Re: RWW Issue From the Internet (Port 4125)



Anything in the Event Logs?

At a command prompt, if the following does not return a result, it should
mean that 4125 is OK (no other process has commandeered it)
netstat -aon | find "4125"

4125 is opened dynamically, only when required, so I believe a "no response"
to the netstat command is appropriate.

http://msmvps.com/blogs/bradley/archive/2007/04/13/vulnerability-in-rpc-on-windows-dns-server-could-allow-remote-code-execution.aspx
"Remember our DNS security issue from yesterday? One clarification that I
need to make is that while port 4125 is "open" in that range from 1000-5000
it's not "listening". Port 4125 has to be open in your routers, but on the
server, it's not really open, and doesn't do it's validation/hand off
process until after you log onto the Remote Web Workplace portal. So you
need to be authenticated on the system and only after that time does the
port start to listen and process RPC processes."

Connect a laptop or workstation to a port on the router, put it in a
workgroup, then try to RWW into the SBS server. This will take the router
out of the equation.

--
Merv Porter [SBS-MVP]
============================

"BMC" <BMC@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:3E2580D7-2405-48EA-A1C0-61E5CABA3DA6@xxxxxxxxxxxxxxxx
Hi Merv

I have re-booted the server and router many times, also replaced the
router
just in-case.

I have also run the CEICW many times

All failed.

I confident it something to do with port # 4125, when i run the netstat
(netstat -an |find /i "4125", I don't get a response (not listening0

Regards
Barry

"Merv Porter [SBS-MVP]" wrote:

HI Barry,

Maybe try re-running CEICW, enabling the firewall, selecting the
services,
completing the web server certificate and finishing CEICW. Even
rebooting
the SBS server might be a fix. In addition, reboot the router. You
might
also try creating the web server certificate with your WAN IP address and
not your SBSservername to rule out a DNS Nameserver issue. You would
then
access RWW using: https://<yourWANIP>/remote

--
Merv Porter [SBS-MVP]
============================

"BMC" <BMC@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:AE1F1F37-AE80-4D21-BF18-7FF491F25427@xxxxxxxxxxxxxxxx
Hi

We are running SBS 2003 with ISA 2004 on 2 NIC's.

RWW has working fine until today.

We are not able to connect from outside (Internet). All is fine from
with-in
the LAN.

The router is working fine, allowing inbound access through the
required
ports.

I can use all other services from the Internet.

I think the issue is with port # 4125, I run a netstat command and
can't
establish with this port?

Any help, guidance would be appreciated.

Regards
Barry





.



Relevant Pages

  • Re: Cost of setting up a network
    ... A router capable of acting as a VPN endpoint for more than one user simultaneously with four Ethernet ports or a switch to suit. ... The rationale for using a server here is basically that the router doesn't need to be able to decide which PC to route the connection to. ... If you are using a router which supports it, you can set up a port-forwarding inbound rule which also _translates_ the port supplied to the receiving port. ... You can use several of these connections to different machines simultaneously. ...
    (uk.comp.homebuilt)
  • Re: Still cant connect to RWW or OWA remotely
    ... No Phantom NICs as far as I can see. ... that it can not find the server. ... Configure your Router as an Eithernet Bridge. ... Once you have this then configure the Routers Firewall and Port ...
    (microsoft.public.windows.server.sbs)
  • Re: Still cant connect to RWW or OWA remotely
    ... No Phantom NICs as far as I can see. ... that it can not find the server. ... Configure your Router as an Eithernet Bridge. ... Once you have this then configure the Routers Firewall and Port ...
    (microsoft.public.windows.server.sbs)
  • Re: changed IP address: cant receive email & need to make domain name match IP address
    ... Port Forwarding for 2Wire 1701HG ... SBS CDs, but it's always a good idea to keep them handy. ... As you are set up now, your SBS server is "bare to the Internet" (not ... need to buy at least another inexpensive router to put between the SBS ...
    (microsoft.public.windows.server.sbs)
  • Re: Cant connect to Mailserver
    ... domain's zone files on the dyndns server, ... I'm presuming it's a simple port forward from WAN to LAN on ... When I telnet to port 25 I should get a response from your ... Are the correct ports open in the router? ...
    (microsoft.public.windows.server.sbs)