
Some of the main topics in this chapter are
Many corporations and smaller businesses are running Windows 95 as a client on their Windows NT network. For end users, Windows 95 provides an enhanced 32-bit operating system and easy-to-use graphical user interface (GUI) on which to run older 16-bit applications and new 32-bit applications. For administrators, Windows 95 brings built-in network support for the Client for Microsoft Networks, as well as several administration and remote tools to help administrators oversee their networks.
The easiest way to add networking components to your Windows 95 work-stations is to add them when you are installing Windows 95. You must have a network adapter installed and a supported network operating system (NOS) established on your client machines, such as Windows for Workgroups 3.11. During the Windows 95 Setup, each workstation is automatically upgraded, and, if possible, a 32-bit protected mode networking client, such as Client for Microsoft Networks, is installed. If your workstations are networked to servers running on mini- or mainframe type computers, those settings are preserved so that the network still functions under Windows 95.
You might have to add Windows 95 networking components after you've installed and set up your Windows 95 clients. This might be because either you've already upgraded your workstations to Windows 95 before establishing a Windows NT 4.0 Server network or you're adding a new workstation to the network. The process for doing so is actually very easy and is explained in the following sections. In general, the steps are as follows:
2. Install and configure Client for Microsoft Networks, including binding protocols to the client and adapter.
3. Set up permissions.
4. Set up shares, including file and printer shares.
5. Set up user profiles and system policies.
Although you're not required to set up shares, you probably will want to do so to take advantage of Windows 95's peer resource sharing across the LAN. Likewise, not every network administrator uses user profiles or system policies.
Before you begin the process of installing networking client software on your Windows 95 machines, you need to install and configure a network adapter for each machine. Overall, Windows 95 makes it easy to add hardware devices to your machine, and installing network adapters is no different. By following Windows 95 on-screen wizards, you can quickly set up the adapter and configure computer resources for it. These resources include IRQ, memory address, and I/O port.
If the network adapter conforms to the Plug and Play specification, installing it usually means inserting the card into your computer, rebooting the computer, and letting Windows 95 find the new adapter. Once found, Windows 95 automatically assigns resources to the adapter according to the hardware specifications detailed in the device itself. If you have non-Plug and Play devices installed that have specific resource requirements, Windows 95 attempts to assign the Plug and Play adapter to other resources to eliminate device conflicts.
The following steps show you how to install a non-Plug and Play network adapter in Windows 95:
2. With the computer turned off, insert the adapter into your computer, using the instructions provided with the adapter.
3. Boot the computer into Windows 95. Choose Start, Settings, Control Panel, and double-click the Add New Hardware icon.
4. Click Next on the Add New Hardware Wizard screen.
5. When prompted to locate the new hardware device automatically, click No (see Figure 33.1). If you click Yes, Windows 95 attempts to find the network adapter for you. Using this procedure is all right but usually takes several minutes--you can do it faster manually. Click Next to continue.
Select No to tell Windows 95 manually what type of network adapter you're installing.
From the Select Device dialog box, pick the manufacturer and model name of your network adapter.
8. The next wizard dialog box shows you the resource and settings Windows 95 will attempt to use to set up the device. If you know these settings conflict with other settings, you cannot change them now. You need to use Device Manager after the NIC is installed and manually change the settings.
You can print these settings by clicking Print and following the instructions on-screen. You should write down these settings in case you need to refer to them later if you experience device conflicts.
TIP: To launch Device Manager, open Control Panel and double-click the System icon. From the System Properties page, select the Device Manager tab.You can usually find resource information for your NIC in the user guide or documentation bundled with your adapter.
NOTE: During this copying phase, Windows 95 might discover that a file (usually a DLL or VxD) on your computer is newer than one being copied from the Setup disks. You're prompted to indicate whether you want to keep the current one or copy over it by using the older version. In most cases, you should answer Yes to keep the current file. If you answer No, you risk copying over a file installed on your computer from a newer program or device that might not work with the older file. You might want to write down this file in case your NIC doesn't work after Windows 95 installs the software so you can go back and install the older version to make your NIC work properly.In previous versions of Windows, applications and devices usually copied over these newer files, sometimes rendering applications and hardware useless. This built-in safety measure in Windows 95 warns you that a file is being shared by at least two devices or applications.
11. Click Yes to restart your computer now. Click No to return to Windows 95 without restarting the computer. You must restart your computer for the new device to work.
After you restart your system, you're ready to install the Client for Microsoft Networks support.
After your network adapter is installed and working, you need to install the Client for Microsoft Networks to enable the Windows 95 clients to connect to the Windows NT 4.0 server. When you get ready to install the Windows 95 networking components, have the Windows 95 CD-ROMs available. You also should have information about the Windows NT server, such as domain name and IP information if you're installing TCP/IP.
