> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Scanning DFS

> Capturing DFS namespaces with servers, folder targets, access rights and replication—as the basis of a permission analysis.

The *DFS* scan module captures DFS servers, namespaces, folder targets and
their share permissions. It requires a connected
[gateway](/docs/en/scan/gateway-install).

## Captured data

The scan creates assets of these two types:

| Type | Groups |
| - | - |
| *DFS Domain* | Namespaces (namespaces, DFS servers, namespace folders, folder targets, access rights) and Replication (replication groups, memberships, connections, replicated folders) |
| *DFS Standalone* | Namespaces (namespaces, namespace folders, folder targets, access rights) |

How the detail pages of the types are structured is described in
[Directory and Network Services](/docs/en/assets/directory-services).

## Setting up the job

The wizard follows the standard path *Basics* › *Targets* › *Schedule* ›
*Summary*—see [Creating a Scan Job](/docs/en/scan/create-inventory). The
*Targets* step is what sets this module apart.

Each row carries the columns *Server Name* and *Credentials*. *Server Name*
takes one namespace server per row, as an address or hostname; the column does
not accept an address range.

*Search DFS Servers* fills in the servers from Active Directory instead: the
dialog asks for the *Domain* and credentials and adds the DFS servers it finds
as rows.

<Note>
  *Search DFS Servers* finds domain-based DFS servers only if the Namespace
  Server role is installed on them. Enter standalone namespace servers as rows
  by hand.
</Note>

The *Credentials* column may stay empty. The scan then runs under the
gateway's service account, and that account needs the rights listed under
[Permissions](#permissions). An entry in *Credentials for all targets* applies
to every row without an assignment of its own.

## Prerequisites

The scan connects to the DFS servers over WMI and to a domain controller over
LDAP.

### Ports and protocols

| Protocol | Port | Transport |
| - | - | - |
| NetBIOS Name Service, NetBIOS Datagram Service | 137, 138 | UDP |
| NetBIOS Session Service, SMB / CIFS over TCP | 139, 445 | TCP |
| RPC, dynamic ports | 49152–65535 | TCP/UDP |
| LDAP | 389 | TCP/UDP |

### Permissions

* The account is a domain user, entered as `DOMAIN\user` or
  `user@domain.local`.
* It is a member of the local Administrators group on the namespace servers.
* It is a member of the local Administrators group on the servers that provide
  resources for the DFS.

### Network requirements

* The firewall allows the ports above.
* PowerShell can run on the DFS servers.
* User Account Control (UAC) is set up for the account's remote access.

If the folder targets are on servers other than the namespaces, access from the
gateway through the namespace server to those servers is a double hop, which
Windows does not allow. In that case, scan the DFS directly on the namespace
servers with the `Discovery-DFS.exe` scan script—see
[Scanning by Script](/docs/en/scan/scan-by-script). For DFS this is the recommended
way.

## Common issues

| Symptom | Cause | Resolution |
| - | - | - |
| The scan is incomplete and SMB access rights are missing, despite full administrator rights. | The folder targets are not on the namespace servers; access is a double hop. | Scan by script on the namespace servers, or run a gateway on the namespace server. |
| After a scan through the gateway, fields stay empty: *Administrative Access* on the namespace; for replication, the status of replication groups, memberships, connections and replicated folders, *Cross-File RDC Status*, and the publishing status of replicated folders. | This information can only be read locally on the server. | Scan by script. |

## Related

After it is created, the job appears among the jobs; how you watch and adjust
it is in [Managing Jobs](/docs/en/scan/manage-jobs). How you provide and run the scan
scripts and read in their results is in
[Scanning by Script](/docs/en/scan/scan-by-script).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.