Windows Auth question/issue

C

C Trailer

Hi, thanks in advance for any suggestions or help.

I have a client who setup a DMZ server W2K3 Standard SP1, IIS 6, ASP.NEt
1.1. The server is dual homed, one address to the private network and one
going to an external address.

I'm trying to get Windows Authentication to work properly. It works as
expected when accessing it locally using http://servername,
http://localhost, http://internalIPaddress . however, when trying to access
it via the external ip address (even on the local machine), windows
authentication fails. The event log indicates an event id 537, Failure
Audit (an unexpected error occurred during logon).

My assumption is that this has something to do with the dual homed nature,
but am seeking any advice or knowledge of this type of setup and error.
Maybe i need to add static route to make sure the AD communication goes
through the internal link.

Any help is greatly appreciated.

..chris.
 
K

Ken Schaefer

I'm not sure you need a static route - you may.

First, ensure that the IIS box knows how to contact your domain controllers
(easiest way is if you set the IIS server's DNS servers to be your
AD-integrated DNS servers). Alternatively, you may need to setup a DNS
server in your DNS that contains the necessary records that point back to
your internal DCs.

Cheers
Ken

: Hi, thanks in advance for any suggestions or help.
:
: I have a client who setup a DMZ server W2K3 Standard SP1, IIS 6, ASP.NEt
: 1.1. The server is dual homed, one address to the private network and one
: going to an external address.
:
: I'm trying to get Windows Authentication to work properly. It works as
: expected when accessing it locally using http://servername,
: http://localhost, http://internalIPaddress . however, when trying to
access
: it via the external ip address (even on the local machine), windows
: authentication fails. The event log indicates an event id 537, Failure
: Audit (an unexpected error occurred during logon).
:
: My assumption is that this has something to do with the dual homed nature,
: but am seeking any advice or knowledge of this type of setup and error.
: Maybe i need to add static route to make sure the AD communication goes
: through the internal link.
:
: Any help is greatly appreciated.
:
: .chris.
:
:
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Members online

No members online now.

Forum statistics

Threads
473,770
Messages
2,569,584
Members
45,075
Latest member
MakersCBDBloodSupport

Latest Threads

Top