ICS Problem

Posted on 2002-06-25
Last Modified: 2010-08-05
I'm currently having a problem with ICS @ the moment;
The details of the network are as follows.

1. Win2000 server connected to a switch on one
Ethernet card, supplying DHCP IP's to Clients.

2. The other Ethernet card is connected to an
ISDN Modem with IP:

I'm using the ISDN Modem IP as the gateway which
is of course
The only PC that can see the internet connection is the server.
All other PC's are set to obtain IP's via DHCP from server.

There is another configuration that I have tried that works
only with Static IP's assigned to all the clients.

1. Win2000 server connected to the switch

2. The ISDN Modem is connected to the switch via crossover cable
with IP:

I'm using the ISDN Modem IP as the gateway and it works, But I feel this is very unsafe, as I would rather go through a firewall on the server, instead of setting up personal firewalls on all the machines.
I have heard the first configuration works, but need a guide to walk me through the process.
Question by:zer0biwan
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
  • 4
  • +2
LVL 79

Expert Comment

ID: 7109598
If you are running ICS on the server, the client's gateway should be set to your server's IP -
I would suggest that each network card be on a separate IP network, i.e. LAN card connected to all PC's =  192.168.0.x, between ISDN modem and Server card: 192.168.1.x

Your server's default is the ISDN modem's IP
Your other client's default gateway is the server
The server is providing NAT services

Author Comment

ID: 7111789
Thanks for the reply lrmoore,
The modem is external.
I've assigned the IP:
to the modem and IP: to
the ethernet card connected to the modem.
I can't connect to the internet even from the server
Also when I enabled ICS on the internet connection I
think it tried to reset the IP of the server-modem to
But of course the LAN ethernet is set to that IP.
I'm going crazy here, there has to be an answer to this!
Anything considered @ this stage.
LVL 41

Accepted Solution

stevenlewis earned 85 total points
ID: 7112643
Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

LVL 41

Expert Comment

ID: 7112646
When using M$ ICS, the NIC on the host connected to the LAN MUST have the ip
usually the other adapter is set to auto configure (the one connected to the modem)

Author Comment

ID: 7115012
Thanks for the reply stevenlewis,
Well I'm beginning to get more info on the problem.
As I said in the original post I'm using DHCP on the
Win2k server (mainly because alot of the clients are
laptops), and while browsing the M$ knowledge base found;
"The ICS service is one implementation of Network Address Translation (NAT) that Windows 2000 uses. The ICS service automatically sets up a mini DHCP scope and a DNS Proxy service to enable clients on the private network to use ICS and get on the Internet.

The DHCP allocator and DNS Proxy services are not configurable in ICS and start as soon as the service is enabled. Because these services bind to the same TCP ports that a DDNS or DHCP server uses, ICS conflicts if these services are running."

The only way to resolve this problem is;

"do not run the ICS service on a DHCP or DDNS server. NAT (which is installed using routing protocols in the Routing and Remote Access Service (RRAS) snap-in) works correctly if you do not enable the DNS Proxy service or the DHCP allocator."

Back to stage one I think!
Any other ideas are welcome.

Expert Comment

ID: 7118973
I had this problem too, but I'll walk you through how I solved it. On my server, the internet connection was a dial-up, and the other computers were connected to it. For ICS to not conflict with DHCP, you need to set the DHCP scope to 192.168.0.x as well (with subnet mask and get the DHCP server to automatically assign IP addresses.

You should have AD installed for this to work, I'm not sure but this is how my network goes. NAT is too complex and I abandoned the idea of configuring it.

Enable ICS on the connection you want to share. Leave everything else the way it was on this connection.

In DHCP, create a new scope called and create an address pool from to

On the network card that is connected to your LAN, enable the TCP/IP protocol if you haven't already, and click properties. check 'Use the following IP address', and type in for the IP address, and for the subnet mask. If you want to enable DNS for your network too, (mandatory anyway) then just type in (localhost) for the DNS address.

When configured this way and if the server's internet connection is working, your network should be able to access the network too, as the DHCP and ICS won't conflict because they are using the same IP. Whatever, this is how mine is set up because I was too lazy to learn about NAT but it works so there.


Expert Comment

ID: 7118976
When I learned about the Windows 2000 conflict between ICS and DHCP I completely disregarded it and reinstalled win2k server about 7 times before I found a way ^ above.

