Link to home
Start Free TrialLog in
Avatar of paulhead
paulhead

asked on

SBS Internet

I am working on SBS 2003 with two nics, the first on the network is manually set the other for the internet connected via a router is DHCP set by the SBS server. I run the the connect to the internet connection wizard and all appeared fine. The system will now recive emails without any problems, I can ping external web and ip address and if I use https://www in the internet explorer on the server and clients i can see web sites. I cannot however just browse the web in the conventional way. It was working fine until about 7 days ago and I have not made any changes .
Avatar of Olaf De Ceuster
Olaf De Ceuster
Flag of Australia image

Please post an Ipconfig/all of server and one workstation.
Olaf
Avatar of paulhead
paulhead

ASKER

Thank you please find IPconfig for server and workstation

Server Ip

Microsoft Windows [Version 5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.

C:\Documents and Settings\Administrator>ipconfig/all

Windows IP Configuration

   Host Name . . . . . . . . . . . . : 4pas01
   Primary Dns Suffix  . . . . . . . : 4pointsassistance.local
   Node Type . . . . . . . . . . . . : Unknown
   IP Routing Enabled. . . . . . . . : Yes
   WINS Proxy Enabled. . . . . . . . : Yes
   DNS Suffix Search List. . . . . . : 4pointsassistance.local

Ethernet adapter Local Area Connection 3:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : HP NC320i PCIe Gigabit Server Adapter
   Physical Address. . . . . . . . . : 00-1B-78-D2-01-73
   DHCP Enabled. . . . . . . . . . . : No
   IP Address. . . . . . . . . . . . : 192.168.44.65
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . :
   DNS Servers . . . . . . . . . . . : 192.168.44.65

Ethernet adapter Local Area Connection 2:

   Connection-specific DNS Suffix  . : 4pointsassistance.local
   Description . . . . . . . . . . . : Realtek RTL8139 Family PCI Fast Ethernet
NIC
   Physical Address. . . . . . . . . : 00-17-3F-9B-A2-41
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   IP Address. . . . . . . . . . . . : 192.168.44.21
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.44.254
   DHCP Server . . . . . . . . . . . : 192.168.44.65
   DNS Servers . . . . . . . . . . . : 192.168.44.65
   Primary WINS Server . . . . . . . : 192.168.44.65
   NetBIOS over Tcpip. . . . . . . . : Disabled
   Lease Obtained. . . . . . . . . . : 28 October 2008 16:34:19
   Lease Expires . . . . . . . . . . : 05 November 2008 16:34:19

C:\Documents and Settings\Administrator>

Workstaion

Microsoft Windows XP [Version 5.1.2600]

(C) Copyright 1985-2001 Microsoft Corp.

 

P:\>ipconfig /all

 

Windows IP Configuration

 

        Host Name . . . . . . . . . . . . : 4pad02

        Primary Dns Suffix  . . . . . . . : 4pointsassistance.local

        Node Type . . . . . . . . . . . . : Hybrid

        IP Routing Enabled. . . . . . . . : No

        WINS Proxy Enabled. . . . . . . . : No

        DNS Suffix Search List. . . . . . : 4pointsassistance.local

                                            4pointsassistance.local

 

Ethernet adapter Local Area Connection:

 

        Connection-specific DNS Suffix  . : 4pointsassistance.local

        Description . . . . . . . . . . . : Intel(R) PRO/100 VM Network Connecti

on

        Physical Address. . . . . . . . . : 00-0B-CD-3D-74-23

        Dhcp Enabled. . . . . . . . . . . : Yes

        Autoconfiguration Enabled . . . . : Yes

        IP Address. . . . . . . . . . . . : 192.168.44.10

        Subnet Mask . . . . . . . . . . . : 255.255.255.0

        Default Gateway . . . . . . . . . : 192.168.44.65

        DHCP Server . . . . . . . . . . . : 192.168.44.65

        DNS Servers . . . . . . . . . . . : 192.168.44.65

        Primary WINS Server . . . . . . . : 192.168.44.65

        Lease Obtained. . . . . . . . . . : 28 October 2008 14:37:54

        Lease Expires . . . . . . . . . . : 05 November 2008 14:37:54

 

Your second NIC CANNOT be in the Server DHCP range.
So logon to your internet router and reset it to for example 192.168.0.1 with DHCP on router disabled. Than set your second NIC to 192.168.0.2 and rerun the Internet connection wizard (Server Management> TO DO List> Point 2). All should be OK after that. Let me know if it isn't.
Olaf
I have tried this and it will not work, with the changes the internet will not work at all and the system no longer collects mail. To clarify this is what I did
Network card 2 set ip address to 192.168.0.2
Router Ip address to 192.168.0.2 DHCP disabled( which it had been previously)
Network Card 3 left as before
Ran Wizard and lost all on server ie could no longer see company page, no web access, no mail.
Workstation no internet access of any form
I have now reset server to the ip setting posted previously as with those i can get mail, use company page and browse to we pages with trhe https prefix.
I have not worked on this syetm before but from some vague notes it appears thethe ip address of the router has allway been fixed as shown in the ipconfig
Thank you for you help so far
Router needs to be 192.168.0.1  not 192.168.0.2 and check to see if NIC2 is defenitely connected to your router.
Disable NIC 3 for now and try again. This is important.
SBS only supports 2 x NIC's. (Unless you set it up properly and you DON'T use the wizards)
Why do you need the 3 rd Nic?
Please try that and get back to me.
Olaf
Hi Olaf

