Koozali.org: home of the SME Server

SME 6.01 - WinXP Pro SP2 Problem -- Solved Duh!

Offline RedBeard

  • ***
  • 62
  • +0/-0
SME 6.01 - WinXP Pro SP2 Problem -- Solved Duh!
« on: May 29, 2005, 08:00:01 PM »
Yesterday, I set up a wireless connection between two buildings with 2 linksys WET11.  This new building had several exsisting WinXP Pro boxes with SP2 installed.  These machines previously connected over the same WET11s to a cable modem for internet access without a problem.  

Server:  

- Dell 400SC 2.8 w/1Gig RAM
- SME 6.01 with security updates
- Dungog’s Dan’s Guardian 2.8.0.3-2av636 (w/clam virus scanning)
- clamav-es-0.85.1-02dungog
- Other Dungog contribs
- DHCP manager contrib
- various contribs

WinXP Pro boxes:

- Machines are NOT logging into domain yet.
- Dell 2400s  (less than a month old)
- SP2 installed  8^(
- McAfee Security Suite (Exited this after startup and it makes no difference)
- Windows Firewall disabled due to McAfee system
- Applied SME XP registry changes to allow login to domain.

The Win98SE machines in the new building have no problem connecting to the internet thru the SME server.  The XP boxes obtain there ip addresses via DHCP from the server, MSN Messenger works fine, I can browse network shares and can get to internal web pages.  External web pages time out.  It indicates that page was found but it never loads.

NOTE: DHCP manager server panel indicates that the machines (XP and 98) are NOT on when they are.  Are WET11 bridges not sending some info regarding DHCP status??

Dans Guardian logs for the XP machines indicate that the requested web pages are OK and request approved:

2005.5.28 21:11:36 - 10.0.0.81 http://ie.msn.com/us/channel/intro/intro.asp *SCANNED*  GET 168
2005.5.28 21:11:37 - 10.0.0.81 http://www.msn.com/us/channel/intro/intro.asp *SCANNED*  GET 13700
2005.5.28 21:11:38 - 10.0.0.81 http://hp.msn.com/c/my/j/myhelp.js *SCANNED*  GET 393
2005.5.28 21:11:40 - 10.0.0.81 http://hp.msn.com/c/my/t/00/style_en_win-ie6.css *SCANNED*  GET 26135
<SNIP>
2005.5.28 21:12:10 - 10.0.0.81 http://windows.microsoft.com/isapi/redir.dll?OLCID=0x0409&CLCID=0x0409&OS=at&PRD=windowsupdate
 *SCANNED* *EXCEPTION* Exception site match. GET 169
2005.5.28 21:12:10 - 10.0.0.81 http://windowsupdate.microsoft.com/default.htm *SCANNED* *EXCEPTION* Exception site match. GET 3191
2005.5.28 21:12:14 - 10.0.0.81 http://windowsupdate.microsoft.com/redirect.js *SCANNED* *EXCEPTION* Exception site match. GET 13590
2005.5.28 21:12:16 - 10.0.0.81 http://windowsupdate.microsoft.com/redirect.asp?UA=true *SCANNED* *EXCEPTION* Exception site match. POST 114
2005.5.28 21:12:17 - 10.0.0.81 http://v4.windowsupdate.microsoft.com/? *SCANNED* *EXCEPTION* Exception site match. GET 136
2005.5.28 21:12:17 - 10.0.0.81 http://v4.windowsupdate.microsoft.com/en/default.asp *SCANNED* *EXCEPTION* Exception site match. GET 8159
2005.5.28 21:12:18 - 10.0.0.81 http://v4.windowsupdate.microsoft.com/shared/js/redirect.js *SCANNED* *EXCEPTION* Exception site match. GET 13590
2005.5.28 21:12:18 - 10.0.0.81 http://v4.windowsupdate.microsoft.com/en/redirect.asp?UA=true *SCANNED* *EXCEPTION* Exception site match. POST 114

From /var/log/messages:

May 29 09:37:20 server e-smith[2186]: Processing event: dhcp-change
May 29 09:37:20 server e-smith[2186]: Running event handler: /etc/e-smith/events/dhcp-change/S10tinydns-conf
May 29 09:37:20 server e-smith[2186]: S10tinydns-conf=action|Event|dhcp-change|Action|S10tinydns-conf|Start|1117377440 81
May 29 09:37:20 server e-smith[2186]: Running event handler: /etc/e-smith/events/dhcp-change/S20dnscache-change
May 29 09:37:20 server e-smith[2186]: S20dnscache-change=action|Event|dhcp-change|Action|S20dnscache-change|Start|1117377
May 29 09:40:00 server ucd-snmp[2642]: Connection from 127.0.0.1
May 29 09:45:00 server last message repeated 8 times
May 29 09:45:00 server last message repeated 7 times
May 29 09:49:38 server ucd-snmp[2642]: Connection from 10.0.0.81 REFUSED  <==XP PRO BOX
May 29 09:49:38 server ucd-snmp[2642]: Connection from 10.0.0.81 REFUSED
May 29 09:50:00 server ucd-snmp[2642]: Connection from 127.0.0.1
May 29 09:55:00 server last message repeated 8 times

Any Ideals on how to proceed?  Later today I may try to move the XP Boxes to the wired network across the street to see if they can connect.

Thanks
Kevin
............

Offline RedBeard

  • ***
  • 62
  • +0/-0
Duh! Solved the problem
« Reply #1 on: May 31, 2005, 05:13:12 AM »
Well Duh! I found out what the problem was.  Apparently exiting McAfee Security Suite does not kill the firewall.  That’s what I get for working on a Saturday afternoon with my mind on going to a party.  So the McAfee firewall was blocking the response from the web proxy.  

Some additional info:
I did some experimenting with a XP pro box at home on my test system.  I could not get the Windows SP2 firewall to allow web traffic back in when Dan’s Guardian was in place.  I tried to open up the firewall as much as possible and it would not let traffic back to the XP machine.  With DG filter off it worked just fine.  I assume it has something to do with the setup of the transparent proxy by DG.

Sorry to bother ya all.
............