Computing.Net > Forums > Networking > WinXP SP2 ICF blocked ICS DNS/clien

WinXP SP2 ICF blocked ICS DNS/clien

Reply to Message Icon

Original Message
Name: Loopdemack
Date: December 17, 2004 at 23:24:07 Pacific
Subject: WinXP SP2 ICF blocked ICS DNS/clien
OS: windows 2000 pro SP4
CPU/Ram: Intel P4 2.4c
Comment:

Hello I got problem with ICS. Here is my spec:
ICS server is Windows XP with SP2 with ICF ON.
ICS Client is Windows 2000 Pro SP4
It worked for several months but suddenly it stopped, mainly problem is in DNS because ICF is blocking something.
I cant browse from client machine any more in http because it start and find destination but cant return DNS data to client machine, when I turn off ICF, DNS is working again and I can surf on client machine.
With ICF on I can use ftp and other services.
I tried static configuration and I tried automatic DHCP configuration for ICS and its same.

I am receiving one error in event on Windows XP SP2:
Event Type: Error
Event Source: ipnathlp
Event Category: None
Event ID: 31008
Date: 12.18.04
Time: 12:08:48 AM
User: N/A
Computer: LONDON11-A56F4D
Description:
The DNS proxy agent was unable to read the local list of name-resolution servers from the registry. The data is the error code.
---

I tried with repair on network connection I tried to flush DNS on Windows 2000 and I tried to test netdiag under ICS Server connected to shared ppp here is results:

C:\Program Files\Support Tools>netdiag /test:winsock /v

Gathering IPX configuration information.
Querying status of the Netcard drivers... Passed
Testing Domain membership... Passed
Gathering NetBT configuration information.
Gathering Winsock information.

Tests complete.

Computer Name: LONDON11-A56F4D
DNS Host Name: london11-a56f4d
DNS Domain Name: (null)
System info : Windows 2000 Professional (Build 2600)
Processor : x86 Family 15 Model 2 Stepping 9, GenuineIntel
Hotfixes :
Installed? Name
Yes Q147222

Netcard queries test . . . . . . . : Passed

Information of Netcard drivers:
----------------
Description: RAS Async Adapter
Device: \DEVICE\{B26B0583-3F58-4ED6-8C1A-38276E77B766}

Media State: Connected
Device State: Connected
Connect Time: 02:58:14
Media Speed: 28 Kbps
Packets Sent: 0
Bytes Sent (Optional): 0
Packets Received: 0
Directed Pkts Recd (Optional): 0
Bytes Received (Optional): 0
Directed Bytes Recd (Optional): 0

[WARNING] The net card 'RAS Async Adapter' may not be working because it has not received any packets.
----------------
Description: 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX) #2 - Packet Scheduler Miniport
Device: \DEVICE\{AD817CB9-80F2-44DE-B0D1-1546C7AC9FDF}

Media State: Connected
Device State: Connected
Connect Time: 03:03:31
Media Speed: 100 Mbps
Packets Sent: 2834
Bytes Sent (Optional): 0
Packets Received: 1796
Directed Pkts Recd (Optional): 1545
Bytes Received (Optional): 0
Directed Bytes Recd (Optional): 0
----------------
Description: 3Com EtherLink 10/100 PCI For Complete PC Management NIC (3C905C-TX) #2
Device: \DEVICE\{E9AC1AFF-88BC-4163-858D-9C19F5D01217}

Media State: Connected

Device State: Connected
Connect Time: 03:03:31
Media Speed: 100 Mbps

Packets Sent: 2834
Bytes Sent (Optional): 0

Packets Received: 1796
Directed Pkts Recd (Optional): 1545
Bytes Received (Optional): 0
Directed Bytes Recd (Optional): 0
----------------
[PASS] - At least one netcard is in the 'Connected' state.