NOTE: Some administrators place a copy of Windows 95 on their server, but it doesn't make much sense to do so. The only way you can use Windows 95 in this case is if you shut down your server and reboot under Windows 95. If you run a small office or have a home network, this might be an option if you don't require Windows NT Server to run continuously. The best situation is to set up separate partitions in which to store Windows 95 and Windows NT Server. If you do this, be sure to back up all your data because partitioning hard drives erases all data on the drive.
You also can place Windows 95 and Windows NT on the same partition, but you must use the FAT file system for both installations. If you want to use NTFS, you must set up separate partitions for each operating system. Note also that Microsoft recommends installing Windows 95 and NT on different partitions because of files both operating systems share in the Program Files folder.
To install the client software, follow these steps:
2. Click Add. The Select Network Component Type dialog box appears (see Figure 33.4).
The Network Properties dialog box shows all the network devices, protocols, clients, and adapters installed on the workstation.
Select the Client option to install networking clients.
4. Select Microsoft on the Manufacturers list. In the Network Clients list, select Client for Microsoft Networks (see Figure 33.5). Click OK.
The Select Network Client dialog box should look similar to this example.
You should see the client listed in the Network Properties dialog box. You now need to install a protocol for your client. In some cases, you might have more than one protocol you want to set up, such as IPX/SPX, NetBEUI, and TCP/IP. The NetBEUI protocol is the default protocol Windows 95 uses for peer-to-peer networking, as well as Windows NT's client/server networks.
The following steps show you how to set up a protocol for your Windows 95 client.
2. Double-click the Protocol option in the Select Network Component Type dialog box. Click Add.
3. In the Select Network Protocol dialog box, select Microsoft from the Manufacturers list and the protocol you want to install from the Network Protocols list. In this example, the NetBEUI protocol is selected (see Figure 33.6).
NetBEUI, TCP/IP, and IPX/SPX are common protocols to select.
The protocol is displayed in the Network Properties dialog box. You now should have the following components installed: the client (Client for Microsoft Networks), an adapter, and protocol(s).
Now you're ready to configure your Windows 95 client to work with the Windows NT 4.0 network.
Before you can connect to a Windows NT server or other Windows 95 workstation on the network, you need to configure the Client for Microsoft Networks components. Items you need to configure include the following:
The primary network logon selections enable you to choose the default network you log on to when starting the Windows 95 client. In this case, you want to use the Client for Microsoft Networks option, which is located on the Primary Network Logon drop-down list in the Network Properties dialog box. When you use this option, a logon screen appears when you start up Windows 95, requesting username and password information from the user.
NOTE: Use the Windows Logon option on the Primary Network Logon drop-down list when you want the workstation to boot into Windows without logging on to the network. When the user attempts to access network resources, such as files or printers, the user is then prompted to enter username and password information.
The computer identification information is located on the Identification tab (see Figure 33.7). You need to fill in identification information for that Windows 95 client so it can be found on the network. Each computer must have a unique computer name and can be part of a defined workgroup. The following list explains each field to fill in:
Fill in the Windows 95 workstation's computer name, workgroup name, and optional computer description.
NOTE: A domain is a collection of computers on the network in which the security of the computers is controlled by the Windows NT 4.0 server. By itself, Windows 95 cannot set up a domain; you must connect to a Windows NT 4.0 computer. On the Windows NT 4.0 server, information such as passwords and user and group information is stored for central access to all computers on the network. This way users can roam between different client machines but still access custom user profiles.
After you fill in the Identification tab, click the Configuration tab to set up domain information for the client. To do this, click the Client for Microsoft Networks option and click the Properties button. The Client for Microsoft Networks Properties page appears. On this page, you set up logon validation for the Windows NT domain for this Windows 95 client. You also set up the way you want this client to log on to the domain. A filled-in page is shown in Figure 33.8. Here are the choices:
Use the Client for Microsoft Networks Properties page to fill in the domain name and whether or not you want to use persistent reconnections.
You read earlier that you can take advantage of Windows 95's peer-to-peer networking features even if you're running a client/server NOS such as Windows NT 4.0 Server. The following resources can be shared on the network:
To set up peer resource sharing:
2. Select the Client for Microsoft Networks option in the components list.
3. Click File and Print Sharing to display the File and Print Sharing dialog box (see Figure 33.9).
Many networks combine client/server resources with peer-to-peer capabilities, such as file and print sharing in Windows 95.
5. Close the dialog box and the Network Properties page. You must restart the computer for the changes to take effect.
You now can access file and printer resources across the network.
Windows 95 offers several customizable features to the user, including wallpaper files, screen savers, desktop preferences, and application settings. Everyone can customize Windows 95 to work and look best for them. Historically, the problem with setting user-specific preferences has been that as users move from one machine to another, the settings did not follow them. With Windows 95, you can set up user profiles that save configuration settings to use on other machines. The user profile is stored in the user's WINDOWS\PROFILES\ subfolder on the network server.
