Visit The New, Modern Unix Linux Community

Special Forums UNIX and Linux Applications Stop samba from querying trusted domain servers Post 302435119 by mph on Tuesday 6th of July 2010 11:44:22 AM
It's not listing from all the domains. It IS trying to reach the other controllers. The problem is that there's no route to some of the servers and others there's no route back to the machine. Doing a tcpdump yields the following

From my samba machine in the DMZ to, and back from, the local AD server:
Quote:
10:45:01.170297 IP 10.xxx.xx.34.44697 > 10.xxx.x.70.389: tcp 0
10:45:01.170434 IP 10.xxx.x.70.389 > 10.xxx.xx.34.44697: tcp 1188
To other AD servers with insufficient routing:
Quote:
10:47:00.154323 IP 10.xxx.xx.34 > 10.xx.xxx.128 tcp 99
10:47:10.462745 IP 10.xxx.xx.34 > 10.x.xx.223 tcp 99
There are 5 or so more remote AD servers from other domains that never come back for due to routing. During the time that it's attempting to query or connect with these servers file listings and such "hang" until the the local machine gives up.

Using the allow trusted domains = no parameter DOES limit the connection attempts to once every half an hour or so. Before that, it would try almost every time a directory listing or anything else that needed to tie a user name to an UID was attempted. It's not the fix, but it SURE helped.

The routing is something that will not be fixed. The other domains need not access nor communicate with our DMZ.
 
Test Your Knowledge in Computers #232
Difficulty: Medium
The ARPANET project was formally decommissioned in 1994.
True or False?

10 More Discussions You Might Find Interesting

1. UNIX for Dummies Questions & Answers

Using Samba to join a win 2000 Domain

I am trying to set samba up to join my windows 2000 domain and I am having troubles If anyone if familiar with this help would be greatly appreciated I issue the following command # ./smbpasswd -j DOMAIN -r DOMAINCONTROLER And the following gets returned load_client_codepage: filename... (4 Replies)
Discussion started by: gennaro
4 Replies

2. UNIX for Advanced & Expert Users

Samba does not connect to domain

I have a samba server and a raid SAN which is actually running samba. Neither one lets me access anything on the samba unix side. I really do not know where to look anymore. there are no errors. When I try to connect to the samba server I get prompted with login and password repeatedly. Frank (4 Replies)
Discussion started by: frankkahle
4 Replies

3. AIX

Servers still querying old DNS server?

Hello, I've created new DNS servers and changed all of the clients /etc/resolv.conf to point to them, but when I check the old DNS logs, I see that the clients are still querying it. Does anybody know why? thanks, (2 Replies)
Discussion started by: ctcuser
2 Replies

4. Red Hat

Samba: Authenticating and joining AD domain as a member

Hi all, I'm having some problems with joining an active directory domain as a member. My Linux servers using the same configuration across the board are all joining as domain controllers, which is bad. I am running Samba 3.0.25b-0.4E.6 on all of my RHEL servers. Here is my global... (1 Reply)
Discussion started by: Bert
1 Replies

5. Solaris

How to stop samba on solaris 10?

Hello to everybody from Argentina. I need to stop samba because i need to fsck a filesystem How can i do this? I presume that the version is higher than 3.0. /usr/sfw/sbin/smbd -D This is the out of ps -ef | grep smbd. Thank you very much for your time i am a litle lost. The... (4 Replies)
Discussion started by: enkei17
4 Replies

6. Homework & Coursework Questions

cannot join xp or vista to samba domain (PDC)

Use and complete the template provided. The entire template must be completed. If you don't, your post may be deleted! 1. The problem statement, all variables and given/known data: I have a barebones XP Pro SP2 with no firewall. CentOS 5.xx running a Samba 3.xx Domain (PDC) The XP machine... (2 Replies)
Discussion started by: pogipants
2 Replies

7. UNIX for Dummies Questions & Answers

Samba change domain controller

Hello people i have a samba and they changed domain controller from a windows 2003 to a windows 2008, there is a problem with the version of samba maybe incompatibilities i dont know what show me this domain_client_validate: unable to validate password for user xxxx in domain xxxx to Domain... (0 Replies)
Discussion started by: enkei17
0 Replies

