Limit what can be seen via network browsing(SMB)
On a Windows Server 2008 R2 server I have an application that uses the SMB (network Browsing/neighborhood) to populate a list of computers to be managed by the application. The problem I am having is that my network is immediately joined by several other networks in a trusted enviroment so the SMB shows computers from my domain and the other domains within our overall network. Is there a way to limit the what is seen by this servers SMB to only the domain that this server is joined to? I found suggestions for older server versions that use either a registry key or group policy to enable the noEntireNetowrk policy but this does not seem to work on the 2008R2 server policy. Any help is appreciated. Thanks, James
October 11th, 2010 8:24pm

Hi James, Thanks for posting here. Based on my understanding that you want this server could only be browsed in this domain that it joined via neighborhood. If I misunderstand please let me know. Have you deployed wins server in your network to provide name solution for all domains ? Are all other domains in same IP segment of this domain? The best way to restrict only local domain computers could be listed in neighborhood is isolate each domain in different IP segment and connected through router , so that the NetBIOS would not be broadcasted to other domains and this server would not be bowered from other domains either. Thanks. Tiger Li TechNet Subscriber Support in forum If you have any feedback on our support, please contact tngfb@microsoft.com Please remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
October 12th, 2010 11:13pm

Based on my understanding that you want this server could only be browsed in this domain that it joined via neighborhood. If I misunderstand please let me know. The Server sees MyDomain, DomainX, and WorkGroupY. I would like to have it so the server only sees in it's network browser items in MyDomain. We have WINS servers up but they are only meant for our domain I belive all the other domains that we are seeing are on the same Class B segement though within that segment they only use certain subnets and we use different subnets for our Servers/Computers. James
October 13th, 2010 6:07am

Hi James, <span style="color: #1f497d;"Please remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
October 14th, 2010 3:14am

Hi James, Thanks for update. Disable “TCP/IP NetBIOS Helper” service on that server and use WINS or DNS for name resolution in your domain could achieve the goal. Thanks. Tiger Li TechNet Subscriber Support in forum If you have any feedback on our support, please contact tngfb@microsoft.comPlease remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
October 14th, 2010 3:14am

Hi James, If there is any update on this issue, please feel free to let us know. We are looking forward to your reply. Thanks. Tiger Li TechNet Subscriber Support in forum If you have any feedback on our support, please contact tngfb@microsoft.com Please remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
October 15th, 2010 4:38am

Tiger Li, Sorry for the delay. Disabling the TCP/IP NetBIOS Helper stops all computers from showing up in the network browser which unfortunately seems to be what the application uses to find other computers. Thank you for your help but I do not believe I am going to find the solution I am looking for, in this particular case. James
October 16th, 2010 8:47pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics