Solved

Samba , windows xp and restricting access from outside

Posted on 2003-11-04
5
2,401 Views
Last Modified: 2013-12-23
I have a workgroup named "simoyigrp" which has about 10 computers in it in my office.
 The problem i m having is that the "workgroup" is all open from anywhere. If I go to a different lab in my school and go to netwok places and select entrire n/w and then microsoft network i can see my workgroup from outside.
What I want to do is only the computers in the current workgroup should be able to interact with each other and nobody else other than the workgroup should be able to visit any of my shares in the workgroup from outside.
so I was told that i should set up a domain. I did set one domain as "simoyigrp" with samba as the PDC. I join the domain but still all my files are accessible from outside.
What I wanna have is like a circular wall surrounding all my PCs in the domain/workgroup and nobody else should be able to see any of my machines or shouldnt be able to access any of the files from outside the wall
let me know how should I go about it ? do i have to make any changes in the smb.conf. I have security = domain encrypted passd=yes, domain logons = yes ? anything else?
0
Comment
Question by:vikrantp
  • 2
5 Comments
 
LVL 40

Expert Comment

by:jlevie
ID: 9683568
How secure do you really want this group of machines? If all shares are limited to authenticated users and those accounts only exist on the workgroup machines they might be visible to other systems on that network segment but only users with accounts on the workgroup systems will actually be able to access the content of the shares. However, if you need more security beyond that you should consider placing all of the machines in this workgroup on a separate network protected from the rest of the network by a firewall.
0
 

Author Comment

by:vikrantp
ID: 9688758
thx for the reply.
the first case you which u talked about is fine as far as the security is concerned. but currently all my shares can be seen from outside of the workgroup without authentication. Ofcourse I havent given the write permission for the shares but I want to do tht later on. so how do I change it so that anyone who is accessing the particular share on any of the machines in the
WORKGROUP will be prompted with a password and if its an aunthenticated user then only the share will be available
so setting samba as the PDC for these machine and making changes to the security settings of smb.conf is not the solution?
let me know
0
 
LVL 40

Accepted Solution

by:
jlevie earned 20 total points
ID: 9689236
You didn't say what windows version you are running on the workgroup machines, but I'll assume it is NT or better that understands multi-user access. The first step is to create an account on each of the workgroup machines for each of the valid users. Then when you share out a folder you change the permissions to only allow those users within the worgroup access to the share.
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When it comes to security, there are always trade-offs between security and convenience/ease of administration. This article examines some of the main pros and cons of using key authentication vs password authentication for hosting an SFTP server.
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question