Solved

a Different ip shown in a network

Posted on 2008-10-11
5
227 Views
Last Modified: 2012-05-05
My local area network is not working proerly.  My local ip range is start from 192.168.0.1 to 192.168.0.254
but some time when i am ping any computer in the local area network its ping to the different ip address 209.62.72.173.  I can't understand the problem is this is dns attack or any spyware issue.  I am using ISA server 2006 for the internet sharing.  When i put a ip address of the ISA server as a gateway for the client side means computer this ip will automatically generate.  I remove a gateway from the ip address list its working fine.  Please tell me a solution
0
Comment
Question by:Arnaw1
5 Comments
 
LVL 13

Expert Comment

by:leegclystvale
ID: 22693453
You need to check where ISA is getting it's DNS info from. It may well be getting it's adresses from an external DNS server if it doesn't know where to look internally. The default gateway should be your router interface. Any other DNS requests should be from a DNS server internally. Check your DNS entries in your DNS server and also flush the DNS on the machines you are using
tpye start>cmd>type ipconfig /flushDNS
Your DNS server should have a forwarding address, usually your ISP, for DNS entries it can't resolve internally.
Is the ISa server a DNS server?
Let me know how you get on checking the above
0
 
LVL 1

Expert Comment

by:Ranjithsk
ID: 22693462
Can you please post a screenshot of the ping output and a Hijackthis log?
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 22695431
A couple of things here. First you are not quite quite correct. Your network is 192.168.0.0 - 192.168.0.255 as you MUST inluce the network ID and broadcast address. You must also include these two addresses in the internal LAT table (ISA gui - configuration - networks - internal - addresses).

If you do a tracert to the internal IP address, where does the route go? Can you post the output?
Are you using ISA as proxy only or as a proxy firewall?

If it is a proxy/firewall, it is likely that you have the networks bound in the wrong order - you MUST have the internal as the first network card in an ISA configuration.

Keith
0
 

Author Comment

by:Arnaw1
ID: 22738919
Pl;ease check the hijackthis log & give me solution.  
hijackthis.log
0
 
LVL 13

Accepted Solution

by:
leegclystvale earned 500 total points
ID: 22738967
Firstly, have you checked the ISA and DNS settings That I suggested?
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

Suggested Solutions

Forefront Threat Management Gateway 2010 or FTMG comes with some very neat troubleshooting tools built-in when trying to identify what is actually happening behind the scenes within the product when traffic is passing through its interfaces. To the …
So the following errors occurs in 2 ways that I am aware of at this stage, and you receive one of the following error messages: ERROR 1. When trying to save a rule: No Web listener is specified for the Web publishing rule Autodiscovery Publishin…
This video discusses moving either the default database or any database to a new volume.
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now