Solved

Cannot access domain resources from laptop, although VPN functioning

Posted on 2010-11-21
19
600 Views
Last Modified: 2012-05-10
I have a new user on our domain. Computer is part of domain computers. User part of domain users. All remote access has been granted. VPN connects successfully. Email works. Network printers connect successfully. However, cannot connect to shared folders on server. I have reviewed all sharing and permissions on share to make sure there's no explicit denials. She is part of a group that is granted read/write to everything. In some cases even gave her explicit full control. Still can't access network shares. Not sure what I'm missing. Usually when I add a new user the wizard does all this for me and things are fine.
0
Comment
Question by:ArcJC
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 5
  • 4
  • +2
19 Comments
 
LVL 15

Expert Comment

by:getzjd
ID: 34184103
Are you trying to access the network shares via unc name or IP?   Can she ping by name and IP both?
0
 

Author Comment

by:ArcJC
ID: 34185209
we use the sbs vpn to access network resource, and then we just type in directory names in windows explorer. for example: \\fileserver\common. However, when this fails, I can usually browse to network in win explorer, but this user can not traverse domain at all. I can ping by both name and IP. but I cannot traverse in explorer.
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 34185361
What about "\\FileServer'sIP\Common", or "\\FQDN of FileServer\Common"
0
Revamp Your Training Process

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action.

 
LVL 4

Expert Comment

by:m203hcon
ID: 34186259
see that when you use the vnp see in ipconfig /all that your dns servers are your windows domain dns servers if not you need to change the ipsetup so that they use the dns
rgds
0
 

Expert Comment

by:faolchu
ID: 34187162
i find on our VPN that we need to use IP not host name to connect to resources
0
 
LVL 4

Expert Comment

by:m203hcon
ID: 34187252
dns problem your dns server should be the dns server of you can set is under properties of vpn  network internet-protocol properties dns and give by hand the dns of your domain probably your domain controller
0
 
LVL 4

Expert Comment

by:m203hcon
ID: 34187261
dns problem
your dns server should be the dns server of your domain
you can set this
network
 under properties of vpn  network internet-protocol properties dns and give by hand the dns of your domain probably your domain controller
0
 

Author Comment

by:ArcJC
ID: 34190214
I have checked my dns server under IPconfig \all. It is configured correctly, both with and without the VPN in place.

Is there any chance I've done something wrong with shareing and permissions or have somehow denied her? The computer is part of the domain. I gave the user explicit permissions to multiple folders, but I can't get to any of them. How would I check whether the share persmissions are correct or not?
0
 
LVL 15

Expert Comment

by:getzjd
ID: 34190245
You have verified both the NTFS permissions and the actual share permissions?
0
 

Author Comment

by:ArcJC
ID: 34190469
getzjd: I don't know. I went to the server, browsed to the folders in explorer and right clicked on each folder, explicitly giving her full control on both security and sharing. I then also went to the SBS management console where the shares are listed and specifically created a share for her. Later, when I got confused about the difference between these two sharing settings, I deleted the share from the SBS management console. Do I need to add it back in?

See, my own folders are shared for all to see, but I don't have a separate share set up in the mgmt console, so I thought maybe that part wasn't necessary.
0
 
LVL 15

Expert Comment

by:getzjd
ID: 34190613
Open up explorer, right click on the shared folder, click on properties, click on the sharing tab and check permissions.   Then click on the security tab and verify permissions
0
 

Author Comment

by:ArcJC
ID: 34190627
I just reconfirmed permissions all around. The effective permissions tab shows her having access to all of the relevant directories. Are there permissions at the computer level that I need to be looking at?

It's not DNS. She and her computer are part of the domain.

0
 
LVL 15

Expert Comment

by:getzjd
ID: 34190683
Can she access this share from on the network or on a different computer?  
0
 

Author Comment

by:ArcJC
ID: 34191706
It seems to be that computer itself. Works from both other desktops and laptops. What could be on the computer that would cause this?
0
 
LVL 15

Accepted Solution

by:
getzjd earned 500 total points
ID: 34192621
Have you tried bringing the computer in to the office, removing it from the domain and rejoining it?
0
 

Author Comment

by:ArcJC
ID: 34192634
No, but I will do that tomorrow.
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 34193737
Offline Files in play as well?
0
 
LVL 4

Expert Comment

by:m203hcon
ID: 34195545
can you ping on the name of your server ?
do you see your domain on explore network ? (in the explorer)
is your computer registered in domain (users and computers) ?
try disabling your firewall
0
 

Author Closing Comment

by:ArcJC
ID: 34258465
Thank you for your help, getzjd. In the end, I did nothing additional, but the next time we used it in the office (with no intervention or tweaking), it worked find. Thanks for confirming and walking me through the possible issues.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article outlines the process to identify and resolve account lockout in an Active Directory environment.
A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question