Re: CEICW Network Error



ISA or no ISA?

Either way they can be adjusted via CEICW for the most part but if you (or someone) have created rules manually in ISA then it's a trip through the ISA console.

"RickD" <support@xxxxxxxxxxxx> wrote in message news:uTHzmjR8IHA.2348@xxxxxxxxxxxxxxxxxxxxxxx
Tha was my original plan...to use a netgear wiireless router and allow visitors internet access outside of SBS, but Optimum insiosted that to have a static public IP I MUST use their Cisco....router...during installation and configuration by Optimum(remotely) I had them pass all traffic through to the router internal side (that has a public IP address) and I configured my Dual-NIC'd SBS 2K3 WAN NIC to a public IP.....as I said all was well until the (actually former) client brought is someone else and heaven knows what he tinkered with...

right now I am trying to put humpty dumpty back together again as it was and when I have completed that I will address the SPAM(the original problem) and any suggested re-configurations.

Please keep the suggestions and ideas comming as I re-install Symantec Endpoint 11.0....

Thanks sooooo much!

The other guy rtan CEICW a couple of times, and as I recall, CEICW disables any custom port filters..I am drawing a mental blank as to where to check those...ANYONE????

RickD

"Larry Struckmeyer [SBS-MVP]" <lstruckmeyer@xxxxxxxxxxxxxxx> wrote in message news:%23M$qvbR8IHA.5164@xxxxxxxxxxxxxxxxxxxxxxx
Agreed on both counts. It is strange, and leave it alone. My comment was intended to give Rick additional info that he might be able to act on later. It is possible that the instructions were not clear from Optimum.

What would you and Rick think of even a consumer grade router between the nic and the Optimum device, which is more in line with what I was creeping up on.?

-Larry

"Merv Porter [SBS-MVP]" <mwport@xxxxxxxxxxxxxxxxxxx> wrote in message news:umWKoTR8IHA.2064@xxxxxxxxxxxxxxxxxxxxxxx
I think Optimum (seen other posts about this ISP) does some strange things. If the ext. NIC hasn't been changed, probably best to leave it alone at this point.

--
Merv Porter [SBS-MVP]
============================


"Larry Struckmeyer [SBS-MVP]" <lstruckmeyer@xxxxxxxxxxxxxxx> wrote in message news:%23a1HUQR8IHA.616@xxxxxxxxxxxxxxxxxxxxxxx
Hi Rick:

While we can't possibly know the ins and outs of every ISP and router on the planet, what you are describing sounds strange to me. Merv gave you a link to a diagram for the usual way this is done. The public IP goes on the Inet side of the router, and the SBS side of the router and the external NIC get a private IP address range that is different from the Internal SBS nic and the workstations.

It sounds to me like this device is not a router, but a DSL or Cable modem that sits at the termination point of the ISP connection to your office.

-Larry

"RickD" <support@xxxxxxxxxxxx> wrote in message news:eTY0x8Q8IHA.4928@xxxxxxxxxxxxxxxxxxxxxxx
the WAN(external) NIC has had a public IP address all along....and everything was working great....

the router was provided by Optimum Online and was needed (according to them) to facilitate a static IP for the External NIC

The end-user complained of large amounts of SPAM and that is why the purchased ESET, removed SEP and the whole thing went downhill from there.






"Merv Porter [SBS-MVP]" <mwport@xxxxxxxxxxxxxxxxxxx> wrote in message news:OtYMo2Q8IHA.3848@xxxxxxxxxxxxxxxxxxxxxxx
I suspect someone reconfigured the external NIC and gave it a public address. Normally with a router in the mix, the router gets the public IP address on its WAN side and its LAN side is given a (static) private IP address in a subnet that is different from the Internal LAN. Then the external NIC is given a (static) private IP address in the same subnet as the router's LAN side.

SBS Two Nic configuration
(works with or without ISA)
http://www.smallbizserver.net/Articles/tabid/266/articleType/ArticleView/articleId/76/Two-Nics-a-static-IP-address-ISA-router.aspx

--
Merv Porter [SBS-MVP]
============================

"RickD" <support@xxxxxxxxxxxx> wrote in message news:%231637xQ8IHA.1200@xxxxxxxxxxxxxxxxxxxxxxx

"Merv Porter [SBS-MVP]" <mwport@xxxxxxxxxxxxxxxxxxx> wrote in message news:ea6ssoQ8IHA.1196@xxxxxxxxxxxxxxxxxxxxxxx
Hi Rick,

Please post results of an ipconfig /all for sbs server.