Per interface results:
Adapter : Local Area Connection 2
Adapter ID . . . . . . . . : {E9AC1AFF-88BC-4163-858D-9C19F5D01217}
Netcard queries test . . . : Passed

Adapter : {D6E50F8A-4993-4724-8F3F-DF69B385DB1F}
Adapter ID . . . . . . . . : {D6E50F8A-4993-4724-8F3F-DF69B385DB1F}

Netcard queries test . . . : Passed

Global results:

Domain membership test . . . . . . : Passed
Machine is a . . . . . . . . . : Standalone Workstation
Netbios Workgroup name . . . . : WORKGROUP
Dns domain name is not specified.
Dns forest name is not specified.
Domain Guid. . . . . . . . . . : {00000000-0000-0000-0000-000000000000}
Logon User . . . . . . . . . . : London11
Logon Domain . . . . . . . . . : LONDON11-A56F4D

NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{E9AC1AFF-88BC-4163-858D-9C19F5D01217}
1 NetBt transport currently configured.


Winsock test . . . . . . . . . . . : Passed
The number of protocols which have been reported : 16
Description: MSAFD Tcpip [TCP/IP]
Provider Version :2
Max message size : Stream Oriented
Description: MSAFD Tcpip [UDP/IP]
Provider Version :2
Description: RSVP UDP Service Provider
Provider Version :6
Description: RSVP TCP Service Provider
Provider Version :6
Max message size : Stream Oriented
Description: MSAFD NetBIOS [\Device\NetBT_Tcpip_{E9AC1AFF-88BC-4163-858D-9C19F5D01217}] SEQPACKET 5
Provider Version :2
Description: MSAFD NetBIOS [\Device\NetBT_Tcpip_{E9AC1AFF-88BC-4163-858D-9C19F5D01217}] DATAGRAM 5
Provider Version :2
Description: MSAFD NetBIOS [\Device\NetBT_Tcpip_{EDEFD001-5935-4B43-BFC5-D66F5C8C95AC}] SEQPACKET 0
Provider Version :2
Description: MSAFD NetBIOS [\Device\NetBT_Tcpip_{EDEFD001-5935-4B43-BFC5-D66F5C8C95AC}] DATAGRAM 0
Provider Version :2
Description: MSAFD NetBIOS [\Device\NetBT_Tcpip_{46BBF3D2-29FD-486E-B0F6-2B75B9935760}] SEQPACKET 1
Provider Version :2
Description: MSAFD NetBIOS [\Device\NetBT_Tcpip_{46BBF3D2-29FD-486E-B0F6-2B75B9935760}] DATAGRAM 1
Provider Version :2
Description: MSAFD NetBIOS [\Device\NetBT_Tcpip_{2F2641BA-C4EA-4314-A047-985266AA0416}] SEQPACKET 2
Provider Version :2
Description: MSAFD NetBIOS [\Device\NetBT_Tcpip_{2F2641BA-C4EA-4314-A047-985266AA0416}] DATAGRAM 2
Provider Version :2
Description: MSAFD NetBIOS [\Device\NetBT_Tcpip_{D3F234E2-926E-434D-ADE6-A9BE8DF70A41}] SEQPACKET 3
Provider Version :2
Description: MSAFD NetBIOS [\Device\NetBT_Tcpip_{D3F234E2-926E-434D-ADE6-A9BE8DF70A41}] DATAGRAM 3
Provider Version :2
Description: MSAFD NetBIOS [\Device\NetBT_Tcpip_{D6E50F8A-4993-4724-8F3F-DF69B385DB1F}] SEQPACKET 4
Provider Version :2
Description: MSAFD NetBIOS [\Device\NetBT_Tcpip_{D6E50F8A-4993-4724-8F3F-DF69B385DB1F}] DATAGRAM 4
Provider Version :2

Max UDP size : 65507 bytes


The command completed successfully

C:\Program Files\Support Tools>netdiag /test:winsock
.......
Computer Name: LONDON11-A56F4D
DNS Host Name: london11-a56f4d
System info : Windows 2000 Professional (Build 2600)
Processor : x86 Family 15 Model 2 Stepping 9, GenuineIntel
List of installed hotfixes :
Q147222

Netcard queries test . . . . . . . : Passed
[WARNING] The net card 'RAS Async Adapter' may not be working because it has not received any packets.

