Click here to get back home

Traffic between two networking cards, HELP

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Traffic between two networking cards, HELP Ray 10-15-2005
Posted by Ray on October 15, 2005, 7:43 pm
Please log in for more thread options
Hi there,

I posted something about a problem of a server having two cards a couple of
days before. That is, I have two subnets (xxx.xxx.19.0/24 and
xxx.xxx.44.0/24) and both of them have Internet connections, my server has
two ethernet cards (xxx.xxx.19.210 and xxx.xxx.44.92) on both subnets, the
configuration of the one on xxx.xxx.19.0/24 has a gateway (xxx.xxx.19.254),
that of the other doesn't. Currently, clients on xxx.xxx.19.0/24 cannot talk
with xxx.xxx.44.92 and clients on xxx.xxx.44.0/24 cannot talk with
xxx.xxx.19.210 either. (Anytime, xxx.xxx.19.0/24 can talk with
xxx.xxx.19.210 and xxx.xxx.44.0/24 can talk with xxx.xxx.44.92 also)

My server is running Windows 2003 server, I set up Windows 2k3 SP1 firewall
on it. If I turn the firewall off, the above problem disappears; if I turn
it on, I have the problem. In fact, we were using VisNetic Deerfield
Firewall, everything was all right. I removed it and change to SP1 firewall
now.

To Wendel,
I found the problem was affected by Win2k3 SP1 firewall, for example,
packets from computers on xxx.xxx.19.0/24 can reach xxx.xxx.44.92 but
xxx.xxx.44.92 cannot reply when the firewall is on, xxx.xxx.44.92 cannot
talk with xxx.xxx.19.210! Anyway, thanks for your consideration before.

Ray




Posted by S. Pidgorny on October 16, 2005, 5:42 pm
Please log in for more thread options
To be quite frank, I don't believe that Windows firewall was designed with a
view to be used as a router/gateway firewall, and is just a personal
firewall. That said, there might be a fix, but it won't surprise me if
you're dealing with a software limitation

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

> Hi there,
>
> I posted something about a problem of a server having two cards a couple
of
> days before. That is, I have two subnets (xxx.xxx.19.0/24 and
> xxx.xxx.44.0/24) and both of them have Internet connections, my server has
> two ethernet cards (xxx.xxx.19.210 and xxx.xxx.44.92) on both subnets, the
> configuration of the one on xxx.xxx.19.0/24 has a gateway
(xxx.xxx.19.254),
> that of the other doesn't. Currently, clients on xxx.xxx.19.0/24 cannot
talk
> with xxx.xxx.44.92 and clients on xxx.xxx.44.0/24 cannot talk with
> xxx.xxx.19.210 either. (Anytime, xxx.xxx.19.0/24 can talk with
> xxx.xxx.19.210 and xxx.xxx.44.0/24 can talk with xxx.xxx.44.92 also)
>
> My server is running Windows 2003 server, I set up Windows 2k3 SP1
firewall
> on it. If I turn the firewall off, the above problem disappears; if I turn
> it on, I have the problem. In fact, we were using VisNetic Deerfield
> Firewall, everything was all right. I removed it and change to SP1
firewall
> now.
>
> To Wendel,
> I found the problem was affected by Win2k3 SP1 firewall, for example,
> packets from computers on xxx.xxx.19.0/24 can reach xxx.xxx.44.92 but
> xxx.xxx.44.92 cannot reply when the firewall is on, xxx.xxx.44.92 cannot
> talk with xxx.xxx.19.210! Anyway, thanks for your consideration before.
>
> Ray
>
>




Posted by Ray on October 16, 2005, 9:18 am
Please log in for more thread options
Svyatoslav,

Thank you for your response. I posted my concern about Windows Firewall here
two week ago, Roger said Win2k3 firewall was totally different with that of
WinXP, and don't need to buy other firewall software. No offense, it seems
there is some limitation on Windows Firewall, anyway, I've disenable one
card and everything is fine now.

Thanks to all that helped me on the networking and firewall problem.

