Platinum Edition Using Windows 98

Previous chapterNext chapterContents


- 39 -

Connecting to an NT Network


by John West

Choosing Your Primary Network Logon

Windows 98 provides the mechanisms to connect to different types of providers on a network. In this chapter, you learn how to set up your Windows 98 workstation to connect to Microsoft Windows NT servers and workstations and to other Microsoft Windows 98 machines. This connection enables you to access shared files and printers. You also learn how to use some of the services provided by Microsoft, one of which is the capability to secure your shared resources using Windows NT native security account databases.

Because Windows 98 provides connectivity with many different network providers, you may at some point need to select which provider you will connect to first as you log on to your workstation. For example, you may work in a company that uses Microsoft Windows NT servers as a corporate standard. However, your department may have a Novell NetWare server with resources you need to access as well. Or you may have a laptop that you want to log on to Windows NT when you're connected locally, but you may want to bypass the logon when you're on the road. You can choose one provider to be your Primary Network Logon. Common choices include Windows Logon, Windows Family Logon, Client for Microsoft Networks, Client for NetWare Networks, and NetWare Client 32.

Your Primary Network Logon is the first provider you want to get a logon prompt for when you begin working. Logon scripts and other tasks are executed based on your selected Primary Network Logon. The logon script of your selected Primary Network Logon runs last. This arrangement is actually a good thing. A vital function of logon scripts is to provide consistent drive mappings to resources from your network provider. By having your primary provider's script run last, you ensure that the drive mappings for it overwrite any previously assigned mappings from your non-primary providers. The exception to this situation is when you have Client for Microsoft Networks installed. In this case, the Windows NT logon script always runs first.

To select your Primary Network logon, follow these steps:

1. Run Control Panel.

2.
Double-click on Network.

3.
Choose your Primary Network Logon from the Primary Network Logon drop-down box as shown in Figure 39.1.

Selecting Windows Logon

Windows Logon is the default choice for Primary Network Logon when you have no network connectivity installed, or when you have no network providers to connect to. When Windows Logon is the Primary Network Logon, you are prompted to log on to the workstation with the prompt shown in Figure 39.2.

FIG. 39.1 You can select your Primary Network Logon from any network providers set up on your workstation.

FIG. 39.2 The Windows Logon dialog box.

The logon feature provides built-in security for Windows 98. When you log on at the Windows Logon prompt, Microsoft remembers the username and password you provide. Windows 98 enables you to log on and identify yourself to the workstation itself for the following reasons:

FIG. 39.3 With password caching, Windows 98 can remember passwords to various services you use.


TIP: If you don't want to have to enter a Windows 98 password each time you log on, you can leave the password blank. Of course, your cache file won't be as secure, so you need to balance convenience and security. If you have assigned a password to your Windows 98 username and wish to remove it, you can change it after you log on under the Passwords applet in Control Panel.


TROUBLESHOOTING:

If you have any problems with your Windows 98 password cache or simply don't feel comfortable with your passwords being cached, you can delete the cache file. It's located under C:\WINDOWS and is named with your username and the extension .PWL. You don't have to be too concerned about the safety of this file, though. Microsoft uses a 128-bit key to encrypt it. Currently, this level of encryption makes the file virtually impossible to decrypt.


Selecting Windows Family Logon

Windows Family Logon, which is new to Windows 98, extends the concept of the Windows Logon. When you install this client under the Network Control Panel applet and choose this client as your Primary Network Logon, you can choose the Windows 98 username that you want to use to log on. For this approach to work, however, you must have previously established the use of user profiles on your machine (see Chapter 3, "Navigating and Controlling Windows"). To log on with Windows Family Logon as your Primary Network Logon, simply highlight your username and enter your password at the prompt, as shown in Figure 39.4.

FIG. 39.4 The Windows Family Logon box.

Selecting Client for Microsoft Networks

If Client for Microsoft Networks is your Primary Network Logon, then any system policies and user profiles that network administrators have created will be downloaded to your machine from the Windows NT network. Also, any logon scripts assigned to you on the server or domain to which you connect will be run.


