Google Mail Calendar Documents Reader Web more »
Recently Visited Groups | Help | Sign in
Google Groups Home
Problem with DNS Lookup behind XP Firewall
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  6 messages - Expand all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Follow-up To:
Add Cc | Add Follow-up to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers that you hear
 
Richard Tubb  
View profile   Translate to Translated (View Original)
 More options 4 Jan 2005, 13:26
Newsgroups: microsoft.public.windowsxp.work_remotely
From: "Richard Tubb" <rich...@netlinktrading.co.uk>
Date: Tue, 4 Jan 2005 13:26:26 -0000
Local: Tues 4 Jan 2005 13:26
Subject: Problem with DNS Lookup behind XP Firewall
Hi,

We've recently rolled out Windows XP SP2 to our remote users and have
enabled the XP Firewall on all network connections, including the VPN
connection to the main office.

We are now experiencing problems wherein users can't access PC's on the
remote domain by name, only by IP address, when connected via VPN. Turning
off the XP Firewall for the VPN immediately solves this problem - so the
issue appears to be with DNS lookup through the XP Firewall.

Is there a way to add an exception to the firewall to allow these lookups?
File and Print Sharing is enabled on all Firewall entries and incoming ICMP
exceptions are enabled.

I'm a little baffled as why this setup doesn't work, but would be grateful
for any advice from somebody with more experience of Firewalls! Am I wrong
to try and firewall the VPN connection in the first place?

Regards,

Richard Tubb.
www.netlinktrading.co.uk


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message, you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Sooner Al  
View profile   Translate to Translated (View Original)
 More options 4 Jan 2005, 13:37
Newsgroups: microsoft.public.windowsxp.work_remotely
From: "Sooner Al" <Soone...@somewhere.net.invalid>
Date: Tue, 4 Jan 2005 07:37:08 -0600
Local: Tues 4 Jan 2005 13:37
Subject: Re: Problem with DNS Lookup behind XP Firewall
My solution, on a small SOHO LAN, is to use a host file on my remote PC to map IP addresses to a
name. Note this is a work group environment. Hopefully one of the other MVPs or another
knowledgeable person can be of further assistance...

--
    Al Jarvi (MS-MVP Windows Networking)

Please post *ALL* questions and replies to the news group for the mutual benefit of all of us...
The MS-MVP Program - http://mvp.support.microsoft.com
This posting is provided "AS IS" with no warranties, and confers no rights...

"Richard Tubb" <rich...@netlinktrading.co.uk> wrote in message

news:OSIqBEm8EHA.2568@TK2MSFTNGP10.phx.gbl...


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message, you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Robin Walker  
View profile   Translate to Translated (View Original)
 More options 4 Jan 2005, 18:09
Newsgroups: microsoft.public.windowsxp.work_remotely
From: "Robin Walker" <r...@cam.ac.uk>
Date: Tue, 4 Jan 2005 18:09:19 -0000
Local: Tues 4 Jan 2005 18:09
Subject: Re: Problem with DNS Lookup behind XP Firewall

Richard Tubb wrote:
> We've recently rolled out Windows XP SP2 to our remote users and have
> enabled the XP Firewall on all network connections, including the VPN
> connection to the main office.

> We are now experiencing problems wherein users can't access PC's on
> the remote domain by name, only by IP address, when connected via
> VPN. Turning off the XP Firewall for the VPN immediately solves this
> problem - so the issue appears to be with DNS lookup through the XP
> Firewall.

My guess is that this is not a DNS problem, but a NetBIOS one.  DNS lookups
are not blocked by Windows Firewall.

Maybe you should check that the "scope" of the File & Print Sharing
Exception in Windows Firewall includes explicitly:
(a) the subnets in use in your office LAN;
(b) the subnet ranges you allocate for VPN connections.

Do not rely on the default "My network (subnet) only" scope.

--
Robin Walker
r...@cam.ac.uk


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message, you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Chris Priede  
View profile   Translate to Translated (View Original)
 More options 4 Jan 2005, 21:31
Newsgroups: microsoft.public.windowsxp.work_remotely
From: "Chris Priede" <pri...@panix.com>
Date: Tue, 4 Jan 2005 16:31:43 -0500
Local: Tues 4 Jan 2005 21:31
Subject: Re: Problem with DNS Lookup behind XP Firewall

Richard Tubb wrote:
> I'm a little baffled as why this setup doesn't work...

I agree with Robin's explanation, but think you should try to fix the VPN
first.

If you investigate, you will likely find that name resolution through DNS
never worked -- because your VPN connection doesn't push the internal DNS
servers and / or the correct DNS suffix to the clients.  When it worked, the
resolution was working through NetBIOS broadcasts.

Getting DNS to work over the VPN would be preferable for the long term.  If
not possible, Robin's suggestions should restore the service as well.

--
Chris Priede (pri...@panix.com)


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message, you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
serge calderara  
View profile   Translate to Translated (View Original)
 More options 5 Jan 2005, 07:43
Newsgroups: microsoft.public.windowsxp.work_remotely
From: serge calderara <sergecalder...@discussions.microsoft.com>
Date: Tue, 4 Jan 2005 23:43:02 -0800
Local: Wed 5 Jan 2005 07:43
Subject: RE: Problem with DNS Lookup behind XP Firewall
hi richard

XP firewall should not be activatre on VPN connexion, it interfears with
sharing objects. This is what microsft is higly recommanding.

Go on technet and search for ICF and VPN

Hope it helps

Serge
MCP


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message, you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Rebecca Chen [MSFT]  
View profile   Translate to Translated (View Original)
 More options 5 Jan 2005, 10:59
Newsgroups: microsoft.public.windowsxp.work_remotely
From: v-r...@online.microsoft.com (Rebecca Chen [MSFT])
Date: Wed, 05 Jan 2005 10:59:38 GMT
Local: Wed 5 Jan 2005 10:59
Subject: RE: Problem with DNS Lookup behind XP Firewall
Yes.

You should not enable Internet Connection Firewall on virtual private
networking (VPN) connections, which are typically used to securely log in
to a corporate network. You should not enable ICF on client computers that
are part of a large company or school network with a server-client
structure. ICF will interfere with file and printer sharing in these
scenarios.

This is detailed in the following article:

Use the Internet Connection Firewall
http://www.microsoft.com/windowsxp/using/networking/learnmore/icf.mspx

Any update, let us get in touch!

Best regards,

Rebecca Chen

MCSE2000 MCDBA CCNA

Microsoft Online Partner Support
Get Secure! - www.microsoft.com/security

=====================================================

When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.

=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message, you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2009 Google