SOLVED Users get Access Denied if they connect via IP Address. Connecting via Hostname works.

jtoninger

Dabbler
Joined
Aug 29, 2018
Messages
13
HI There,

We have had a FreeNAS system in Production for several years. Running 11.2 U8 and bound to AD. Seemingly out of nowhere last night users were unable to connect to their usual SMB Shares. Typically they use \\Ip-address\Sharename. However now when they try to access the share they get access denied.

However, they CAN still access the share if they use the Hostname of the FreeNAS instead. \\Hostname\Sharename works fine. I've tried toggling the Trusted Domain and Default domain settings but that has not helped.

I am a bit stumped here, and doing some searches for this issue leads to endless results of people having the exact opposite issue, so I'm a bit stuck.

I already wasted tonnes of time thinking it was a permissions issue.

Any advice appreciated. Thanks!
 

anodos

Sambassador
iXsystems
Joined
Mar 6, 2014
Messages
9,554
HI There,

We have had a FreeNAS system in Production for several years. Running 11.2 U8 and bound to AD. Seemingly out of nowhere last night users were unable to connect to their usual SMB Shares. Typically they use \\IP-address\Sharename. However now when they try to access the share they get access denied.

However, they CAN still access the share if they use the Hostname of the FreeNAS instead. \\Hostname\Sharename works fine. I've tried toggling the Trusted Domain and Default domain settings but that has not helped.

I am a bit stumped here, and doing some searches for this issue leads to endless results of people having the exact opposite issue, so I'm a bit stuck.

I already wasted tonnes of time thinking it was a permissions issue.

Any advice appreciated. Thanks!
Sounds like NTLM authentication is not working, but kerberos is working (in AD if you're not using FQDN, you're using NTLM). Maybe start with checking the relevant GPO settings.
 

jtoninger

Dabbler
Joined
Aug 29, 2018
Messages
13
Just to circle back on this, it was one of those "How did the ever work in the first place?" issues. I found an old Reverse PTR record pointing the FreeNAS IP to a different host. It had been there for years but only started causing an issue recently. Removed that and all was well.
 

anodos

Sambassador
iXsystems
Joined
Mar 6, 2014
Messages
9,554
Just to circle back on this, it was one of those "How did the ever work in the first place?" issues. I found an old Reverse PTR record pointing the FreeNAS IP to a different host. It had been there for years but only started causing an issue recently. Removed that and all was well.
1585942312481.png
 
Top