?
Solved

Windows Server 2008 client gets security error in Win 7 Pro

Posted on 2013-12-13
10
Medium Priority
?
341 Views
Last Modified: 2014-02-01
I have a client with a new laptop who logs into a new Windows Server 2008 R2 domain, with redirected Documents folder.  When she took her laptop home, she turned it on, and without getting onto LAN or wireless, her documents folder was empty, consisting only of the Public folder.

At her office, I dropped in, and connected her to the office wireless, and without logging off/on, browsed to the server and was prompted for user name and password. In that box was the message:

The system has detected a possible attempt to compromise security.  Please ensure that you can contact the server that authenticated you."

The DNS settings for the LAN and wireless are set to automatic, and while connected to the LAN, she seems to be fine.

I thought that the system should give her connection to her documents even if she is connected to *no* network.

Microsoft says, "To resolve this problem, configure the network firewall so that TCP port 88 and UDP port 88 are not blocked for either domain."  I assume this is a change for the laptop's firewall?  Or is it the server's?

I need help. Thanks.
Dave
0
Comment
Question by:DaveWWW
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 3
10 Comments
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39717330
This would refer to the laptop's firewall.
http://support.microsoft.com/kb/938457

I have also seen issues like this when the default gateway is not configured properly.

Will.
0
 

Author Comment

by:DaveWWW
ID: 39717419
There are three laptops, all configured the same, seemingly.  Only this one has an issue.  I have added the ports to the firewall.  No difference.
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39717435
Check the event viewer on the users machine for Event ID 6 as it could very well be related to token size. The below link will provide sets to correct this...

http://technet.microsoft.com/en-us/library/dd348689%28WS.10%29.aspx

Will.
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 

Author Comment

by:DaveWWW
ID: 39732436
The only ID 6 I have relates to the fingerprint sensor.  I'm remoted in with the client right now. When I log on, the documents folder has only the public folder.  I have Hamachi on this laptop as well.  Same result if the Hamachi program is shut off.

I'm at my wits end.
0
 

Author Comment

by:DaveWWW
ID: 39732447
I should mention that the domain controller is not on a static IP.  I'm assuming this is irrelevant as I would have assumed that no syncing would take place until the laptop is back on the DC network?
0
 

Author Comment

by:DaveWWW
ID: 39732581
I'm now wondering if this is all as simple as the fact that I need to add the Documents folder to the sync set in "Sync Center" in Control Panel?
0
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39732599
I would definitly change the DC to static. Think about it that means your DNS server/s IP is changing. If your clients are not flushing the DNS entries it might be looking for DNS query's at the cached IP address. If that changes and the clients to update their cache then this creates a huge issues.

Change that IP to static on the DC's.

Will.
0
 

Author Comment

by:DaveWWW
ID: 39732685
Sorry, I meant the router's WAN address is dynamic. The server *definitely* has a static internal IP :-)
0
 

Accepted Solution

by:
DaveWWW earned 0 total points
ID: 39757868
It turns out that the user removed her laptop from the domain before an initial sync was accomplished.  I suspect this is the source of at least some of the problems.  I'll post back once I have the laptop on site again.

Dave
0
 

Author Closing Comment

by:DaveWWW
ID: 39826074
The sync issues resulted because an initial sync was not completed.
0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Suggested Courses
Course of the Month9 days, 21 hours left to enroll

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question