Solved

Cant access admin shares on a windows7 machine on a domain when the firewall in enabled as a domain admin

Posted on 2011-09-13
9
569 Views
Last Modified: 2012-05-12
Hi , I am a domain admin on our network. On all windows 7 machines with the firewall turned on and file and print share enabled I still cant access admin shares on remore pc's. I am a domain admin and have no problem accessing any win xp or server2003 or server2008 machine admin shares. If i turn off the firewall I can access the admin shares on the win7 machine. I tried enabling the firewall and allowing all programs through and still wont work.
0
Comment
Question by:mestek
  • 4
  • 4
9 Comments
 
LVL 5

Expert Comment

by:ErikCamacho
ID: 36531166
Im guessing you want to keep your firewall on...
So here is a link on how to cofnigure some rules

http://technet.microsoft.com/en-us/library/dd448559(WS.10).aspx
0
 
LVL 38

Expert Comment

by:ChiefIT
ID: 36531773
Go into the firewall properties and make an exception to "File and Print Sharing"
0
 

Author Comment

by:mestek
ID: 36531940
Already did.. I posted that in the body. Thanks though.
0
NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

 
LVL 38

Expert Comment

by:ChiefIT
ID: 36535282
As in your post:

So, even if you have file and print sharing enabled, and you turn the firewall on, it doesn't work??>>But, with the firewall off, it does work??

Still sounds like a firewall setting, don't you think?

------------------------------------
Background information:
File and print sharing is performed using netbios broadcasts. These broadcasts are held to the broadcast domain. This means the broadcasts will not go through a VPN tunnel, across a NAT router, to separate VLANS, ect... If everything is on the same broadcast domain, they are not "remote" computers. They are local to the same subnet. This sounds like the case for you.

Since the firewall seems to be the issue, let's discuss the software firewall's function. A system state firewall is defined as a firewall that blocks certain traffic, IF the communications were not started by the host. This means any UDP traffic to this host will be blocked. Any requests from the host should work. So, you will not be able to see computers in my network places, nor will file and print sharing because much of the traffic is broadcasted traffic and most firewalls block netbios broadcasts. The hosts that are not seeing other computers on the network possibly have a firewall blocking them.

Then, there is the specific features of WIN 7. Navigate to: Control Pannel>>Network and Sharing Center>> "Change Advanced Sharing Settings. There you will see a list of settings to control file and print sharing as well as network discovery. This is how Netbios is minipulated for WIN 7 computers IN ADDITION to firewall settings you have seen in XP 'puters.

_____\
With that said, if you truly have a remote comptuer, (meaning computers not on the same subnet or not on the same broadcast domain), let me know. There are ways to get this to work.
0
 

Author Comment

by:mestek
ID: 36536242
Im sorry , I used the term "remote" losely.. The computers are indeed on the same subnet.
0
 
LVL 38

Expert Comment

by:ChiefIT
ID: 36591931
We are not on the same sheet of music:

When you disable the firewall, it works. When enabled, it doesn't. This is a firewall setting to allow file and print sharing. Also see if IPsec is enabled. You can see this by going to the command prompt and typing, IPconfig /all
0
 

Accepted Solution

by:
mestek earned 0 total points
ID: 36599324
Turns out that there was a group policy applied to Privledge Authority that was disabling .. file and print sharing..
0
 

Author Closing Comment

by:mestek
ID: 36895830
Talked with the network engine who went through all policies and found the policy over riding the file and print sharing.
0
 
LVL 38

Expert Comment

by:ChiefIT
ID: 36601479
OOPS.... Glad to see it resolved.
0

Featured Post

Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Resolve DNS query failed errors for Exchange
An article on effective troubleshooting
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question