Re: RRAS/NAT connected stations can't access websites



Hi Jian-Ping

Thanks for getting back to me so quickly.

To answer your questions:

1. To ensure that the connection to the internet works well, please check
whether the web page could be opened on RRAS server.

The RRAS Server is able to connect to the Internet when it is in a stand-alone situation and not part of a domain.

2. To ensure there aren't any route related issues, please check whether
you could ping any public IP addresses from your client PC. You could use
the external DNS Server IP address provided by ISP to do the test.

Before enabling NAT network access is fine and DNS resolution through NSLOOKUP and a web browser both function correctly. After enabling NAT it is still possible to use NSLOOKUP from all client computers and the RRAS Server, and it finds the ISP DNS Server. Names resolve to IP addresses correctly but no machine on the network is able to ping or browse the web. IP Addresses garnered from NSLOOKUP return "Destination Unreachable" when trying to PING them.


3. As you have mentioned that " Computers inside the network can ping the
LAN Adapter successfully and using NSLookup from computers behind the NAT
it is possible to resolve DNS Names to IP Addresses." Have you tried to
resolve the external web site's name to IP address? Can this be resolved
correctly?

Yes for instance using NSLOOKUP from a client workstation you can resolve a name to an IP successfully. But the web browser will not return a webpage by DNS Name or IP Address.

4. How did you configure your client PCs' DNS server settings?
Did you point to the DNS server in your LAN?

Yes, DHCP is being handled by the DC and it assigns itself as the primary DNS.

More informations:
================
The following information is for your reference:

Troubleshooting NAT
http://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/intwork/
inae_ips_xsxh.mspx?mfr=true

The above article also apply to Windows Server 2003.

Deploying Dial-up and VPN Remote Access Servers
http://technet2.microsoft.com/windowsserver/en/library/8ff3534e-0f08-45bc-84
87-3b618bc8ad621033.mspx?mfr=true

I look forward to hearing from you soon. :)

Sincerely,
Neo Zhu,
Microsoft Online Support
Microsoft Global Technical Support Center

Get Secure! - www.microsoft.com/security
=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.

--------------------
| From: "Thorin" <The_Mighty_Thorin@xxxxxxxxxxxxx>
| Subject: RRAS/NAT connected stations can't access websites
| Date: Sun, 1 Jun 2008 22:15:14 -0700
| Lines: 23
| Message-ID: <BE5FB8CD-0A16-475C-90CB-28AD916F5CAC@xxxxxxxxxxxxx>
| MIME-Version: 1.0
| Content-Type: text/plain;
| format=flowed;
| charset="iso-8859-1";
| reply-type=original
| Content-Transfer-Encoding: 7bit
| X-Priority: 3
| X-MSMail-Priority: Normal
| X-Newsreader: Microsoft Windows Mail 6.0.6001.18000
| X-MimeOLE: Produced By Microsoft MimeOLE V6.0.6001.18000
| X-MS-CommunityGroup-MessageCategory:
{E4FCE0A9-75B4-4168-BFF9-16C22D8747EC}
| X-MS-CommunityGroup-PostID: {BE5FB8CD-0A16-475C-90CB-28AD916F5CAC}
| Newsgroups: microsoft.public.windows.server.networking
| Path: TK2MSFTNGHUB02.phx.gbl
| Xref: TK2MSFTNGHUB02.phx.gbl
microsoft.public.windows.server.networking:12958
| NNTP-Posting-Host: TK2MSFTNGHUB02.phx.gbl 127.0.0.1
| X-Tomcat-NG: microsoft.public.windows.server.networking
|
| Recently it became necessary to setup RRAS on Windows Server 2003 R2 to
| perform NAT for a small network that is being used as a testing
environment.
| The network had an existing domain controller that holds the roles for
| DHCP/DNS and Directory services. The RRAS server has just two network
| connections (WAN, LAN) and there it connects directly to the outside
world.
|
| The WAN NIC is set to:
| Public interface connected to the Internet
| Enable NAT on this interface
|
| There are no Inbound or Outbound Filters on the connection.
|
| Computers inside the network can ping the LAN Adapter successfully and
using
| NSLookup from computers behind the NAT it is possible to resolve DNS
Names
| to IP Addresses. What doesn't work is when a client tries to connect to a
| website using a browser all of the clients recieve an error that they
cannot
| display the page.
|
| Has anyone seen a document that explains setting up a simple NAT router
| using Windows Server 2003 R2?
|
| Thanks.
|
|


.



Relevant Pages

  • Re: newbie lost in trying to setup NAT
    ... The settings in 2003 NAT are slightly different from 2000. ... Internet" button set, and the "enable NAT on this interface" and the "enable ... that sounds correct for the DNS forwarding. ... be able to resolve both local and Internet names from this server. ...
    (microsoft.public.windows.server.networking)
  • Re: newbie lost in trying to setup NAT
    ... i installed RRAS through 'configure you server wizard'. ... >Is the Cable Modem also a NAT Device? ... DNS setting. ... >> How To Configure DNS for Internet Access in Windows ...
    (microsoft.public.windows.server.networking)
  • Re: natting in win2000
    ... The normal operation of NAT is to use the NAT router ... as its own DHCP-type allocator and to use the NAT router as a DNS relay. ... local DNS server. ... will give the clients the wrong DNS address. ...
    (microsoft.public.win2000.ras_routing)
  • Re: Intra-site DNS problems
    ... > other site for resolution thus the creating the great circle of DNS. ... > After running DCDIAG.exe on the DC behind the NAT it returns an error: ... Check the DNS server, DHCP, ... Microsoft Windows MVP - Windows Server - Directory Services ...
    (microsoft.public.windows.server.dns)
  • Re: DNS registry fix, now cant connect to internet
    ... > recently installed AD on new DC (previously run just as RRAS server, ... > controllers that have the RRAS and DNS service installed". ... > installing AD and promoting machine to DC had something to do with it ... The server can see the router, ...
    (microsoft.public.win2000.dns)

Loading