win2k3 server and workstation internet access

Associate
Joined
3 Jan 2006
Posts
1,141
Location
Elgin
yep i have the same issues with mine m8 havent found a solution to the windows firewall but im behind a hardware firewall so that solves my issue there
but i'd deffo like to know if there is a solution to this :confused:
 
Associate
Joined
2 Aug 2006
Posts
59
Not exactly sure what you mean.
I can't think of any reason why windows firewall would stop internet access.
Windows firewall only blocks stuff coming in, doesn't block anything going out.

How are the machines all connected? What's the infrastructure?
 
Associate
Joined
3 Jan 2006
Posts
1,141
Location
Elgin
its blocking internet access due to the machines pointing at the server as a DNS weird i know, i guess its because the requests to resolve names are being blocked by the servers windows firewall for some stupid reason

had a quick surf around and i think its something to do with the ICMP settings on the advanced tab?
 
Last edited:

Deleted member 58846

D

Deleted member 58846

Torch [P4] said:
its blocking internet access due to the machines pointing at the server as a DNS weird i know, i guess its because the requests to resolve names are being blocked by the servers windows firewall for some stupid reason

had a quick surf around and i think its something to do with the ICMP settings on the advanced tab?

the firewall would not block dns requests. It has nothing to do with why you can't get websites. I suggest you check the settings.

Inside the DNS server there will be a tab to forward dns queries to your external dns (ISP DNS). Make sure you have added them in there otherwise only sites you add to the Internal DNS will be resolved.
 
Soldato
Joined
8 Nov 2002
Posts
9,128
Location
NW London
zen62619 said:
the firewall would not block dns requests. It has nothing to do with why you can't get websites. I suggest you check the settings.

Inside the DNS server there will be a tab to forward dns queries to your external dns (ISP DNS). Make sure you have added them in there otherwise only sites you add to the Internal DNS will be resolved.

By default a Windows DNS server will use root hints to resolve any domain it doesn't know. You shouldn't have to add forwarders to get it to work.
 
Associate
Joined
3 Jan 2006
Posts
1,141
Location
Elgin
zen62619 said:
the firewall would not block dns requests. It has nothing to do with why you can't get websites. I suggest you check the settings.

Inside the DNS server there will be a tab to forward dns queries to your external dns (ISP DNS). Make sure you have added them in there otherwise only sites you add to the Internal DNS will be resolved.

all i know is that with the firewall off it can access websites whilst still pointing at the server as the DNS
with the firewall on and using nslookup it cant resolve the domain name but can resolve internet addresses ?
correct theres no need to add a forwarding address as the server points at the router for DNS resolution which then points at the ISP DNS etc
i presume this is the same situation that the initial question was asking?

to summarise my setup:
win2k3 r2 server which is connected via gigabit switch to a router and the servers dns settings (in the NIC) points towards the router, host machines point to the server for DNS
the servers nic has its firewall turned off altho the host machines have theres turned on
the router dishes out the IP addresses via DHCP to all machines altho they are issued the same address via there mac addresses
 
Last edited:
Soldato
Joined
8 Nov 2002
Posts
9,128
Location
NW London
Torch... When you say "with the firewall off it can access websites", What firewall are you talking about?? Are you talking about on the Win2k3 Server?

If so then i assume it will just be the fact that the DNS requests from clients are being blocked by the firewall.
 
Associate
Joined
3 Jan 2006
Posts
1,141
Location
Elgin
yeah with the win2k3 firewall ie microsofts built in firewall for the NIC turned off, then the host machines which point at the servers IP for DNS resolution can get access to websites ?
 
Soldato
Joined
8 Nov 2002
Posts
9,128
Location
NW London
Well if you must have it on (and i don't believe many setups have it enabled on a server) then you will probably need to manually add a rule to allow incoming DNS requests.
 
Associate
Joined
3 Jan 2006
Posts
1,141
Location
Elgin
yep :D mine is fine m8 as its behind a hardware firewall but Tried & Tested (the original ?) may need some direction?
u can restrict requests to just your local IP addy's can't u ?
 
Soldato
OP
Joined
11 Jul 2004
Posts
16,048
Location
Neptune
Thanks for replies so far. Torch is right...i do need some direction here; we don't have a hardware firewall (at least at the moment) and to confirm: whenever the Win2k3 Server Windows Firewall is ON the workstations connected to it cannot access the internet. Turn the Win firewall off and they work just fine.

Any pointers of what i need to add/modify?

Thanks all. :)
 
Back
Top Bottom