Ray

> To be quite frank, I don't believe that Windows firewall was designed with
> a
> view to be used as a router/gateway firewall, and is just a personal
> firewall. That said, there might be a fix, but it won't surprise me if
> you're dealing with a software limitation
>
> --
> Svyatoslav Pidgorny, MS MVP - Security, MCSE
> -= F1 is the key =-
>
>> Hi there,
>>
>> I posted something about a problem of a server having two cards a couple
> of
>> days before. That is, I have two subnets (xxx.xxx.19.0/24 and
>> xxx.xxx.44.0/24) and both of them have Internet connections, my server
>> has
>> two ethernet cards (xxx.xxx.19.210 and xxx.xxx.44.92) on both subnets,
>> the
>> configuration of the one on xxx.xxx.19.0/24 has a gateway
> (xxx.xxx.19.254),
>> that of the other doesn't. Currently, clients on xxx.xxx.19.0/24 cannot
> talk
>> with xxx.xxx.44.92 and clients on xxx.xxx.44.0/24 cannot talk with
>> xxx.xxx.19.210 either. (Anytime, xxx.xxx.19.0/24 can talk with
>> xxx.xxx.19.210 and xxx.xxx.44.0/24 can talk with xxx.xxx.44.92 also)
>>
>> My server is running Windows 2003 server, I set up Windows 2k3 SP1
> firewall
>> on it. If I turn the firewall off, the above problem disappears; if I
>> turn
>> it on, I have the problem. In fact, we were using VisNetic Deerfield
>> Firewall, everything was all right. I removed it and change to SP1
> firewall
>> now.
>>
>> To Wendel,
>> I found the problem was affected by Win2k3 SP1 firewall, for example,
>> packets from computers on xxx.xxx.19.0/24 can reach xxx.xxx.44.92 but
>> xxx.xxx.44.92 cannot reply when the firewall is on, xxx.xxx.44.92 cannot
>> talk with xxx.xxx.19.210! Anyway, thanks for your consideration before.
>>
>> Ray
>>
>>
>
>




Posted by Wendel Hamiltonùg§uéGjh¥¶‰ÝŠÇ. on October 17, 2005, 7:20 am
Please log in for more thread options
Ray,
I believe that the windows firewall will do what you want but it must be
configured in RRAS. Here is an article supporting my statement.
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/ServerHelp/7c9a082b-0c5c-49d1-a1a8-5bfccc0eeb5c.mspx
The firewall can run in 2 modes Basic and Internet connection Sharing (NAT)
You need to ensure that it is running as a Basic firewall.


"Ray" wrote:

> Svyatoslav,
>
> Thank you for your response. I posted my concern about Windows Firewall here
> two week ago, Roger said Win2k3 firewall was totally different with that of
> WinXP, and don't need to buy other firewall software. No offense, it seems
> there is some limitation on Windows Firewall, anyway, I've disenable one
> card and everything is fine now.
>
> Thanks to all that helped me on the networking and firewall problem.
>
> Ray
>
> > To be quite frank, I don't believe that Windows firewall was designed with
> > a
> > view to be used as a router/gateway firewall, and is just a personal
> > firewall. That said, there might be a fix, but it won't surprise me if
> > you're dealing with a software limitation
> >
> > --
> > Svyatoslav Pidgorny, MS MVP - Security, MCSE
> > -= F1 is the key =-
> >
> >> Hi there,
> >>
> >> I posted something about a problem of a server having two cards a couple
> > of
> >> days before. That is, I have two subnets (xxx.xxx.19.0/24 and
> >> xxx.xxx.44.0/24) and both of them have Internet connections, my server
> >> has
> >> two ethernet cards (xxx.xxx.19.210 and xxx.xxx.44.92) on both subnets,
> >> the
> >> configuration of the one on xxx.xxx.19.0/24 has a gateway
> > (xxx.xxx.19.254),
> >> that of the other doesn't. Currently, clients on xxx.xxx.19.0/24 cannot
> > talk
> >> with xxx.xxx.44.92 and clients on xxx.xxx.44.0/24 cannot talk with
> >> xxx.xxx.19.210 either. (Anytime, xxx.xxx.19.0/24 can talk with
> >> xxx.xxx.19.210 and xxx.xxx.44.0/24 can talk with xxx.xxx.44.92 also)
> >>
> >> My server is running Windows 2003 server, I set up Windows 2k3 SP1
> > firewall
> >> on it. If I turn the firewall off, the above problem disappears; if I
> >> turn
> >> it on, I have the problem. In fact, we were using VisNetic Deerfield
> >> Firewall, everything was all right. I removed it and change to SP1
> > firewall
> >> now.
> >>
> >> To Wendel,
> >> I found the problem was affected by Win2k3 SP1 firewall, for example,
> >> packets from computers on xxx.xxx.19.0/24 can reach xxx.xxx.44.92 but
> >> xxx.xxx.44.92 cannot reply when the firewall is on, xxx.xxx.44.92 cannot
> >> talk with xxx.xxx.19.210! Anyway, thanks for your consideration before.
> >>
> >> Ray
> >>
> >>
> >
> >
>
>
>


Similar ThreadsPosted
smart cards December 11, 2005, 7:09 am
Smart Cards & ISA 2004 September 1, 2005, 4:24 pm
Free PKI Smart Cards & CSP for Microsoft Newsgroup Participants May 14, 2007, 7:21 am
Re: disable wireless network cards and bluetooth devices with GPO June 21, 2008, 6:25 am
Intermittent traffic issue March 19, 2006, 10:44 am
Seeking Advice- Securing Server Traffic January 6, 2007, 7:21 pm
Allowing SNMP traffic through "Windows Firewall" on WIN2K3 SP1 October 4, 2005, 7:52 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap