Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Accessing network shares through a webpage via VPN

Status
Not open for further replies.

MarkDym

Technical User
Apr 23, 2004
101
GB
Hi folks

I have setup a VPN to our network. The network is a single active directory domain environment, and users access the VPN via a RADIUS server (on the domain controller), using their usual username/password/domain information.

I have created a website in IIS that provides links to DFS namespaces on the domain controller. The namespaces each link to a collection of shared folders on a storage server, also within the domain and located at the same site. The domain controller hosts IIS.

I created the site using MS-Word to create a HTML document with hyperlinks which link to each DFS namespace, then added the .htm file to IIS using the New Webpage function.

Accessing this from within the domain works fine, and all the DFS links open in My Computer. However, when I access this via the VPN, although the web page will display, all the links error-out.

I have tried adding the DFS namespace (\\htlincs.local) to the lmhosts file using the include feature, but am not sure if this is the right thing to do, or even if I did it correctly.

I have also tried creating virtual directories which link to the DFS shares (\\htlincs.local\namespace) and although when I browse each directory within IIS the groups of folders that the links point to are shown in the right-hand pane, when the virtual directory is selected in IIS:

1. I get 403 forbidden error when trying to access it from within the network (I have not tried this using the VPN yet)

2. If I open the properties for the virtual directory, I get a 'The system cannot find the path specified' error when I click OK.

Can anyone give me some help with this please. I've never used IIS before, and I've done a bit of hunting around on Microsoft's site, but because I am not sure what the problem is, I do not really know what to look for.

I am not sure if it is a IIS configuration error or whether the LMHOSTS file needs to be changed so that the traffic through the VPN is recognised.

I've posted this question in the IIS section, but have had no responses so am trying here.

Thank you
 
Your setup is extremely similar to the way I'm set up here.

Since it is on an internal network, I would test this in a couple of ways. One would be to lower the security to allow anonymous connections. This should get rid of the 403 errors. Then you can monkey with the settings to make it behave like you want. Doing this doesn't lower the security on the DFS, that is still dependent on the domain permissions.

FOr the second, I'm wondering if a VPN'd user can connect to said machine at all? If your default gateway is NOT the vpn device, you will have to add a route on the IIS server to send traffic back to the VPN device.
 
Hi haykatyck, thanks for your reply.

The Directory Security Authentication and Access Control is set to anonymous access, except where NTFS permissions are required - when it uses 'integrated Windows authentication'

With regards to the second point, the VPN has been fine. All users can browse the network when logged on, and I can use Remote Desktop to access all the PC's and servers without problem.

I'm pretty sure it has to do with the fact that I have referenced DFS namespaces. This is most preferable to referencing individual shares as the DFS namespaces can display groups of shares, reducing screen clutter, and makes it easier for our staff to get to the resources they require.

Thanks again for your help. If anyone else has any suggestions, please post them.

Thanks
 
I've sorted this out. It was a configuration error. I had setup the virtual directories incorrectly.

Thanks for the replies.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top