network sharing

First, the normal way to share

1. Change the different computer name, set the same workgroup.

2. Manually set the IP, the ip provided with a network, subnet mask, and the same DNS resolution.

3. Open the Server service.

4. Firewall - Exceptions - check the "File and Printer Sharing", of course, you can also turn off the firewall.

5. secpol.msc: Local Policies - Security Options
  "Local Security Settings" - "Security Options" - the "Network access: SAM does not allow anonymous enumeration of accounts and shared" to "disabled", it is best to disable "network access: Do not allow anonymous enumeration of SAM accounts"
  "local security settings" - "security options" - the "account: local account use of blank passwords to console logon only" disable

6. Double-click My Computer, open Explorer - Tools - Folder Options - View - will "use simple folder sharing" in front of hook removal!

Second, local area network sharing with guest login

1. Enable the user guset

Secpol.msc 2.
  "Local Security Settings" - "User Rights Assignment" - "the refusal of access to this computer from the network" inside the guest user to delete
  the "Local Security Settings" - "User Rights Assignment" - "the refusal as a server and batch job "inside the guest user to delete users and SUPPORT_388945a0
  " local security settings "-" security options "-" network access: local account sharing and security model "- the" classic "to" guest only. "

Third, the reason for the investigation can not be shared

1. Open Services (services.msc): Workstation, Server, Computer Browser

2. Turn on the agreement: local connection - properties
  for Microsoft Networks File and Printer Sharing
  Internet Protocol (TCP / IP) -> Advanced -> WINS -> NetBIOS open

3, ports: TCP 445 port, NetBIOS (TCP 139 port)
  local connection - properties TCP / IP properties - Advanced - Options -TCP / IP filtering - attribute - Allow all (TCP ports, UDP ports, IP protocol)

Fourth, other

1. Network Access: SAM does not allow anonymous enumeration of accounts and shared

This security setting determines whether to allow SAM accounts and shares anonymous enumeration.

Windows allows anonymous users to perform certain activities, such as enumerating domain accounts and network shares. This is convenient, for example, when an administrator wants to grant the user does not maintain mutual trust trusted domain access permissions. If you do not want to allow SAM accounts and shares anonymous enumeration, enable this policy. Default setting: Disabled.

Convenient point, "disable" safe point: "Enable." You do not Guannameduo, this is just to say you want to share files easily spot it in time? Or security point of it?
You have to convenient point, such as playing your \\ machine name \ file name can be opened directly in your machine other machines share files
you want to secure points, hit \\ your machine name in other machines \ file name will appear system username and password box otherwise not visit

2. "Account: local account use of blank passwords to console logon only"

This security setting determines whether or not password-protected local accounts can log on from a location outside the physical computer console (such as remote login) of. If you enable this setting is not password-protected local account will only be able to log on the computer keyboard.

Reproduced in: https: //www.cnblogs.com/rainman/archive/2013/05/27/3102795.html

Guess you like

Origin blog.csdn.net/weixin_34186950/article/details/93561324
Recommended