Win2K3 SP2 servers connected with a permanent site-to-site link.
But over a VPN from a WinXP SP3 machine in another location I can't connect to any share in the DFS namespace.
The VPN works fine in all other respects i.e. I can access the individual shares on the servers, just not the name space share.

This is the error message from Windows Explorer
"The drive could not be mapped because no network was found."

Client - WinXP SP3
Server - Win2K3 SP2

Note - I am not a hugely experienced sysadmin and fell into doing it for our family business, so go easy on the heavy stuff.  I have no issue understanding this stuff, but I might need a bit of a "noddy" explanation.

Cheers.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-06-18 at 17:04:53ID24504437
Tags

VPN

,

DFS

,

Networking

Topics

Virtual Private Networking (VPN)

,

Windows 2003 Server

,

Network Operations

Participating Experts
2
Points
500
Comments
20

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. DFS Issue
    My inherited network: VPN Connection over T1 lines. Win2k Server at one location and Win2k3 server at the other both domain controllers on the same domain. Replication works fine but my problem is the workstations seem to connect to the remote server's dfs and not the one ...
  2. Access DFS Namespace via VPN
    I have two servers, in two sites, each with a shared directory. I have setup DFS Namespace with the two directories, within the office, I can map to this just fine. Over my VPN connection, I can map to the DFS share, but then clicking on the folder gives the message "sh...
  3. Access DFS share from VPN
    I currently have DFS setup in my Windows 2003 Domain. I can access the share \\domain\internal\share with no problems in the corporate LAN. When I go home and attempt to access the DFS share via, VPN, it failes to connect. Is it even possible to access a DFS share over a v...
  4. DFS and VPN
    We have just setup DFS on our network in Windows Server 2008. Users have the share mapped as \\domain\files which they have no problem accessing those files while on the network. However, when those users try to access them through the VPN they cannot with that path. Any idea...
  5. Unable to connect to DFS Namespaces with Small Business…
    Hi Folks, We have a perfectly functioning and replicating namespace that is accessible fine from inside the network and all sites. We have three sites. Head office with a SBS2003R2 Box and a W2K3R2 Box (Namespace server1) Site 2 with a W2K3R2 Box (Namespace server2) and s...
  6. Add DFS replication folders to new domain-based name n…
    We have two Windows 2008 servers synchronizing over VPN through DFS. Currently these two computers are using stand-alone namespaces and we need them to use the domain-based namespace. Is there any way to convert these two replicated folders to domain-based namespace withou...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: rockadoodooagainPosted on 2009-06-18 at 17:55:01ID: 24663068

On the routers hosting the VPN link, make sure NetBIOS is allowed to forward on Both ends.  Sometimes it's called Windows Networking, SMB or TCP Port 137.  This protocol is used to keep track of shares.  See http://support.microsoft.com/kb/204279.  You will also need ports UDP 138, TCP 445, TCP 135, and possibly both TCP and UDP 389 allowed on both ends.  See System Service Name DFS at http://www.microsoft.com/smallbusiness/support/articles/ref_net_ports_ms_prod.mspx


 

by: doowellPosted on 2009-06-19 at 00:56:58ID: 24664486

rockadoodooagain

Thanks for that - very comprehensive!  I'll figure out how to act on your advice over the next day or so.

 

by: doowellPosted on 2009-06-22 at 05:59:31ID: 24681917

Going a bit slow on this - jammed with a zillion competing demands.

Haven't forgotten and will check it in the coming days.

Cheers.

 

by: doowellPosted on 2009-06-25 at 19:09:32ID: 24717570

So far have confirmed that NetBIOS is being forwarded.
What's weird is that nslookup on the namespace root of DFS gives the right IP addresses but pinging fails.
ie. nslookup \\dfs.local returns the IP addresses of all servers included in our DFS scheme.
I can ping the remote machines themselves but ping \\dfs.local fails

I tried adding an entry to the "hosts" file on the client machine, hard-coding dfs.local to a particular server but even here I can't ping the UNC name.

Still a bit of a newbie at all this and our third-party sysadmin remains as confused as we are.  Still thinking about this so sorry for slow pace of replies.

 

by: ChiefITPosted on 2009-06-28 at 22:59:49ID: 24733882

Netbios broadcasts are not routeable, you need wins to support netbios over a VPN tunnel.

This includes Netbios over SMB and netbios over TCP. That's both methods used to send Browser list and DFS shares.

Another option is to allow Site to Site replication of your DFS shares. Replication services, (FRS or DFSR) will replicate using DNS. DNS is a routeable protocol and will propogate over a VPN connection. This is why you can ping computers via host name but not computer name.

 

by: doowellPosted on 2009-06-29 at 05:47:12ID: 24735612

Hi ChiefIT

Thanks for the response.  It's going to take me a while to understand it!

 

by: ChiefITPosted on 2009-06-29 at 08:57:28ID: 24737368

Well, let's get you fixed, then I will answer any questions you have on DFS from site to site:

To fix you, I need to ask a few questions so I am not assuming things:

1) Do you have a Domain Controller at each site, or are you trying to get DFS shares directly from your main site? If you have DCs at each site, are both global catalog servers and are you showing signs of replication problems?

2) Do you have WINS set up?

3) How many computers at your remote site?

4) Is this for group Sysvol/Netlogon shares or some other network share?

 

by: doowellPosted on 2009-06-29 at 09:02:50ID: 24737424

Excellent.  Much appreciated.

1. Domain Controller is at head office.  I'm trying to connect from a branch office that does not currently have a Domain Controller.  In due course there will be a Domain Controller at the branch office too, but that's only once this simpler set up is working.

2. I don't really understand what WINS is yet so don't know/not sure.  I'll check into this.  To be honest I hve not yet grasped the difference between DNS, WINS, NetBIOS, UNC.  They all seem to do the different versions of the same thing!

3. Remote site has just one PC behind a Netgear firewall.  Nothing complicated.  I connect to head office using the IPSec VPN built into Windows Server 2003 E2.

4. The share in question is a folder of company-wide documents.  So for end-users not sysadmins or technies.

 

by: doowellPosted on 2009-06-29 at 09:16:12ID: 24737523

Sorry just realised I didn't answer 4 properly, so....

4. it does happen to be the same DFS namespace \\mybiz.local as for Netlogon.  We are adding shares to the same namespace for other purposes.

 

by: ChiefITPosted on 2009-06-29 at 10:22:34ID: 24738136

One computer, huh?

This is a pretty easy fix. But, you are going to have to remember we did this. It will interfere with WINS in the future.

First, let's straighten out a little confusion:

UNC path stands for Universal Naming Convention path. It can use multiple protocols to do the same thing.

example:
\\servername\share (uses the netbios name to map to a share)

\\servername.domain.name\share (uses the fully qualified domain name, (also refered to as the host name), of the share)

\\xxx.xxx.xxx.xxx\share (uses the IP to map the share, also known as ARP (address resolution protocol))

It's called Universal because of its compatibility to use either netbios, DNS or IP to map to a share.
___________________________________________________________________

DNS is simply like a phone book that uses the fully qualified domain name, (also commonly referred to as a host name). This phone book changes the host name to an IP and visa versa. Also included in this phone book are SRV records and a bunch of other records that specifically point the way to your domain controllers, mail servers, ect... So, it is like the yellow pages and government pages in your phone book.

For more information on about DNS, I wrote an article about it with links to different types of DNS records and how a DNS query is propogated over the network. Read this at your leisure. For now it is not important to fixing your problem.
http://www.experts-exchange.com/articles/Networking/Protocols/DNS/DNS-Troubleshooting-made-easy.html

___________________________________________________________________

WINS is another form of phone book. It converts the netbios name, also referred to as the computername or LMHOST name (lan manager host name)) to an IP address and visa versa.
WINS was suppose to be replaced by DNS, However the netbios broadcasts were pretty usefull.

When logging onto a computer with netbios enabled, it will send out a broadcast message that basically says "I am here" and "this is my OS". All nodes on the LAN will pick this up and use this information to determine the site's master browser. If this master browser is a Domain controller, it will be elected a Domain master browser, by default.

However, without WINS, the local broadcasts only stay within the local SITE. WINS is another phone book that will share, between sites, its phone list.

By default, WINS is not enabled. You have to manually install it and configure it, much like you have to install DNS and enable it on a domain computer.

File and printer sharing as well as the browselist, (that populates the list of computers in "My Network Places" is used by netbios broadcasts. It does this by two simultaneous ways:

1) Netbios over TCP/IP
and
2) Netbios over SMB



AND HERE IS YOUR PROBLEM:

Since you don't have a WINS server configured, your netbios broadcasts are not reaching remote site computer. It would be equal but not related to not having a DNS server phone book that provides the IP to your host name. In other words, you don't have the phone book that provides an IP to your computer name.

