Windows Server 2008 R2 Cross-Domain File Sharing Not Working

Posted on 2010-04-07
Medium Priority
Last Modified: 2012-05-09
Odd problem with sharing across two Domains in a single Forest.

Domain controller DC1 is in Domain1. Domain controller DC2 is in Domain2. Both domains are separate trees in the same Forest. Both DC's are Windows 2008 R2.

No problem with browsing for users and groups across domains and assigning the relevant permissions to shares and folders. No evidence of replication or other AD issues.

Permissions on shares and folders are definitely correct.

We can browse to System shares across domains. Eg browse to \\dc1\sysvol or \\dc1\c$ from DC2 (or another machine on Domain2) works as expected. (Using FQDN, just shortened here for easier typing).

Browsing to \\dc1\myshare from DC2 or another machine on Domain2 brings up a "path not found" error. Actual error varies depending on OS but they are similar. Shares work as expected within Domain1.

Server1 is a member server (Windows 2008) on Domain1. No problem browshing to shares on Server1 from Domain2.

The same problem occurs in reverse - ie accessing shares on DC2 from Domain1.

We have many other domains set up in a similar way using Server 2008 DC's and have not encountered this problem. The problem seems limited to Server 2008 R2.

I have seen similar issues with SMB shares when operating across WAN with IPSec VPN, but this is across a Gb switch. Servers are on seperate subnets but there is no network security between them. FIrewall on the Windows servers has been disabled.

Any ideas?

Question by:milott
  • 2
  • 2
LVL 21

Expert Comment

ID: 30010975
"path not found" seems like a address resolution issue. Can you ping DC1 server from DC2 using FQDN? If no I would start looking at DNS on DC2 and make sure it knows about DC1.


Author Comment

ID: 30057625
I can ping and even browse system shares like Sysvol and C$. It's not a name resolution issue.
It seems that something in 2008 R2 security policy has changed from previous versions.

Accepted Solution

milott earned 0 total points
ID: 31259116
Had to solve this ourselves. Standard shares resolved itself after a day or so - guessing it was replication issue somewhere but couldnt see any issues.
DFS was a bit trickier. By default it uses NetBIOS names resolution which wasnt working across domains. Forced it to use DNS and all good.
LVL 21

Expert Comment

ID: 31277483
..." DFS was a bit trickier. By default it uses NetBIOS names resolution which wasnt working across domains. Forced it to use DNS and all good."....

I don't really care about the points however I believe my very first comment dealt with address resolution.....


Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Background Information Recently I have fixed file server permission issues for one of my client. The client has 1800 users and one Windows Server 2008 R2 domain joined file server with 12 TB of data, 250+ shared folders and the folder structure i…
A procedure for exporting installed hotfix details of remote computers using powershell
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
Suggested Courses
Course of the Month4 days, 1 hour left to enroll

601 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question