Microsoft Windows [Version 5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.

C:\Documents and Settings\administrator.AxxxxxxxE>ipconfig/all

Windows IP Configuration

Host Name . . . . . . . . . . . . : Axxxxxxx01
Primary Dns Suffix . . . . . . . : axxxxxxxe.local
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : Yes
WINS Proxy Enabled. . . . . . . . : Yes
DNS Suffix Search List. . . . . . : axxxxxxxe.local

Ethernet adapter LAN:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Broadcom NetXtreme Gigabit Ethernet
Physical Address. . . . . . . . . : 00-19-B9-FE-F2-8A
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.0.2
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . : 192.168.0.2
Primary WINS Server . . . . . . . : 192.168.0.2

Ethernet adapter WAN:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Realtek RTL8139 Family PCI Fast Ethernet
NIC #2
Physical Address. . . . . . . . . : 00-40-F4-70-7D-A5
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 96.nn.nn.250
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . : 167.206.112.138
167.206.7.4


Any errors in the event logs?

--
Merv Porter [SBS-MVP]
============================

"RickD" <support@xxxxxxxxxxxx> wrote in message news:OgckxfQ8IHA.2064@xxxxxxxxxxxxxxxxxxxxxxx
SBS 2K3 SP 2

Dual Nic

WAN public IP Address nnn.nnn.nnn.250
LAN 192.168.0.2

router with IP address nnn.nnn.nnn.249

Users brought in another tech and messed up internet connectivity....server had internet access, but AD desktops cannot get to internet.

NOW NEITHER server or desktops have internet access

I have reviewed both NICs, binding orders, services....etc...

When I run CEICW I get these errors in the error log:

Error 0c8007007e returned from call to installing RRAS (LAN)().
Error 0c8007007e returned from call to CNetCommit::Common().
Error 0c8007007e returned from call to CNetCommit::Common().
calling CRFireCommit::Commitex (0x2d93C0).
calling CRFireCommit::ValidatePropertyBag no RRAS NAT Public Interface, Basic Firewall will not be configured.().
Error 0x1 returned from call to CRFireCommit::CommitEx ValidatePropertyBag returned S_FALSE().


The whole problem started when the other tech tried to mUNINSTALL Symantec Endpoint 11.0 and then install ESET server and client.

Any H E L P is greatly appreciated...

TIA

RickD


















.



Relevant Pages

  • Re: port forwarding (rerouting) with isa server.
    ... This is a problem for portable users which have to access the isa ... > server from within the internal network aswell from the internet. ... > exteral ip of the router), but as i told it is a problem with portable ... >>> I have a question about port forwarding with isa server. ...
    (microsoft.public.isa)
  • Re: port forwarding (rerouting) with isa server.
    ... adress (in the appliction software on the client pc)where the clients have ... This is a problem for portable users which have to access the isa ... server from within the internal network aswell from the internet. ... exteral ip of the router), but as i told it is a problem with portable users ...
    (microsoft.public.isa)
  • Re: VPN, SBS2003 and Router
    ... Your internal clients will have solid internet access, as SBS acts as the ... DHCP and DNS server for your LAN - you'll see this when running the CEICW. ... Ditch the Linksys, don't DMZ, get a router that is known to work and re-run ...
    (microsoft.public.windows.server.sbs)
  • Re: port forwarding (rerouting) with isa server.
    ... The App running on ISA should, ... connect to the App with the Router IP# (which is passed to the ISA's ... In the router is a port> forwarding rule configured so that all traffic for port 99 is forwarded to> the ip adres 192.168.0.1. ... This solution would work, but most of these> clients are installed on notebooks, which needs to work on the internal> network aswell, outside the internal network on the internet. ...
    (microsoft.public.isa)
  • Re: Closing Ports!
    ... The pinging is coming from the Hotmail website and my router is picking up the attacks but whenever I go surf various pages or links it triggers off attacks and a constant connection. ... ISA isnt picking up anything. ... >> I just have my router relay syslog data to my PC, which give me feedback on ports opened/connected to the internet, etc. ...
    (microsoft.public.isa.enterprise)