HERE IS YOUR FIX for this ONE computer:
With only one computer at the remote site, you can create an LMHOST record between your Domain server and your remote comptuer and enable LMHOST lookup on both the DC and the remote computer on the NIC configuration>>TCP/IP properties>>WINS tab.

That LMhost record can be found on both machines at:
C:\Windows\system32\drivers\ect\LMHost
You can edit that file using NOTEPAD or WORDPAD.

Add both your domain server and your remote computer on both machines.

HERE IS YOUR FIX WHEN YOU GET A REMOTE DC:
Make the DC a global catalog server and use DNS to REPLICATE your DFS shares from one site to the other. Replication doesn't need netbios or use WINS, it uses DNS.

DNS and IP mapping of DFS shares are routeable, while netbios mapping is not.


 

by: doowellPosted on 2009-06-29 at 10:47:36ID: 24738366

Wow!  Thanks for that!  Let me digest it and get back to you.

 

by: doowellPosted on 2009-06-29 at 12:34:38ID: 24739388

Hi ChiefIT

I tried adding the following to the LMHosts.sam file on both machines

192.168.1.199    <<our domain>>.local
192.168.1.199    <<primary domain controller>>
192.168.40.4     <<machine in branch office>>

Is that correct?

If so when I try to ping \\<<our domain>>.local I get
"Ping request could not find host \\<<our domain>>.local. Please check the name and try again."

The ping request did however work without the leading double back-slash i.e. ping <<our domain>>.local

And obviously I have substituted the real machine and domain names instead of the dummies here in the angle-brackets.

Should I restart the VPN connection once I've edited the files maybe?

 

by: ChiefITPosted on 2009-06-29 at 12:41:21ID: 24739447

Unlike HOST files, you will want to use the computer name, (also recognized as the LMHOST name).

Don't use the Fully qualified domain name.

This should guide you through the LMHOST file edits:
http://technet.microsoft.com/en-us/library/cc977235.aspx

Furthermore:
File and print sharing needs to be enabled on both server and remote computer

Then, make sure Netbios over TCP/IP is enabled on the NIC, (NOT netbios over DHCP).

and make sure LMHOST lookup is enabled on the WINS tab of both server and remote computer's nics.

Once done, go to the command of the client and type:
NBTSTAT -RR

 

by: doowellPosted on 2009-06-29 at 12:44:16ID: 24739476

This is pushing my understanding, so I'll let you know I get on.

Thanks a million so far anyway.

 

by: doowellPosted on 2009-08-02 at 16:09:15ID: 25001024

Hi all
Thanks so much for your responses.  I've been swamped with other issues and have not forgotten this.  Having trouble coordinating with our third-party support people - no criticism of them, just too much to do.
I will definitely get around to this - also this topic is rather beyond my powers so I'm struggling a bit.
Cheers for your patience.  I'll be giving points to all who helped.

 

by: doowellPosted on 2009-08-03 at 16:49:30ID: 25009485

Further update on this.  We're actively considering implementing a new site-to-site link instead of a VPN.  That would make this query go away.  To that extent, I'm unable to close this query until the decision is made.  Sorry for that.

 

by: doowellPosted on 2009-08-07 at 02:31:12ID: 25041075

Hi all,
OK, we've gone for the new site-to-site link which will dispense with this issue as we already use it elsewhere in our WAN setup.
Does anyone have any suggestions as to how I should award points?
I want to thank all who contributed.
Matt

 

by: ChiefITPosted on 2009-08-11 at 10:01:01ID: 25071076

The site-to-site should resolve your problems, only if it is not on different subnets. Remember Netbios will not go through to different subnets because it is not routeable.

If the site-to-site connection works for you, You might accept that as your acceptable answer. Points on EE are just 1's and 0's on a computer somewhere to me. I like seeing EE database full of correct answers.

 

by: doowellPosted on 2009-08-11 at 10:20:34ID: 31594211

A bit overwhelming on the technical knowledge required (I spent ages looking stuff up), but a very impressive line-up of advice.  I'd rather be pushed by an answer than not, as then it's an opportunity to learn.
Thanks to all who contributed.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...