[nottingham] Win2K, Samba PDC and firewall

From: Matthew Sackman (matthew@sackman.co.uk)
Date: Fri 15 Mar 2002 - 23:11:46 GMT


Hi all.

I'm setting up a linux server running Samba which has to act as a PDC
(Primary Domain Controller) for a bunch of Win2k machines. Having firewalled
it quite heavily I found that none of the machines would log in. tcpdump
and netstat and samba's debugging logs showed no connection was being
established.

I then removed the firewall and everything was fine. I've now added back
in the firewall but included an additional rule to accept anything that
is sent to the broadcast address. It now works.

Firstly, is this likely? : Should you always have to have a rule to accept
traffic sent to the broadcast address or should the tcp/ip stack just deal
with it implicitly (Policy on the firewall is drop)? Network is switched
100Mbps ethernet.

Secondly rather than just blindly accept everything sent to broadcast, are
specific ports used? I don't understand the whole broadcast thing in *too*
much detail so any help here would be great.

Many thanks,

Matthew

-- 

Matthew Sackman Nottingham England

BOFH Excuse Board: Computers under water due to SYN flooding. -------------------------------------------------------------------- http://www.lug.org.uk http://www.linuxportal.co.uk http://www.linuxjob.co.uk http://www.linuxshop.co.uk --------------------------------------------------------------------



This archive was generated by hypermail 2.1.3 : Fri 15 Mar 2002 - 23:12:25 GMT