Authenticating Remotely

Authenticating Remotely

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Authenticating Remotely JD Benton 11-18-2005
Posted by =?Utf-8?B?SkQgQmVudG9u?= on November 18, 2005, 11:25 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello All
I have already posted this in another group but wonder if this might not be
the better place for it.

I have a very strange problem that I am sure someone here is just dieing to
solve for me. At least that is my hope.
Our setup is like this:
1. Windows 2003 domain
2. Many remote users with IBM laptops or Fujisu Stylistic Tablets
3. Checkpoint SecureClient VPN client software
4. RSA Ace server for VPN authentication
5. Scriptlogic 6.5.2 for mapping drives etc

The problem:
We have several users that authenticate to our network through a VPN
connection. These users have Checkpoint SecureClient installed on their
machines and are authenticated to a RSA Ace server in our domain. Once the
user is logged on they run a batch file that maps thier network drives via a
short-cut to the Slogic.bat file in the Netlogon directory of our PDC
Emulator. Now for most people this is not a problem but for some laptop
users and all Fujisu Tablet users the process of trying to run the login
script takes anywhere from 30-60 minutes to complete. What happens to the
people having a problem is this:
1. User runs the short-cut to Slogic.bat
2. After about 7-15 minutes they are prompted for a username and password
3. If they type in their domain user name and password they get prompted
again after about 4-10 more minutes with a message saying "that
authentication has been previously tried and failed".
4. The user can then type in a username and password from a temporary
account I created to help resolve this problem. This account is just a
simple domain user.
5. After several more minutes the logon screen will appear but can take up
to 35-40 to complete
6. When complete, the user checks for their drives but none have mapped.

As you can image, they are not very happy after taking all of this time only
to find out things did not work.

If the same user logs onto the network with the same machine while they are
in the office, everything works very quickly and as it should.

I have looked in the trace file that Scriptlogic creates and this an example
of the error message that I see:
08:44:58 Mapping drive G \Server1\Graphics [SLP00001 1/30]
08:46:02 Error: Unable to map drive: 1265 The system detected a possible
attempt to compromise security. Please ensure that you can contact the server
that authenticated you.

I have been in contact with Scriptlogic and they tell me it is a Windows
authentication issue. I read one post where a person appeared to have a
somewhat similar issue to mine and they apparently resolved it by hard coding
the DNS address to on the user machine to point to the DNS server in the
domain. I gave this a shot but did not have any success. This seems to be
an obvious case of authentication but for the life of me I am stumped.

Hopefully someone out there has run into the same problem that has been
dogging me for several months and is able to lend a hand.

Thank you to all that take the time to read this and especially those that
fire me off some suggestions.

JD Benton


Similar ThreadsPosted
Authenticating user from another domain December 10, 2006, 6:20 pm
Password Changes remotely thru VPN February 22, 2007, 3:07 pm
Set C: Drive Permissions Remotely October 18, 2005, 1:56 pm
Has my computer been accessed remotely? July 2, 2007, 4:50 pm
event logs : is there a way to save them remotely? November 14, 2005, 12:05 pm
how to check .pfx certificates in personal store remotely April 5, 2006, 11:50 am
Can someone remotely access my home PC through MSN instant message May 31, 2006, 9:53 pm
Remotely modifying Registry ACL using RegistrySecurity (and Access January 8, 2009, 6:10 am
Enabling windows firewall on 2003 server remotely December 27, 2005, 3:39 pm
Re: Viewing Win2k3 Event logs remotely in a Win2k Domain May 26, 2005, 5:50 pm

The site map in XML format XML site map

Contact Us | Privacy Policy