Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Buffalo Linkstation and AD user rights

Status
Not open for further replies.

royalmail

IS-IT--Management
Jan 16, 2002
283
0
0
US
I recently got an LS-QL series Linkstation and have successfully added it to our AD domain.

However, when it comes to applying domain user/group account persmissions to folders it just says that it was unable to obtain the account information, and the only option I have is to use local based user accounts (which I don't want to do).

As far as I can tell all the settings are fine, bar WINS as I don't think we are running a WINS server, but I don't see this affecting an AD account import.

Anyone have any ideas? Finding information regarding this seems to be like trying to find a needle in a haystack.
 
Just to give a bit more background, we are running 2003 based AD.

I've just upgraded the firmware on the Linkstation to the latest version (1.11), but it doesn't appear to have made a scrap of difference.

I can add the Linkstation to the domain without issue, but once done it just says that it 'cannot obtain' the domain user list.

I heard that you first need to prepare/create the computer account for the device from within ADUC before going to the web management interface of the Linkstation and starting the process. However, I've tried this too and it doesn't change a thing.

If you know of a resource with clear instructions on how to do that, or can think of anything else, it would be appreciated. Without being able to apply domain based user access this 2TB is a waste of time, money, and electricity.

As you can tell, I'm not overly impressed with this kit so far!
 
Turns out that you can only apply 2003 AD based permissions on a LinkStation IF your forest/AD structure is flat.

So if you have an AD tree/complex structure, then forget about using AD permissions on the LinkStation.

I suspect that, for many companies, that makes the hardware a waste of time...

There is a workaround of sorts, but it is pretty inflexible. It means you can assign permissions based on AD user accounts, but individual user accounts only. No groups. Also, the account needs to authenticate with the NAS first. The LinkStation needs to be in a workgroup too, not the domain.

So pretty useless, but better than nothing:

Under Network->Workgroup/Domain, select Workgroup and put a checkmark in the "Delegate Authority to External SMB Server", "Use Windows Domain Controller as Authentication Server", "Automatic User Registration", and "Authentication Shared Folder" and enter the required information.
The "Authentication Shared Folder" option will create an open share. Have the domain users that are to access the unit login to that share. This will register those users on the Terastation.
Afterwards, you can set Access Restrictions on the shares using those users. The users will be the actual domain users, so if you change the password in AD, it will change for the unit.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top