Re: Sharing stopped workin, cannot connect out



I think one of the latest Microsoft updates has reset the built-in XP
firewall to block services on a local subnets that were previously available.
I do not think simply stopping the XP firewall is sufficient. I am
searching Microsoft to see if I can verify this but right now all I see is a
lot of issues that *could* be related. On the machine you are unable to
communicate with, go into the XP firewall settings and try allowing tcp 139
for the local subnet and, depending on what type of DNS server you have in
that environment, tcp 445 for a Microsoft DNS server or tcp 53 for any other
type of DNS. TCP 139 should get your file shares working if you use IP
addresses and the DNS ports should fix the name resolution if you prefer to
use names instead of IPs. I will check back on this thread to see if you
have any luck!

"Old-T" wrote:



"Malke" wrote:

Old-T wrote:

My desktop is a WinXP home that's been running for 3½ years now
without any problem. The machine has an iTunes share and a couple of
file shares. Last week the machine suddenly started to behave strange.
The machine is connected to a router through a wireless network.

From the machine I can
- use the internet,
- use SAMBA shares that is on my Linux machine
- download files from ftp server when I have the full path to the
file. - connect and log in to ftp server
I cannot
- share my iTunes library
- share files using standard file sharing
- LIST anything on other ftp server.

The ip address of the XP machine is 176.8.128.19

When I from another machine tries to conect to my ..19 machine
everything fails :-(
It does not even respond to ping.

I ran a port scan on both the machine locally and from another
machine. I get different result....
When I run the port scan from the XP on the XP it says that port 21,
80, 110, 139 and 443 are open
When I run the same port scan from another machine it says that ALL
ports except port 110 are blocked.

(snip)

Unless you made a typo, here's your problem:

The ip address of the XP machine is 176.8.128.19

Allowable IPv4 addresses for private networks (your local area network)
are:

10.0.0.0/8. The 10.0.0.0/8 private network is a Class A network ID that
supports the following range of valid IP addresses: 10.0.0.1 through
10.255.255.254.

172.16.0.0/12. The 172.16.0.0/12 private network can be interpreted
either as a block of 16 Class B network IDs or as a 20-bit assignable
address space (20 host bits) that can be used for any subnetting scheme
within the private organization. The 172.16.0.0/12 private network
supports the following range of valid IP addresses: 172.16.0.1 through
172.31.255.254.

192.168.0.0/16. The 192.168.0.0/16 private network can be interpreted
either as a block of 256 Class C network IDs or as a 16-bit assignable
address space (16 host bits) that can be used for any subnetting scheme
within the private organization. The 192.168.0.0/16 private network
supports the following range of valid IP addresses: 192.168.0.1 through
192.168.255.254.

I don't know what caused your machine's IP address to change, but you
need to make sure it is using one of the private IP schemes above and
naturally matches the rest of your lan.

Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User


I've been using these 176.8.128.xx for years now without any problem.
I have four machines with a static ip (176.8.128.19-23), the rest are DHCP
rangin from 176.8.128.2-7

I have various OS:es as well, Linux Suse 10.1, XP Home, XP Pro, ME and an
XBox on the same subnet but only this particular XP Home that have this
problem.

The machine used to show itself with name on the router, but now the router
just reports UNKNOWN.

The XP behaves as if there is a "second" firewall that blocks all port
accesses.
Disabling the Windows Firewall does not help.

I tried to uninstall the AVG Anti virus, but the result was the same.

// Confused-T
.



Relevant Pages

  • Re: DMZ and file sharing
    ... original poster is not in that zone as he refers to a "port", presumably a real DMzone is a different subnet and/or IP range rather than a fowarded/open "port"? ... firewall does indeed have an additional physical port which is another ...
    (microsoft.public.windows.server.sbs)
  • RE: Adding firewall tomorrow - am I doing this right?
    ... Disconnect the cable from the wan card. ... Plug it into the incoming port on the firewall device and the then connect ... server and subnet Maskthat match the subnet of ...
    (microsoft.public.windows.server.sbs)
  • Re: [fw-wiz] scanning...
    ... > ports are allowed through the firewall for each host... ... > cant see the port... ... > subnet and go ... > do network discovery and even seems that it will do so via whatever port you ...
    (Firewall-Wizards)
  • Re: [fw-wiz] scanning...
    ... you can put in the IP range or subnet ... ports are allowed through the firewall for each host... ... listening because you cant see the port... ... Isn't there a "true" management network operation you can use on Cisco ...
    (Firewall-Wizards)
  • FC3 traffic cant get thru firewall
    ... A client attached an FC3 box to an existing private network of about 80 ... existing firewall. ... An Internet router connects to eth0 on an iptables ...
    (Fedora)