Question
November 21, 2007 at 08:21 AM
techrepublic.com.com

Domain admin cannot map drive to client’s c$ or browse it via Win Explorer.

by techrepublic.com.com . Updated 18 years, 9 months ago

Dear all,

I wonder if someone can please help, the problem is as above, here are some details.

Background: The network is smallish and all Win XP SP2 PCs, one file server (Win2003 NOT a DC) and a network printer are getting their IP addresses dynamically from a 3COM ADSL switch/router (192.168.1.1) with DHCP server enabled, everyone is connecting to the file share on the W2K3 server and is printing happily on the network printer. Every PC/server is on a the same workgroup, aptly named ‘WORKGROUP’, and is getting all network settings assigned by the 3COM.
(on the PCs – ‘ipconfig /all’ shows the Def. Gateway, DHCP server and DNS server all having 192.168.1.1, the subnet is 255.255.255.0 and the IP address is within the range 192.168.1.100-200, obviously varies. DHCP leases expire after two weeks)
The network cabling ran from each PC to a hub/cheap switch in every room, from where it uplinked to the ADSL router. Certainly everyone can access the internet.

Enter the big idea (why, oh why?) to setup a domain and get everyone on it with all the benefits that it has – central administration, access rights management, roaming profiles, backup etc.

So I thought that I’ll do a bit of testing first:

I did the following:

1. Promoted the Win 2003 server (SRV2) to a DC for a new domain with AD and DNS. Named the domain (aptly?) ‘DOM1’ (just that, not qualified further like dom1.company.com). The process required me to give the server a static IP address. I chose BELOW the DHCP range – 192.168.1.12. Changed Def. Gateway to 192.168.1.1 (the 3COM router). The DNS entry changed itself (wow?) to 127.0.0.1. In DNS console, right-clicked SRV2, selected ‘Forwarders’ tab and added 192.168.1.1.

2. Joined one Win XP SP2 client to the domain with Firewall switched off. Left it with a dynamically assigned IP address, BUT changed the DNS server to point first to the new DC (192.168.1.12, preferred) and then to the ADSL router (192.168.1.1, alternate). There aren’t any DNS suffixes. The gateway stays 192.168.1.1 – as automatically assigned by the DHCP server (3COM). The computer account (named PC1) was created automatically on the AD upon joining.

3. Created a test user in AD and assigned it a homefolder and a profile folder (all folders created previously on the server, with the appropriate rights etc.. that bit works…)

4. Logged on the client PC (PC1) with the test user account – worked fine. Logged off, and back again – observed the creation of the profile files in the assigned profile folder on the server. The home folder drive (I:) connects exactly as it should. The client can browse the Internet happily without any settings whatsoever in IE.

5. Stuck a bottle of champers in the canteen’s fridge. Went back and started thinking as far ahead as login scripts. Tried to browse to the client PC1 from the DC via Network Neighbourhood. Nope. Tried manually typing \\PC1\c$ in Windows Explorer – nope, won’t have it, comes up with an error (below). Tried pinging it – that was OK, both by name and IP address. Hmmm.

6. Onto the Client XP. Tried pinging the DC from the XP client PC – ’twas all fine. Tried browsing the DC – yep fine, opened available shares (netlogon, sysvol) and stuff, fine too. The client PC’s C$, IPC$ and ADMIN$ shares and all exists as they should. If I click on its own name PC1 in Network Neighbourhood, it does open its own ‘Scheduled Tasks’ and ‘Printers and Faxes’, as it should.

7. Back to the DC – still pings the XP client, still doesn’t browse. Upon clicking the client it comes up with “\\PC1 is not accessible. You may not have permissions to use this network resource”. What I was expecting to see is at least the ‘Scheduled Tasks’ and ‘Printers and Faxes’.

8. Went to the DNS console on the DC. PC1 is not listed there under ‘DOM1’ in Forward Lookup Zones. Only the srv2 is listed.

9. Took the PC1 out of the domain. Deleted the computer account in AD. Joined PC1 to the domain again, the computer account was created automatically.

10. Went to PC1, logged as the domain admin. In a command prompt typed ipconfig /registerdns. Came up with “Registration of the DNS resource records for all adapters of this computer has been initiated. Any errors will be reported in the Event Viewer in 15 minutes..”. No errors were found in Event Viewer. The PC1 still doesn’t appear in the DNS console. should it actually? Still can’t browse the PC1, can ping though.

Can someone please point me to the [obvious] stupid mistake that I’m making and put me out of my misery (not by shooting me hopefully).

Thank you all very much in advance.
MB

This discussion is locked

All Comments