NOTE: What are system policies and user profiles? System policies are settings specific to the workstation from which you're logging on. For example, administrators at your site may have decided to display a dialog box with a legal notice concerning unauthorized use of network resources prior to a user logging on to any workstations on the network. The use of system policies would enable them to distribute the settings for this dialog box over the network.
User profiles are settings specific to a user or group. If you have your PC configured for multiple users, you are using user profiles. However, user profiles that get downloaded from a server overwrite any existing settings you have. For example, you may have a particular graphic you like to use at work for your wallpaper. However, the network administrators might prefer for everyone to use a corporate graphic as wallpaper. If the administrators configure this wallpaper in the network-based user profiles, your PC will be configured for the corporate graphic when you logon. 

Selecting Client for NetWare Networks

If Client for NetWare Networks is your Primary Network Logon, system policies and user profiles can also be downloaded. They will be retrieved from your preferred server (see the section on configuring Client for NetWare Networks). The NetWare login script will also be run. See Chapter 40, "Connecting to a NetWare Network," for more information on NetWare connectivity.

Joining a Windows Workgroup

Many smaller organizations use a peer-to-peer network to fulfill their file and print-sharing needs. A peer-to-peer network consists of workstations that are used for daily computing tasks by their users, but that have also been configured to make resources available to other users on a network. With peer-to-peer networks, users' workstations are grouped into logical units called workgroups. Workgroups don't affect whether or not a user can get to a resource on another computer. They affect only what a user sees by default when he or she looks for the resource through Network Neighborhood, Explorer, or other programs in Windows 98 that support network browsing.

Identifying Your Computer

Every computer used in peer-to-peer networking must have a unique computer name. The name can be up to 15 characters long and must not include spaces. Follow these steps to name a computer:

1. Run Control Panel.

2.
Double-click on Network.

3.
Select the Identification tab, shown in Figure 39.5.

4.
Fill in your computer name.

FIG. 39.5 Use the Identification tab to configure your workstation-naming parameters.

Identifying Your Workgroup

The workgroup name you provide enables you to select which workgroup of computers your computer displays by default when you browse network resources. The name you use is arbitrary as long as any other computers you want to browse use the same name. In other words, if you name the workgroup ABC, for example, you'll see other computers in your default browse list that also gave the name ABC to their workgroup. The workgroup name is not case sensitive.

Adding a Comment to Describe Your PC

While you're at the Identification tab, fill in a comment for your PC. This entry is important when your computer has file and print sharing enabled. Other users browsing for your computer can see this comment if their browse program enables them to view details. Figure 39.6 shows an example of viewing details in Network Neighborhood.

FIG. 39.6 Viewing details in Network Neighborhood enables the user to see comments about the computers in the workgroup or domain.


TIP: Include your name in the comment field if your workstation name doesn't already represent your name. This information tells users who need resources located on your computer who to contact if they have problems connecting to your workstation. For example, if your workstation name is Finance and someone has a problem connecting, he or she would know to call you if the description for the workstation is Financial Services - Jane Doe.

Logging On to a Windows NT Network

Windows NT, in both the workstation and server versions, is a more robust network server platform than Windows 98. With Windows NT Server especially, the platform has been designed from the ground up to be a network provider. Windows NT has several advantages over Windows 98 that make Windows NT the better solution for file and print sharing.

Microsoft Windows NT is gaining more and more market share. Even if your company isn't using Windows NT as its primary network provider, chances are that sooner or later Windows NT will be implemented in some capacity in your environment.

Connecting to a Windows NT Domain

Windows NT servers can be organized into a logical unit called a domain. Each domain has one Primary Domain Controller (PDC). The PDC stores the master copy of the security account database for the domain. This database is where users, groups, and their respective settings, such as passwords and the logon script that will be run for the user, are contained. The PDC periodically replicates the changes in the security account database to the Backup Domain Controllers (BDCs). Consequently, resources such as files and printers on any of the servers can be assigned security using the same users and groups. This approach means that you, the user of these resources, do not need a separate user account and password for each server.

Windows NT domains can even be related to each other in a hierarchical fashion by using trust relationships. A trust relationship enables the administrator of one domain to assign security rights for resources to users and groups from another domain. This flexibility is important to you because you can log on as a user in one domain and yet access resources in another domain.

Follow these steps to configure your workstation to log on to a Windows NT domain:

1. Run Control Panel.

2.
Double-click on Network.

3.
Set your Primary Network Logon to Client for Microsoft Networks.

4.
Highlight Client for Microsoft Networks in the list of installed network components and click on Properties. See Figure 39.7.

FIG. 39.7 The Client for Microsoft Networks Properties dialog box.

5. Check the Log on to Windows NT Domain check box.

6.
Fill in the name of the domain to which you want to log on in the Windows NT Domain: text box. As mentioned previously in regard to trust relationships, the domain you log on to and the domain from which you access resources may be different.

7.
Select whether you want to enable _Quick Logon or Logon and Restore Connections. Quick Logon displays previously mapped drives (called persistent drive mappings) when you browse your computer's drives; however, your workstation does not actually contact the provider of the resource to ensure that it's available until you first attempt to use the drive. Logon and Restore Connections, however, tries to contact the provider as it maps the drives. This option increases your logon time, but at least you know before you begin work that the drives really are ready for use.


TIP: If you're a road warrior, choose Quick Logon to avoid drive mapping errors when you log on to your computer while you're not connected to the network.

After you configure these settings and restart your machine, the logon dialog box shown in Figure 39.8 appears. Then when you successfully enter your username and password for the domain, your logon script runs (if your administrator has assigned you one) and any persistent drive mappings are restored.

FIG. 39.8 Client for Microsoft Networks uses the domain name you specified in the network setup when prompting you to log on.

You can also override the domain name shown in the prompt. This approach is useful if you have accounts on more than one domain at your company. To override the default domain name, simply type over it with the name of another domain on your network.


NOTE: The workgroup name discussed in the section "Joining a Windows Workgroup" is also useful in a Windows NT domain environment. In this environment, you set the workgroup to the name of the domain that contains most of the resources you use. For instance, if you log on to a domain called Accounts, but you use resources from a trusting domain called Resources (not very original, I know), you are better off setting your workgroup name to Resources. This way, when you browse, you see the servers in the Resources domain first. 

Connecting to a Windows NT Workstation

A computer with Windows NT Workstation as its operating system stores a security account database on the local machine. (In contrast, Windows 98 has no means to store user account information.) Connecting to a Windows NT workstation is similar to connecting to a Windows NT server domain. However, instead of entering the domain name at the Windows NT Domain prompt, you should enter the name of the workstation. When you log on, you are prompted for a username and password. If you do not yet have a user account in the security account database on the Windows NT workstation, the administrator of that workstation needs to create one for you before you can log on.

Changing Your Windows NT Password

To change your Windows NT password and your Windows 98 Logon password to the same new password, follow these steps.

1. Run Control Panel.

2.
Double-click on Passwords.

3.
Click on Change Windows Password.

4.
Select any other passwords you want to change. Select Microsoft (see Figure 39.9).

FIG. 39.9 When you change your Windows password, you are prompted to change other provider passwords at the same time.

5. Enter your old Windows 98 Logon password and a new password twice for verification.

6.
If your current Windows 98 Logon password and your Windows NT password are not the same, you are prompted to enter your current Windows NT password (see Figure 39.10).

FIG. 39.10 If your Windows password and Windows NT password aren't the same, you are prompted to enter your current Windows NT password.

After you enter everything correctly, your Windows and Windows NT passwords will be set to the new password you specified.


TIP: Keeping your Windows and Windows NT passwords the same means that you won't have to remember two passwords and you won't have to log on twice at startup. See Chapter 44, "Remote Access with Dial-Up Networking," for more details.

If you don't want to keep your two passwords in sync, follow these steps:

1. Run Control Panel.

2.
Double-click on Passwords.

3.
Click on Change Other Passwords...

4.
Select Microsoft Network and click on Change.

5.
Enter your old Windows NT password and a new password twice for verification.

Setting Up User-Level Access Control

Windows 98 enables you to share your files and printers with other network users who connect to your machine and access those resources remotely. Of course, you may want to limit the people who can connect to these resources. Therefore, you need some type of security on them. Windows 98 provides two methods. The first method is share-based security. Using this type of security, you specify a password on a resource and whether it allows read-only access, full access, or both, depending on the password entered by the person accessing it. This security method has limitations however. Everyone must use the same password, and you can't limit the access by user. For this reason, Windows 98 provides user-level access.

User-level access enables you to assign rights to resources based on security information kept by a network provider. This section discusses using Windows NT as the provider. Windows NT has a security account database that contains usernames and passwords, as well as other information. User-level access on Windows 98 enables you to leverage these usernames to secure your resources. For instance, to restrict access to a financial package to users in the financial department, you can assign full rights to the package to the LAS0Finance group to which all financial department users belong.

User-level access control enables you to take advantage of security on a per-user or per-group basis without having to administer these users and groups. Your network administrators can worry about that.

To set up user-level access control, follow these steps.

1. Run Control Panel

2.
Double-click on Network.

3.
If you don't see File and Printer Sharing for Microsoft Networks in the list of networking components, click on File and Print Sharing and make the appropriate selections, depending on whether you want to share files, printers, or both. Close the Control Panel Network applet and reboot.

4.
After the reboot, begin at the Control Panel Network applet again. Click on the Access Control tab (see Figure 39.11).

FIG. 39.11 You must specify a domain from which to assign rights to users and groups.

5. Select User-Level Access Control and specify the domain to whose users and groups you will assign rights on your computer.

6.
Reboot again.

To see a Windows 98 or Windows NT computer when browsing a workgroup in Network Neighborhood or other such tools, the computer must advertise which workgroup it belongs to on the network.

If a computer isn't sharing any resources, that computer does not need to show up in any workgroup listings. However, if a computer has shared resources, displaying it in a list helps a user on the network choose a resource on the machine to use. Otherwise, you'd have to know the name of the machine ahead of time.

To set up your computer to advertise its existence, go to the Control Panel Network applet, choose File and Print Sharing for Microsoft Networks, and click on Properties. The dialog box shown in Figure 39.12 appears on your screen.

Table 39.1 shows the browse options.

Table 39.1  Browse Options with File and Print Sharing for Microsoft Networks

Option Description
Browse Master With a Windows network, the computer that becomes the browse master stores information about all the other computers in the workgroup. Whenever a computer wants to enumerate the other computers in the workgroup, it contacts the browse master for the information. An election process determines which computer becomes the browse master. If you set this option to automatic, it follows a predetermined set of election rules to determine whether it should be the browse master. If you set the option to Enabled, it always acts as a browse master. If you set it to Disabled, it never becomes the browse master.
LM Announce If you have a LAN Manager domain, you should set this option to Yes. Otherwise, leave the default setting of No.

FIG. 39.12 You need to specify how your computer should advertise its existence on the network.


TIP: If your Windows 98 computer is participating in a Windows NT domain, choose the Disabled setting under the Browse Master option. A Windows NT machine should always be the Browse Master. Windows NT has much more robust capabilities to function in this role.

After you set up user-level access control, you can assign rights to the users and groups in the domain you selected when you set up shares on your computer. See Chapter 7, "Advanced File Management Techniques," Chapter 41, "Windows 98 Network Administration," and Chapter 43, "Sharing Network Resources." 


Previous chapterNext chapterContents


© Copyright, Macmillan Computer Publishing. All rights reserved.