Re: Cannot Use LAN IP Addresses

From: A.Klimkin (aklimkin)
Date: 11/19/04


Date: Fri, 19 Nov 2004 11:10:40 +0300

You're right, Phillip.
I believe it's a serious bug in firewall client/ISA2004 because there are
some cases when you're not able to use netbios or dns names in the url
string (like script-generated urls, for example).
I think it can be fixed by allowing firewall clients to resolve names by
their own, rather than by firewall service. But I can't find the appropriate
configuration option. Does anyone know if there is some registry value?

Regards,
Andrew

"Phillip Windell" <@.> wrote in message
news:eTw7INczEHA.1204@TK2MSFTNGP10.phx.gbl...
> Ah! I saw this right after I sent my other post,...check it out....(hehe).
>
> It is seeing the "dots" in the IP# and treating it as a FQDN (treats the
> numbers as if they were letters). It then trys to process it that way and
> creates a mess.
>
> Keep in mind that *all* FQDNs are *assumed* to be out on the Internet
until
> after they are resolved to an IP#,...so they always are proccessed by the
> proxying service. Once they are resolved and determined to be on the
Private
> side of the LAN the "proxying services" bail out and let it transit to the
> destination directly. If it improperly interprets the IP# in the URL to be
a
> FQDN instead,...well the problem becomes obvious.
>
> MS Exchange and the IIS SMTP Service will also do this and require that a
> raw IP# be enclosed in [ ] such as, [192.168.1.3] to indicate that they
> are simply a raw IP# and not a FQDN. But I doubt that would work with ISA
if
> you did that in the browser's address bar.
>
> Unfortunately, I'm not sure what causes it and I have no idea where the
> problem is happening either to even know what to blame.
>
> --
>
> Phillip Windell [MCP, MVP, CCNA]
> www.wandtv.com
>
>
> "Cyskon" <cyskon@msn.com> wrote in message
> news:OMqoxjZzEHA.3028@TK2MSFTNGP10.phx.gbl...
> > I should also let you know that, if I type in the NetBIOS name for the
> > resource I can get access to it, but NOT via the IP address.
> >
> > "Cyskon" <cyskon@msn.com> wrote in message
> > news:#zeJ$hLzEHA.260@TK2MSFTNGP11.phx.gbl...
> > > Hello Newsgroup,
> > >
> > > Here's my problem. My test workstations that I have installed the FWC
on
> > > cannot access other machines on the network using their IP address.
> > >
> > > I have a few web servers within my network that I access at times
using
> > the
> > > local IP address of the machine. Now I am unable to do this.
> > >
> > > Can someone tell me why and how to resolve the issue?
> > >
> > > Thanks
> > >
> > >
> >
> >
>
>



Relevant Pages

  • Re: NetBIOS over IP -- XP to NT via VPN
    ... Although I can resolve to the computer name, I can see it's computer name. ... > Allow you to browse objects on the remote network - which LMHOSTS doesn't ... > NetBIOS names to IP addresses. ... there is a firewall, and I will try to disable it for my next wins test... ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Patching a Firewall
    ... NetBIOS has been disabled, since the shares don't exist without NetBIOS. ... In my opinion the OS used for a firewall is not really a big deal, ... need to hack the registry to turn off the administrative shares. ... >>Captus Networks ...
    (Security-Basics)
  • Re: Cannot Use LAN IP Addresses
    ... I believe it's a serious bug in firewall client/ISA2004 because there are ... I think it can be fixed by allowing firewall clients to resolve names by ... > FQDN instead,...well the problem becomes obvious. ... >> I should also let you know that, if I type in the NetBIOS name for the ...
    (microsoft.public.isa.clients)
  • Re: Cannot Use LAN IP Addresses
    ... I believe it's a serious bug in firewall client/ISA2004 because there are ... I think it can be fixed by allowing firewall clients to resolve names by ... > FQDN instead,...well the problem becomes obvious. ... >> I should also let you know that, if I type in the NetBIOS name for the ...
    (microsoft.public.isaserver)
  • Re: Cannot Use LAN IP Addresses
    ... I believe it's a serious bug in firewall client/ISA2004 because there are ... I think it can be fixed by allowing firewall clients to resolve names by ... > FQDN instead,...well the problem becomes obvious. ... >> I should also let you know that, if I type in the NetBIOS name for the ...
    (microsoft.public.isa)