Per interface results:

Adapter : Local Area Connection 2

Netcard queries test . . . : Passed

Adapter : {D6E50F8A-4993-4724-8F3F-DF69B385DB1F}

Netcard queries test . . . : Passed

Global results:

Domain membership test . . . . . . : Passed
Dns domain name is not specified.
Dns forest name is not specified.

NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{E9AC1AFF-88BC-4163-858D-9C19F5D01217}
1 NetBt transport currently configured.

Winsock test . . . . . . . . . . . : Passed

The command completed successfully

C:\Program Files\Support Tools>netdiag /test:dns

.......

Computer Name: LONDON11-A56F4D
DNS Host Name: london11-a56f4d
System info : Windows 2000 Professional (Build 2600)
Processor : x86 Family 15 Model 2 Stepping 9, GenuineIntel
List of installed hotfixes :
Q147222

Netcard queries test . . . . . . . : Passed
[WARNING] The net card 'RAS Async Adapter' may not be working because it has not received any packets.

Per interface results:

Adapter : Local Area Connection 2

Netcard queries test . . . : Passed

Adapter : {D6E50F8A-4993-4724-8F3F-DF69B385DB1F}

Netcard queries test . . . : Passed

Global results:

Domain membership test . . . . . . : Passed
Dns domain name is not specified.
Dns forest name is not specified.

NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{E9AC1AFF-88BC-4163-858D-9C19F5D01217}
1 NetBt transport currently configured.

DNS test . . . . . . . . . . . . . : Passed

The command completed successfully

C:\Program Files\Support Tools>netdiag
.............................
Computer Name: LONDON11-A56F4D
DNS Host Name: london11-a56f4d
System info : Windows 2000 Professional (Build 2600)
Processor : x86 Family 15 Model 2 Stepping 9, GenuineIntel
List of installed hotfixes :
Q147222

Netcard queries test . . . . . . . : Passed
[WARNING] The net card 'RAS Async Adapter' may not be working because it has not received any packets.

Per interface results:

Adapter : Local Area Connection 2

Netcard queries test . . . : Passed

Host Name. . . . . . . . . : london11-a56f4d
IP Address . . . . . . . . : 192.168.0.1
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . :
Dns Servers. . . . . . . . :
AutoConfiguration results. . . . . . : Passed
Default gateway test . . . : Skipped
[WARNING] No gateways defined for this adapter.

NetBT name test. . . . . . : Passed
[WARNING] At least one of the <00> 'WorkStation Service', <03> 'Messenger Service', <20> 'WINS' names is mis

WINS service test. . . . . : Skipped
There are no WINS servers configured for this interface.

Adapter : {D6E50F8A-4993-4724-8F3F-DF69B385DB1F}

Netcard queries test . . . : Passed

Host Name. . . . . . . . . : london11-a56f4d
IP Address . . . . . . . . : 195.178.32.58
Subnet Mask. . . . . . . . : 255.255.255.255
Default Gateway. . . . . . : 195.178.32.58
NetBIOS over Tcpip . . . . : Disabled
Dns Servers. . . . . . . . : 195.178.32.2
195.178.32.19

AutoConfiguration results. . . . . . : Passed
Default gateway test . . . : Passed
NetBT name test. . . . . . : Skipped
NetBT is disabled on this interface. [Test skipped]
WINS service test. . . . . : Skipped
NetBT is disable on this interface. [Test skipped].

Global results:

Domain membership test . . . . . . : Passed
Dns domain name is not specified.
Dns forest name is not specified.

NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{E9AC1AFF-88BC-4163-858D-9C19F5D01217}
1 NetBt transport currently configured.

Autonet address test . . . . . . . : Passed
IP loopback ping test. . . . . . . : Passed
Default gateway test . . . . . . . : Passed
NetBT name test. . . . . . . . . . : Passed
[WARNING] You don't have a single interface with the <00> 'WorkStation Service', <03> 'Messenger Service', <20>

Winsock test . . . . . . . . . . . : Passed
DNS test . . . . . . . . . . . . . : Passed

Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{E9AC1AFF-88BC-4163-858D-9C19F5D01217}
The redir is bound to 1 NetBt transport.

List of NetBt transports currently bound to the browser
NetBT_Tcpip_{E9AC1AFF-88BC-4163-858D-9C19F5D01217}
The browser is bound to 1 NetBt transport.

DC discovery test. . . . . . . . . : Skipped
DC list test . . . . . . . . . . . : Skipped
Trust relationship test. . . . . . : Skipped
Kerberos test. . . . . . . . . . . : Skipped
LDAP test. . . . . . . . . . . . . : Skipped
Bindings test. . . . . . . . . . . : Passed

WAN configuration test . . . . . . : Passed
Entry Name: Telekom
Device Type: Framing protocol : PPP
LCP Extensions : Enabled
Software Compression : Enabled
Network protocols :
TCP/IP
IP Address : Server Assigned
Name Server: Server Assigned
IP Header compression : Enabled
Use default gateway on remote network : Enabled

Connection Statistics:
Bytes Transmitted : 26547
Bytes Received : 60610
Frames Transmitted : 221
Frames Received : 255
CRC Errors : 255
Timeout Errors : 0
Alignment Errors : 0
H/W Overrun Errors : 0
Framing Errors : 0
Buffer Overrun Errors : 0
Compression Ratio In : 3
Compression Ratio Out : 6
Baud Rate ( Bps ) : 64000
Connection Duration : 324344
Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Passed
Service status is: Started
Service startup is: Automatic
IPSec service is available, but no policy is assigned or active
Note: run "ipseccmd /?" for more detailed information

The command completed successfully

-----------


Maybe its something in policy (which I didn't touch at all) or their is some setting in ICF for connections like to put some protocols without protection, I didn't had this problems with XP SP1.

I need help!.


Report Offensive Message For Removal


Response Number 1
Name: Dave02
Date: December 18, 2004 at 00:06:45 Pacific
Reply: (edit)

You may want to see if there is a driver update for this network adapter. It appears that it is either not connected or not working.

Description: RAS Async Adapter
Device: \DEVICE\{B26B0583-3F58-4ED6-8C1A-38276E77B766}

Media State: Connected
Device State: Connected
Connect Time: 02:58:14
Media Speed: 28 Kbps
Packets Sent: 0
Bytes Sent (Optional): 0
Packets Received: 0
Directed Pkts Recd (Optional): 0
Bytes Received (Optional): 0
Directed Bytes Recd (Optional): 0

[WARNING] The net card 'RAS Async Adapter' may not be working because it has not received any packets.


Report Offensive Follow Up For Removal

Response Number 2
Name: Loopdemack
Date: December 18, 2004 at 02:04:11 Pacific
Reply: (edit)

Thank you on fast response, but this RAS device is ISDN MODEM connection that was shared in ICS, on ICS Server this connection is perfect and I can surf and I can do every operation, on the client machine if I shutdown completely ICF(Internet Connection Firewall integrated with in Windows XP SP2) on ICS server machine I can surf on Ics client machine, if I start ICF it will block again ICS web surfing on Client machine, explorer start to find website like web site found, waiting for reply. The moment I OFF ICF client work, the moment I on web stop again.
I tried to exclude In ICF, Local network connection which is used for ICS it didn't help.


Report Offensive Follow Up For Removal

Response Number 3
Name: Dave02
Date: December 19, 2004 at 21:13:19 Pacific
Reply: (edit)

Allow local adresses on the ICS server PC's ICF. Put in the entry "192.168.0.*"

Hope this helps


Report Offensive Follow Up For Removal

Response Number 4
Name: Loopdemack
Date: December 19, 2004 at 23:51:36 Pacific
Reply: (edit)

I tried that already and if you remember, this ICF firewall is integrated in Windows XP SP2 and you don't have only scope to enter, you must enter combination of scope and port number(udf or tcp). But thank you very much on your effort.


Report Offensive Follow Up For Removal







Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: WinXP SP2 ICF blocked ICS DNS/clien

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software




Have you ever used OpenOffice?

Yes, as my main suite.
Yes, occationally.
Yes, but only once.
No, never.


View Results

Poll Finishes In 5 Days.
Discuss in The Lounge