Recommended way to set up Windows shares using Active Directory permissions

Status
Not open for further replies.

Taomyn

Cadet
Joined
Mar 14, 2012
Messages
1
I just built a new box using 8.04 with a RAID-Z volume that I wish to share out to my network. I have configured AD on FreeNAS to connect up to my domain and wbinfo -u and -g both show my users/groups have been imported. Yet no matter what I do I cannot get access to my shares unless I allow guest access.

Normally I would expect when entering just \\SERVERNAME into my Explorer address bar to show me all the shares available, but all I am greeted with is a request for my username and password. None of my other boxes, a Windows 2008 R2 server, various Win7 machines, my router running DD-WRT nor my old QNAP NAS prompt me at that point - only if I try to access a share that my logged in account doesn't have access to. I did manage to see my test share by using "nobody" as the username but that's useless.

I've looked up and down this forum, Googled various permutations of words to try and get a guide to setting this up properly, but for every one I find there is no mention of using AD.

Is Windows Sharing simply broken in FreeNAS 8? I'm no IT newbie, been in the business for over 20 years, but this has me totally puzzled. I played with FreeNAS 7 about 18 months ago and was impressed at the time how easy it was to get going, but I didn't have anything useful to run it on. Has anyone actually got something like this working with v8?

** UPDATE **

I factory reset FreeNAS and did things one step at a time:

1. Created a ZFS RAID-Z2 volume
2. Created a ZFS dataset for my share, called "testfolder"
3. Configure CIFS:

Authentication Model: Local User
NetBIOS name: FREENAS
Workgroup : MYWG
Description : FreeNAS Server
DOS charset: CP437
UNIX charset: UTF-8
Log level: Minimum
Local Master: Unchecked
Time Server for Domain: Unchecked
Guest account: nobody
Allow guest access: Unchecked
Only allow guest access: Unchecked
File mask:
Directory mask:
Large RW support:Unchecked
Send files with sendfile(2): Checked
EA Support: Unchecked
Support DOS File Attributes : Checked
Allow Empty Password: Unchecked
Auxiliary parameters:
Enable home directories: Unchecked
Enable home directories browsing: Unchecked
Home directories:
Enable AIO : Unchecked
Minimum AIO read size: 4096
Minimum AIO write size: 4096
Zeroconf share discovery: Unchecked

4. Enabled CIFS
5. Created a CIFS share called "TestFolder", settings of note:

Browsable to Network Clients: Checked
Show Hidden Files: Checked

After this I still could not see the share, so I enabled "Allow Guest Access" for the main CIFS settings and voila, the share popped up. Access was denied to the share itself but I sort of expected that. So I also enabled "Allow Guest Access" to the CIFS share itself and again, voila I was able to open the share. Tried to copy a file and was denied - quite rightly.

So the next step was to enable Active Directory, which I did. Have confirmed my users and groups are all present. So I tried to access the same share.

Did it work? Nope. Can't even see the share :-(

What the heck is going on? I'm using same machine to try to connect so my connection credentials haven't changed.

I rebooted FreeNAS, still the same. I disabled AD, still the same. I rebooted FreeNAS back to working, but no AD active.
 
Status
Not open for further replies.
Top