Network Access | Windows

Network Neighborhood access mode of the following two: "Guest only - local users will authenticate as Guest" and "Classic - local users authenticate as themselves", the different access mode is set, workflow, and failure phenomena just getting started has been plagued by network users, the following work in my practice to discuss the next Jane.
First, two kinds of access mode setting method: First, in the "Local Security Policy" - "Security Options" - "Network access: Sharing and security for local accounts model"
Another folder on the "Tools" - "Folder Options" - "View" - "Advanced Settings" under Settings, select the "Use simple file sharing" is equivalent to "Guest only - local users will be guestsAuthentication "method
Is not selected "Use simple file sharing" is equivalent to "Classic - local users authenticate as themselves" approach
Second, the characteristics of two kinds of access mode: "Guest only" approach is a simple way to share and can not set access permissions to the user's identity and so on, is like a simple hotel right to live in a person to inspect a lax. The "classic" approach is a more complicated way to share, you can set access permissions to the user's identity and so on, is like a one-star high-rise hotels on the arrival of customers and stringent checks. We can through different access mode, the settings interface for the shared folder to be understanding,
1, "Guest only" mode: You can see only a "Allow network users to change my files"

2, "classic" approach: there is a "permission" setting, in which you can set access to the user's identity and authority.

3, two kinds of access patterns of workflow:
1, "Guest only" mode: This mode is for all to access the user identity is mapped to guest, does not require the user to enter any user name and honey code to verify. But to ensure that the services side to enable the "guest" account. As shown below: "Accounts: Guest account status" in the "Enabled" state, if not enabled the following dialog box will pop up, the user can not change, called the gray, the password no matter what the type is not valid.

2, "classic" approach: that is, if the server is disabled simple file sharing, or the server's local security policy - Security Options in the "Network access: Sharing and security for local accounts Mode" set to the classic. First, the client will have priority to the current login account information to submit certification information, such as the client's current logged-on user for the test, password test, if it is time to visit online neighbors, it uses this as a user name and password to validate the information submitted by . If you happen to exist on the server the same name and same password, account and the account has not been disabled, the client will draw the user's identity into the next phase of the local security policy verification, then if the server does not exist on the same name with the password for this account, while the guest account on the server is not disabled, the client will be guest account directly into the identity of the next phase of security policy validation phase. If the server is disabled on the guest account will pop up asked to enter a user name and password dialog box below, then provides the server if there is a user name and password, will be as the user's identity security policies into the next phase of the inspection process.

There is a very common misconception, in determining whether the guest account is enabled, many users is to look inside the user account control panel, where to see whether the guest account enabled. If the display is not enabled on the guest account that the guest is disabled, but the actual guest to determine whether the disabled should be observed in the Computer Management Local Users and Groups where guest user state. In the Control Panel, the user account is meant to enable guest account to allow guest from a local sign-on (appear in the logon welcome screen). In the Control Panel, disable the guest user account does not disable the local user guest account.
Also view the guest enabled easiest way is to use the command net user guest view, look at the output of "account activation" a column of information.
4, a note of caution: we may encounter another problem, namely, when a user's password is empty, regardless of the manner in which access to or can not log on, access will still be rejected. This is because, in the system, "Security Options" in the "accounts: local account use of blank passwords to console logon only" policy is enabled by default (see below), according to security policy in Windows XP refused to give priority to the principle of the user a blank password for network access by using the Windows XP computer will be banned. Of this strategy will be suspended as long as we can solve the problem. In the security options, find the "local account use of blank passwords to console logon only" item, you can disable.
5, common failure analysis:
Breakdown of 1: Regardless of which way the above log entry, and sometimes appears the following error,

Failure Analysis: On the My Network Places feature problem is that there is a need to explain a hidden share IPC $ problem. We visit the My Network Places to see the list of shared resources on the server because the installation of the Microsoft File and Printer Sharing component, it will create a hidden share called IPC $, connected to a computer by looking at the implicit sharing to obtain the list of shared resources on the server. If you delete this shared viewers can not get list of shared resources on the server, of course, can not properly access the shared resources.
Troubleshooting: In the purpose to open a DOS computer to share NET SHARE IPC $.
Breakdown of 2:
Two winxp machines, the user only established the administrator user, do not set the password to \ \ IP address of the form of an interview without prompting the user name and password on the show refused to log on. Two machines are not using simple file sharing.
Failure Analysis:
Do not prompt the user name and password, explained that it had passed the user authentication phase. Because it does not use simple file sharing. Login is based on the client's login account, authentication, the administrator is also logged, but because of the server's administrator without password, According to the default security policy no passwords to console logon account only and therefore refused to receive the login prompt.
Troubleshooting:
Enable the guest account, for the two machines Simple File Sharing enabled, then no password to access. (Note that the Simple File Sharing is enabled before the first check the need to share the NTFS directory permissions allow guest access.
The above is for internet access in the neighborhood visiting a simple model to explore, and I believe a vast network of enthusiasts help, of course, practical work, on-line exchange of visits between neighbors are much more complex situations, such as there is agreement, port, service and other related configuration, in subsequent work in practice, let us work together to improve it.

Comments

Popular posts from this blog

How to remove the service by using Register tool/Command line

Change Default Font in Lotus Notes | IBM | Lotus Notes|

The Port 80 is occupied by other application