Linux Netfilter discussions
 help / color / mirror / Atom feed
* Re: MS Windows domain logon via netfilter NAT
       [not found] <3CDEA665.5040605@ufl.edu>
@ 2002-05-12 18:30 ` Joerg Mayer
  2002-05-13  3:41 ` Iced Tea
  1 sibling, 0 replies; 2+ messages in thread
From: Joerg Mayer @ 2002-05-12 18:30 UTC (permalink / raw)
  To: Kramer; +Cc: netfilter

On Sun, May 12, 2002 at 01:29:09PM -0400, Kramer wrote:
> Windows client hosts on the NATed LAN can't find the NT4 Domain for 
> logon.  Therefore Network Neighborhood browsing doesn't work.  Strangely 
> direct UNC connections will work if logon credentials are not required.

In normal IP networks running windows, the DC is found via the WINS service.
WINS is the pre win2k version of DNS. WINS is used to map host- and service-
names to IP-addresses. AFAIK, there is currently no support for WINS in
iptables/netfilter, thus the answer your win client gets back points to
the not-NATed address, which is unreachable. By directly specifying the
machine you work around that problem (you manually to what the wins service
would have done otherwise).

  ciao
        Jörg

--
Joerg Mayer                                          <jmayer@loplof.de>
I found out that "pro" means "instead of" (as in proconsul). Now I know
what proactive means.



^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: MS Windows domain logon via netfilter NAT
       [not found] <3CDEA665.5040605@ufl.edu>
  2002-05-12 18:30 ` MS Windows domain logon via netfilter NAT Joerg Mayer
@ 2002-05-13  3:41 ` Iced Tea
  1 sibling, 0 replies; 2+ messages in thread
From: Iced Tea @ 2002-05-13  3:41 UTC (permalink / raw)
  To: Kramer; +Cc: netfilter


----- Original Message -----
From: "Kramer" <kramer@ufl.edu>
To: <netfilter@lists.samba.org>
Sent: Sunday, May 12, 2002 7:29 PM
Subject: MS Windows domain logon via netfilter NAT


> I have gotten a RedHat 7.3 box operating as a router/filter to a private
> (192.168.132.0/24) with dhcp without too much trouble.  One major
> problem remains that I can't find any info on.  The fixes for the NAT
> public address reverse routing and the broadcast address fixes are
> already applied.
>
> Windows client hosts on the NATed LAN can't find the NT4 Domain for
> logon.  Therefore Network Neighborhood browsing doesn't work.  Strangely
> direct UNC connections will work if logon credentials are not required.
>
> I am sure I am not the first to run into this.  Can anyone help?
>
> Jack Kramer
> University of Florida
> Fort Lauderdale

Windows usually build its browselist via broadcasting.
If the clients are not on the same network they need a domain master in each
network that knows the other network. That cannot work if the domains are
the same.
Then set up fine routing and start a wins server a machine, and all other
machines have to use wins.
works fine here, im'm migrating a network to an other ip range without
interrupting client users ...

bye

    Iced_tea



^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2002-05-13  3:41 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] <3CDEA665.5040605@ufl.edu>
2002-05-12 18:30 ` MS Windows domain logon via netfilter NAT Joerg Mayer
2002-05-13  3:41 ` Iced Tea

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox