Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


How to get a Canon IR2200i to store documents on a Windows server 2008

Posted on 2009-04-07
Medium Priority
Last Modified: 2013-12-27
Hello everyone,

at our office we have a Canon IR2200i that is supposed to "deliver" scanned documents to a server by storing them on a SMB share. When the share was hosted on Windows server 2003R2, this was merely a matter of disabling SMB signing on the server, since (like so many "professional" copiers) the Canon cannot handle that apparently.

However, since we switched to Windows Server 2008, I cannot get the Canon to store anything on an SMB share, even when I disable SMB signing completely in the domain controllers policy. The copier only produces the less than useful message "FEHLER" ("error").
The error message is displayed immediately after scanning, so a name resolution problem is unlikely (too little delay).

If anyone had an idea either how to make it work or how to get the machine to display a more meaningful error message, it would be greatly appreciated.

The server, in its event log, records a failed logon with the following data (this is for a logon attempt including the domain name, i.e. with a username of "pps\t.test"):
Security ID: NULL SID
Account Name: PPS\T.TEST
Account Domain:

Workstation name: PPS\T.TEST

Especially the reported workstation name sends shivers down my spine. Seems like the copier uses a pretty "free" interpretation of what information to deliver. In its network settings, its name is configured as "canon" btw.

In the unit's address book, I used the following settings to access the server (known to work, tested with Liunx smbclient):
server: \\server-01\Benutzer
Path: \t.test\Dokumente\Scans
User: pps\t.test
Password: ************
The canon has SMB support switched on; TCP/IP networking is configured by DHCP and working.
Question by:MFollwerk
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3

Accepted Solution

jrtec earned 2000 total points
ID: 24092741
Just to check, is this what you have changed and it didn't work?
Microsoft Network Server: Digitally signed communication (always) -> disabled
If so, then try the following also, toghether with the previous setting:
Domain member: Digitally encrypt or sign secure channel data (always) -> disabled

Also you can try
Network security: LAN Manager Authentication level -> Lower the level and test

Dont forget to execute Gpupdate /force or reboot to apply policy each time you change something.

You will not be able to change these setting trough gpedit , local computer policy since it is overrided by the Domain security policy.

On server 2008 one way to get there is the following:
Administrative Tools
Server Manager
Group Policy Manager
Forest: ...
Default Domain Policy
 Computer configuration
   Windows Settings
    Security Settings
     Local Policies
      Security Options
        Microsoft Network Server: Digitally Sign Communications (Always)
            Ï Define This Policy
            Ï Disabled

execute Gpupdate /force or reboot to apply policy

Just to check if the policy is being correctly applied try the following:
Trough gpedit (local computer policy) you will be able to see the options but not change them (greyed out), so I suggest that after the change you cannot scan to the folder check trough gpedit if it is disabled.
If it is not disabled, disable it at the top of the hierarchy. Something may be overriding the setting.

Hope any of this helps

Author Comment

ID: 24094960
Hello jrtec,

thanks for the suggestions. I am currently out of office, but will test them later today and let you know the results.

Author Comment

ID: 24098083
Hello again,
I now had time to test it all out. You are right btw in your assumption that I changed the "domain controllers" policy, not the normal domain policy. I even completely disabled SMB signing (not even optional) - no effect.
I followed your other suggestions and lowered the LAN Manager Authentication Level (down to the lowes possible) and even did a reboot to be absolutely certain that the settings were applied.

No effect, unfortunately. :-(

I checked the event log on the Windows server and it says "unknown user name or wrong password" (or simliar, I have to translate it from German) when it rejects the connect. I have quadruple-checkde username and password of course. You even enter them in cleartext on the Canon, so there is little room for error.

I am on it further.
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!


Assisted Solution

jrtec earned 2000 total points
ID: 24100605
Did you also changed Domain member: Digitally encrypt or sign secure channel data (always) -> disabled?

Did you check trough Run -> gpedit.msc (local computer policy) if the options are disabled, you can't change them trought here (greyed out), but you will be able to see if they disabled?

Did you check if you can access the shared folder on the server from another computer on the network using that username and password?

Here are some other things you can try:
See if you can find the domain field in the machine and and enter the correct domain name. Ex: company.local
That will be appended to the username for authentication.
Or if you don't have the domain field in the machine input the username like Ex: user@company.local


Expert Comment

ID: 24100649
Sorry, Forget this question since have already tested.
Did you check if you can access the shared folder on the server from another computer on the network using that username and password?

Author Comment

ID: 24108371
Yes, I did check that. Other Windows- and Linux-systems can access the folder fine using the same credentials. I'll try the hint about the username and domain name after the holiday (which is friday and monday here in Germany) and let you know the results. Thanks for your help so far. Your input is much appreciated.

Author Comment

ID: 24213288
just to let you know, after lots of debugging and browsing logs, I have given up on this. It turned out that the copier sends completely wring credentials (i.e. user name where domain name should be etc). While Windows Server 2003 apparently gets along with this, neither Linux Samba servers nor windows Server 2008 do. I consider this machine broken by design.
I nevertheless accept your solution, jrtec, because in my experience it works for many other machines and is nicely put together.

Author Closing Comment

ID: 31567401
It didn't work in the end, but the suggested measures work for many other machines. The Canon is most definitely bugged beyond hope.

Featured Post

Nothing ever in the clear!

This technical paper will help you implement VMware’s VM encryption as well as implement Veeam encryption which together will achieve the nothing ever in the clear goal. If a bad guy steals VMs, backups or traffic they get nothing.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
A safe way to clean winsxs folder from your windows server 2008 R2 editions
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question