User profiles have several components:
TIP: One way user profiles are optimized is to include specific applications, documents, or files that launch automatically depending on the user who logs on.
A profile is created for the first time after the user or system administrator enables the User Profiles feature in the Password Properties sheet in Control Panel. To enable user profiles, use the following steps:
2. Click the Users can customize their preferences... option to activate the User Profile Settings options on the bottom half of the User Profiles tab.
3. Click the options under the User Profile Settings to tell the Windows 95 workstation what to include in each profile, as in the following option list:
Use the User Profiles tab to activate user profile capabilities in Windows 95.
5. Shut down and restart Windows 95.
When the system boots, you're asked to log on by using a username and password. If no password is set for this user, create and confirm one now.
NOTE: A nice feature for network administrators to set up is mandatory user profiles. Mandatory user profiles (named USER.MAN) are profiles the administrator creates that users on the network cannot modify. When a user logs on to the network, the USER.MAN file rather than the USER.DAT file is used. USER.MAN (the MAN stands for mandatory) contains settings that are used every time the user logs on to the network, regardless of any changes the user made the last time he or she used Windows 95. Users cannot save desktop or environment changes to the USER.MAN file. Only the administrator has rights to do so.Creating a USER.MAN file is relatively easy. Enable user profiles in Windows 95 and customize the desktop to the way you want it for all users who will be assigned the mandatory profile. For each user, copy this new USER.DAT file (it's still a DAT file at this point) into the user's home directory on the Windows NT 4.0 server. To finish, rename USER.DAT to USER.MAN in each user's home directory. Reboot Windows 95 and log on for the mandatory profile to be activated.
To set up roving users on your network, you need to perform some specific steps. Use the following steps for setting up Windows NT after you've enabled user profiles on all the attached Windows 95 computers.
2. In the Primary Network Logon list, make sure Client for Microsoft Networks is selected.
3. Switch to the Windows NT 4.0 Server computer and ensure the roving user is set up and has an assigned home directory. The path for this is \\server_name\home_ directory.
4. Use the NET TIME command to synchronize the clocks of all computers on the network. Here's the syntax:
NET TIME \\computer_name | /WORKGROUP:workgroup_name /SET /YES
The user profiles are automatically stored on the Windows NT 4.0 server in the appropriate home directories when the users log off the server.
System policies are files that establish configurations (stored in the Windows 95 Registry) on a computer when a user logs on to the network. System policies can be applied to users, groups of users, or specific computers. You can use system policies to customize the desktop, limit the number of Control Panel applets a user can use, configure network settings, and other actions. Administrators can set, change, and maintain these settings for each entity on the network. You can control the type of environment and rights a user has by combining policies assigned to a certain user, the machine he or she is logged on to, and any groups to which the users belongs.
You use the System Policy Editor to create system policy templates, which are then placed on the network to be automatically downloaded to the computer when a user logs on. You can find the System Policy Editor on the Windows 95 CD in the \ADMIN\ APPTOOLS\POLEDIT directory. Microsoft provides predefined policies you can choose from to create your own system policies, but you have the option of creating your own customized policies to fit specific needs.
Two types of files are used when you create policies: ADM and POL files. ADM files are template files that establish the scope of administrative polices. POL files enforce the policies you create. Each type is explained in the following list:
TIP: System polices overwrite USER.DAT Registry settings; therefore, POL files take precedence over a user's profile. Remember this when you decide to create user profiles or system policies.
NOTE: After you create the POL file, you need to provide a pointer to its new location. You can do this by adding an entry in the default location and changing the Registry so that it looks in the correct location. You can do this by editing the following Windows 95 Registry subkey:HKEY_LOCAL_MACHINE\Network\Logon
To use the System Policy Editor, install it from the Windows 95 CD. You must install the ADMIN.ADM, POLEDIT.EXE, and POLEDIT.INF filesWhen you install these files, ADMIN.ADM is placed. When you install these files, ADMIN.ADM is placed in the INF folder below your Windows 95 folder. This file provides the system policy templates for you to use in the System Policy Editor.
After you install these system policy files, you can install the GROUPPOL.INF files, enabling you to create group system polices. When you do this, GROUPPOL.DLL is placed in the \WINDOWS\SYSTEM folder. For each client on your network, you must install this file in that directory. Group policies can be created only for Windows NT and NetWare networks that have existing groups set up. You cannot, for example, use the System Policy Editor to create a new group for either of these networks. The System Policy Editor is placed on the Start menu under Programs, Accessories, System Tools folders. Figure 33.11 shows you what the System Policy Editor looks like.
This figure shows the System Policy Editor with the local computer properties open.