Besides, your ISDN modem should have an automatically assigned IP address, by yout ISP...don't use
On all the other computers use AS THE GATEWAY NOT because the IP of the server is and the modem is connected to it. Now I realize that is the reason your internet connection isn't working. Besides your IP for the modem shouldn't be anyway because that is a private network address. On all the client computers check "Use DHCP for WINS resolution" and leave all the other settings to automatic. If you want to use DNS I have no idea how to go further on this as my network doesn't use it.

OK JUST TO CLARIFY THIS IF YOU HAVE SET THE GATEWAY TO ON THE CLIENT COMPUTERS then it won't work for sure as there probably isn't a computer with that IP on your network with an internet connection.

As for connecting anything to a switch with a crossover cable, that is stupid, because the switch automatically crosses standard RJ-45 category 5 patch cables and that crosses it over twice which counters the effect.


:P i think that might help.

Expert Comment

ID: 7118981
Oh yes another thing is if your server is win2k server MAKE SURE YOU GET ALL THE LATEST DRIVERS for all the NICs on your clients because i had a major problem of this, all the configuration was correct but it still didn't work until i got the latest drivers which had win2k server support.

Author Comment

ID: 7119292
Thanks for the replies once more,
This is cobblers, crossovers can be used for an assortment of tasks.
Anyway it's the only way I can connect the modem to the switch(RTFM).
Got it sorted though, I only wanted to make the entire network more secure and decided on a cheap PC running wingate to bridge the networks.
Got to give the points to stevenlewis cause through the links I found what I was looking for.
Excellent help though guys',
thanks to all of you.
LVL 41

Expert Comment

ID: 7119351
why the "C"?

Expert Comment

ID: 7119356

Don't be greedy for points and marks...this community isn't a competition. Be glad that you helped the guy.
LVL 41

Expert Comment

ID: 7119404
How Do I Know What Grade to Give?
Although we use an A-D scale here at Experts Exchange, it works differently than, say, school grades. If one or more Experts' proposals are accepted as answers, they should usually be given an A or B grade, since they have taken the time to provide you with a working solution. If a possible solution is incomplete - ask for clarification or details before accepting the answer and grading it. People should not be given lower grades because of incorrect grammar or because you just accepted their answer or comment to close the question. Keep in mind, your question and any follow-up comments should be focused so that there can be a specific answer. The following is a good guideline to follow when grading:

A: The Expert(s) either provided you with a thorough answer or they provided you with a link to information that thoroughly answered your question. An "A" can also be given to any answer that you found informative or enlightening beyond the direct question that you asked.

B: The Expert(s) provided an acceptable solution, or a link to an acceptable solution, that you were able to use, although you may have needed a bit more information to complete the task.

C: Because Experts' reliability are often judged by their grading records, many Experts would like the opportunity to clarify if you have questions about their solutions. If you have given the Expert(s) ample time to respond to your clarification posts and you have responded to each of their posts providing requested information; or if the answers, after clarification, lack finality or do not completely address the issue presented, then a "C" grade is an option. You also have the option here of just asking Community Support to delete the question.

Remember, the Expert helping you today is probably going to be helping you next time you post a question. Give them a fair chance to earn an 'Excellent!' grade and they'll provide you with some amazing support.


Author Comment

ID: 7120411
Hi stevenlewis,
You were given a "C" mainly because the information that led to the resolution of the problem was from a different source.
If you had directly given me the info you would have gotten your "A".
Fair is fair, I had to do alot of surfing before I got a solution that worked for me.
As heheman3000 has stated "this community isn't a competition".

Expert Comment

ID: 10026403
you can not route between 192.168.0.x and 192.168.0.x, they are both on the same subnet.

you need to have one NIC with a public IP Address such as 24.x.x.x, which is the internet NIC. the other one with the 192.168.0.x.

let me know if further hlep need.


Featured Post

Don't miss ATEN at NAB Show April 24-27!

Visit ATEN at NAB Show to learn how our "Seamlessly Entertaining" solutions deliver fast, precise video streaming without delays for the broadcasting and media environment. ATEN will showcase its 16x16 Modular Matrix Switch (VM1600) and KVM Over IP Solution (KE6900 series).

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Connectivity issues after power outage 5 62
Basic Client Hyper-V test lab connectivity issue. 7 74
Palo Alto site-to-site vpn monitoring 5 50
Bandwidth cap???? 8 60
Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
When it comes to security, there are always trade-offs between security and convenience/ease of administration. This article examines some of the main pros and cons of using key authentication vs password authentication for hosting an SFTP server.
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Internet Business Fax to Email Made Easy - With  eFax Corporate (, you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question