I am going back to clarify later but just to let you know the system only has two nics they are just called 2 and 3 which is confusing. Will this change anything. I will also check as I think my last comment contaed a typo as I am sure that i set the router to 192.168.0.1 and the nic to 192.168.0.2
Thankyou for your help
Paul
Hi Olaf

Just to let you know I have returnned to the system,have reset to the following
Nic2   192.168.0.2        
Nic 3   192.168.44.65
Router 192.168.0.1
Ran wizard and set router to 192.168.0.1 with DNS details from ISP.  I am now recieving emails can ping www.bbc.com, can browse to httPs://www.natwest.com but cannot vist google I recive the following error The Address is not valid. This is the same error that I had with the previous settings. Do you have any more ideas as I am struggling.
Thank You
Firstly confirm DNS of your ISP.
Then:
In Server Management> Internet and Email>Change server Ip address: Change IP to what server address is now 192.168.44.65, It will ask you to redo the Internet connection wizard . Please do that and make sure you enter your ISP DNS servers.
Restart a workstation and test internet. Google for example.
If still no joy. Open a command prompt and type: ping www.google.com and tell me what you get.
Also ping your server address and tell me what you get.
Also at C:\ type "nslookup 192.168.44.65 and tell me what you get.
Also on server check the following; In the properties of my network places>Tools>Advanced>Advanced Settings: Move your server NIC to be at the top.
Let me know,
Olaf

Hi Olaf I have confirmed DNS Settings with ISP and tested as you stated no luck below are the
details from the ping and nslookup.

many Thanks

Pinging www.l.google.com [66.102.9.147] with 32 bytes of data:

Reply from 66.102.9.147: bytes=32 time=44ms TTL=240
Reply from 66.102.9.147: bytes=32 time=43ms TTL=240
Reply from 66.102.9.147: bytes=32 time=44ms TTL=240
Reply from 66.102.9.147: bytes=32 time=44ms TTL=240

Ping statistics for 66.102.9.147:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 43ms, Maximum = 44ms, Average = 43ms

C:\Documents and Settings\Administrator>
C:\Documents and Settings\Administrator>ping 192.168.44.65

Pinging 192.168.44.65 with 32 bytes of data:

Reply from 192.168.44.65: bytes=32 time<1ms TTL=128
Reply from 192.168.44.65: bytes=32 time<1ms TTL=128
Reply from 192.168.44.65: bytes=32 time<1ms TTL=128
Reply from 192.168.44.65: bytes=32 time<1ms TTL=128

Ping statistics for 192.168.44.65:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms

C:\Documents and Settings\Administrator>nslookup 192.168.44.65
*** Can't find server name for address 192.168.44.65: Non-existent domain
Server:  UnKnown
Address:  192.168.44.65

*** UnKnown can't find 192.168.44.65: Non-existent domain

C:\Documents and Settings\Administrator>
Did you run the change server IP address?? It will reset your DHCP scope.
Can you also check to see if you have an A record for your server in DNS?
Also set in tcp/IP properties of your NIC on workstation: Manually add the server DNS for DNS1
Try internet again.
Certainely looks like a DNS issue.
Olaf
Hi Yes I did change server ip
not sure how to check A record in server DNS
will check tcpip properties in workstaion and manually add dns
could it have anything to do with reverselookup ?

Paul
Hi Olaf

I have now tried adding DNS 192.168.44.65  manually to workistation this has no effect
just to let you know the browsing issue is the same on the server and workstation.

Thanks

paul
Yep you do need a PTR or reverse DNS for all A records.
On server command prompt (you might need the support tools) enter dcdiag /test:dns. It should tell you iff DNS is OK.
Olaf
Olaf

I have too leave to obtain support tools will return and check
Thank you
Hi Olaf DNS Diag Results

C:\Program Files\Support Tools>dcdiag/test:dns

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\4PAS01
      Starting test: Connectivity
         ......................... 4PAS01 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\4PAS01

DNS Tests are running and not hung. Please wait a few minutes...