Compared to Windows NT 4.0 Server, Windows 95 has very little security. In fact, the lack of security in Windows 95 makes many corporate and large installations wary of using Windows 95 for housing vital information and resources. If you need a highly secure operating system for your organization, Windows NT 4.0 Server and Workstation are better suited to meet those needs.
Windows 95 provides share-level and user-level security on the network.
Share-level security is set up by requiring passwords for each shared resource on the network. This means that if a workstation has a shared CD-ROM drive attached to it, you can assign a password to that CD-ROM drive, requiring all those who want to access it via the network to enter the password to use it. Likewise, you can assign the same or a different password to another shared resource on the same workstation (such as a printer).
Each Windows 95 workstation maintains the list of passwords for its shared resources, making it difficult for administrators to control the types of resources being configured with share-level security. You might, for example, want the root drive (the C:\ drive) on each workstation to have share-level security set up. If you have relatively few workstations, walking around to each computer and setting this up is not a burden. However, for large installations, it can be a huge time sink. Also, you lack control over users at the workstation disabling the share-level access.
To set up share-level security, use the following steps:
2. Double-click the Network option in Control Panel. In the Network Properties dialog box, select the Access Control tab.
3. Select the Share-level access control option (see Figure 33.12)--this is the default setting--and click OK.
You should use share-level security only when all you require is a password for someone to access a shared resource.
Now you can assign a password to any shared resource, such as a printer, as shown in the following steps:
2. Click the Shared As option, which activates the rest of the Sharing tab (see Figure 33.13).
The Sharing tab enables you to add share-level security to a resource.
The information in the Comment field appears in the Comment column in the Network Neighborhood browse window. It can be used to provide additional information about a shared resource, such as displaying times and days when the resource is available (remember that a shared resource on a workstation is probably disconnected from the network each evening when the main user goes home).
4. Click OK to save your settings.
User-level security uses a list of users and groups that can access a resource and then has the password and usernames authenticated by a security provider whenever a user requests to use a resource. For user-level security, you must be running a Windows NT domain (or NetWare server) and have user groups set up on the domain. On the Windows NT server, you maintain the list of user accounts and passwords assigned to each resource. This eliminates the need for each Windows 95 workstation to maintain a separate list.
To set up user-level security on Windows 95, use the following steps:
2. Double-click the Network option in Control Panel. In the Network Properties dialog box, select the Access Control tab.
3. Select the User-level access control.
4. Enter the name of the domain or Windows NT workstation where the user accounts are stored.
5. Click OK. If you've set up share-level security on any resources, this is deleted because you're changing to user-level security. Reboot your computer to make the changes take effect.
After your computer reboots, you can set up user-level security on shared resources:
2. Click the Shared As button and insert a name for the resource. You also can add a comment to the Comment field. Click Add. The Add Users dialog box displays (see Figure 33.14).
The Add Users dialog box enables you to assign users and groups access rights to resources.
4. Click OK to return to the properties sheet of the shared resource with
names and access rights displayed on the Sharing tab.
If you've included any users or groups in the Custom access rights area, the Change
Access Rights dialog box appears (see Figure 33.15). In this box, you can select
custom access rights, as explained in Step 3. Select the access rights you want to
give that user, and click OK to return to the shared resource properties sheet.
Set the user's rights by using the Change Access Rights dialog box.
6. Click OK to save your changes.
Windows 95 stores passwords in a password list file, which has the PWL extension. The PWL file contains passwords for workstations that use Windows 95 share-level security, password-protected applications that use the Master Password API, NetWare servers, and Windows NT computers not in a domain.
The password cache is activated when you first log on to Windows 95. If you bypass that initial logon screen by clicking Cancel, you need to fill in passwords for the resources as you access them. You can have the password cache save your password the first time you access a password-protected resource. Then, when you return to that resource, you don't have to remember the password for that resource. This eliminates the problem of users forgetting passwords for resources to which they need access. When you install Windows 95, password caching is enabled, but you need to select the Save This Password in Your Password List option when you first access a password-protected resource to have the password saved in the cache list.
NOTE: The Windows 95 password cache received a lot of attention at the end of 1995 when an algorithm was available on the Internet that enabled users to read PWL files and obtain password lists. Microsoft made available a patch that made cracking PWL files 296 times tougher than the original algorithm. You can obtain this patch by installing the Windows 95 Service Pack 1, available on the Microsoft World Wide Web site at the following URL:
http://www.microsoft.com/windows/
One way to add more security to your Windows 95 workstations is to use some of the system policy settings devoted to security. In Passwords policies, you can set the following:
You also can use the System Policy Editor to disable password caching:
2. Choose Local Computer Properties, Network, Passwords.
3. Select the Disable Password Caching option.
4. Save your settings, and exit the System Policy Editor.
© Copyright, Macmillan Computer Publishing. All rights reserved.