8. Debian

Testing a SAMBA Domain Controller

Hello,,, We have an existing(working) MS PDC in our office. I have already installed SAMBA with LDAP Authentication on a TEST machine (on same LAN). But, am unable to join a WinXP machine to this domain. in smb.conf i have: WORKGROUP = mydomain and tried to join the XP machine to... (0 Replies)
Discussion started by: coolatt
0 Replies

9. Windows & DOS: Issues & Discussions

Lost Domain Admin Privileges in Samba

Hello, I have apparently lost all domain admin privledges in Samba. I have had several problems ever since I installed the 1/31 Solaris patch cluster. I had to roll out one Samba update (146363-01), which denied all logons network access. However, this particular problem seems to have begun... (0 Replies)
Discussion started by: stringman
0 Replies

10. UNIX for Dummies Questions & Answers

Help with accessing Samba shares on external (NON-DOMAIN) webserver(s)

Hi all, You may have seen my recent topic, where I asked for help getting some samba shares to work on our network. Now that these are working, I move on to the next hurdle! We have a few externally hosted (Windows Server 2008 R2) web servers which are not on our domain, but can still... (0 Replies)
Discussion started by: mgreen81
0 Replies
uux(1c) 																   uux(1c)

Name
       uux - unix to unix command execution

Syntax
       uux [-] command-string

Description
       The  command gathers 0 or more files from various systems, executes a command on a specified system, and sends standard output to a file on
       a specified system.

       The command-string is made up of one or more arguments that look like a shell command line, except that the command and file names  may	be
       prefixed by system-name!.  A null system-name is interpreted as the local system.

       File names may be one of the following:

       o    A pathname

       o    A pathname preceded by ~xxx, where xxx is a userid on the specified system and is replaced by that user's login directory

       o    Any other syntax that is prefixed by the current directory.

       For  example,  the  following  command  line  gets  the f1 files from the usg and pwba machines, executes a command and puts the results in
       f1.diff in the local directory.
       uux "!diff usg!/usr/dan/f1 pwba!/a4/dan/f1 > !f1.diff"

       When using special shell characters such as <>'!, you should either quote the entire command-string, or you should quote the special  char-
       acters as individual arguments.

       The  command  attempts  to  get all files to the execution system.  If both the file and command are located on different remote sites, the
       file is first brought to the local system and is then transferred to the execution system.

       If you want to include files as arguments to a command, but you do not want those files to be processed by enclose the filename	in  paren-
       theses.	For example:
       uux a!uucp b!/usr/file (c!/usr/file)
       The  previous  example  sends  a  command  to  system The is transferred from system to the local system, and then is passed to system When
       arrives at system the command executes and sends to system

       If the request is not allowed on the remote system, the command notifies you.  This response is sent through remote mail  from  the  remote
       machine.

Options
       -c, -l
	  Do not copy local file to the spool directory for transfer to the remote machine.  This is the default.

       -ggrade
	  Specifies  the  grade which is a single letter or number from 0 to 9, A to Z, or a to z.  The highest grade is 0, the lowest grade is z.
	  The default is A.  Lower grades should be specified for high-volume jobs, such as news.

       -n Sends no notification to user.

       -p, -
	  Reads stdin.

       -r Queues the job, but does not start the file transfer.

       -xdebug
	  Produces debugging output on stdout.	The debug option is a number between 0 and 9.  Higher numbers provide more  detailed  information.
	  Debugging is permitted only for those users with read access to

       -z Notify the user if the command fails.

Warning
       An installation may limit the list of commands executable on behalf of an incoming request from Typically, a restricted site permits little
       other than the receipt of mail through

Restrictions
       Only the first command of a shell pipeline may have a system-name!.  All other commands are executed on the system of the first command.

       The use of the shell metacharacter asterisk (*) shell metacharacter may not behave as you expect.  The shell tokens (<<	>>) are not imple-
       mented.

       You are not notified when execution on a remote machine is denied.  Only commands listed in on the remote system are executed at the remote
       system.

Files
       /usr/spool/uucp	   spool directory
       /usr/lib/uucp/*	   other data and programs

See Also
       uucp(1c)
       "Uucp Implementation Description" ULTRIX Supplementary Documents Vol. III: System Manager

																	   uux(1c)

Featured Tech Videos

All times are GMT -4. The time now is 01:27 AM.
Unix & Linux Forums Content Copyright 1993-2020. All Rights Reserved.
Privacy Policy