   Running partition tests on : ForestDnsZones

   Running partition tests on : DomainDnsZones

   Running partition tests on : Schema

   Running partition tests on : Configuration

   Running partition tests on : 4pointsassistance

   Running enterprise tests on : 4pointsassistance.local
      Starting test: DNS
         Test results for domain controllers:

            DC: 4pas01.4pointsassistance.local
            Domain: 4pointsassistance.local


               TEST: Forwarders/Root hints (Forw)
                  Error: Forwarders list has invalid forwarder: 194.74.65.59 (<n
ame unavailable>)

               TEST: Records registration (RReg)
                  Network Adapter [00000007] Realtek RTL8139 Family PCI Fast Eth
ernet NIC:
                     Error: Missing A record at DNS server 192.168.44.65 :
                     4pas01.4pointsassistance.local

               Warning: Record Registrations not found in some network adapters

         Summary of test results for DNS servers used by the above domain contro
llers:

            DNS server: 194.74.65.59 (<name unavailable>)
               1 test failure on this DNS server
               This is not a valid DNS server. PTR record query for the 1.0.0.12
7.in-addr.arpa. failed on the DNS server 194.74.65.59

         Summary of DNS test results:

                                            Auth Basc Forw Del  Dyn  RReg Ext
               ________________________________________________________________
            Domain: 4pointsassistance.local
               4pas01                       PASS PASS PASS PASS PASS WARN n/a

         ......................... 4pointsassistance.local passed test DNS

C:\Program Files\Support Tools>
Start>Admin Tools>DNS>Your server>Forward Lookup Zones>4pointsassistance.local> Right click on 4pointsassistance.local >New Host A>leave blank for Name and enter for IP address:192.168.44.65 press add host. (make sure Create associated pointer (PTR) record is ticked.)
And again right click on 4pointsassistance.local >New Host A>In the name space type 4pas01 and enter IP:192.168.44.65 (make sure Create associated pointer (PTR) record is ticked.)
Right click on server name under DNS>Properties>All Tasks>Restart
Try again.
If still not woking forward another DCDiag.
Olaf
Thank you I have tried this now and it has no effect below is the DNS Diag, just to let you know i did run the internet wizard again afterwards to just to see if that would help. I can still ping www.google.co.uk and go to any address with httpS:// and view. Many Thanks


Microsoft Windows [Version 5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.

C:\Documents and Settings\Administrator>dcdiag/test:dns

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\4PAS01
      Starting test: Connectivity
         ......................... 4PAS01 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\4PAS01

DNS Tests are running and not hung. Please wait a few minutes...

   Running partition tests on : ForestDnsZones

   Running partition tests on : DomainDnsZones

   Running partition tests on : Schema

   Running partition tests on : Configuration

   Running partition tests on : 4pointsassistance

   Running enterprise tests on : 4pointsassistance.local
      Starting test: DNS
         Test results for domain controllers:

            DC: 4pas01.4pointsassistance.local
            Domain: 4pointsassistance.local


               TEST: Records registration (RReg)
                  Network Adapter [00000007] Realtek RTL8139 Family PCI Fast Eth
ernet NIC:
                     Error: Missing A record at DNS server 192.168.44.65 :
                     4pas01.4pointsassistance.local

               Warning: Record Registrations not found in some network adapters

         Summary of DNS test results:

                                            Auth Basc Forw Del  Dyn  RReg Ext
               ________________________________________________________________
            Domain: 4pointsassistance.local
               4pas01                       PASS PASS PASS PASS PASS WARN n/a

         ......................... 4pointsassistance.local passed test DNS

C:\Documents and Settings\Administrator>
Problem still exists:  Error: Missing A record at DNS server 192.168.44.65 :
                     4pas01.4pointsassistance.local
That's what we need to fix.

Please run the change server Ip wizard and change it to the same value 192.168.44.65 .
Restart server.
And  post a screenshot of your forward lookup zone with all sections expanded.
Had a long day and off to bed but will have a look tommorow AM (my time)
Olaf
Hi Olaf

Thank you for help so far please find DNS details in attatched file I have done as you said with ip address and restartd system with no effect.
DNS-Forward-local.bmp
Doesn't seem to be DNS.
Lets see if its a networking issue.
Please download the SBSBPA and fix what needs fixing.
http://www.microsoft.com/downloads/details.aspx?familyid=3874527A-DE19-49BB-800F-352F3B6F2922&displaylang=en
Olaf
sorry for the delay in getting this back not been to well I dont think it helps much!
olafdc


Have you been able to take alook at this for me still causing problems
Hi Paul,
Did you run the SBS BPA?
Any issues like EDNS and task offloading?
Olaf
Hi Thanks for coming back yes I did run it and attatched the file to the message before last. I could not see any problems. But can repost later

Paul
Can't see the attached file? Can you resend?
yes will send in about 1 hour
Hi Paul.
It is 11:30pm at night here.I'll have a look at the file tomorrow.
Can you also post a netdiag? Use the support tools.
It might also be a wise thing to reset your router to factory defaults and reconfigure it from scratch. Make sure you do a backup of the router config first so you can always restore if things go bad.
Olaf
Hi Olaf

I am sorry i missed this so have not performed a netdiag . I have allready perforrmed a reset
on the router and this had not effect. I will not be able to get access for the netdiag until Monday.Please see attatchment for previous. This was an eml doc but could not be sent so i have converted to word

Many Thanks
SBSBPA.200811051207401362.data.doc
SBS BPA tells us taskoffloading issue: To fix: http://msmvps.com/blogs/bradley/archive/2008/09/29/disabletaskoffload.aspx
EDNS is enabled and shoulb be disabled: To Fix: http://www.ntsecurity.net/article/articleid/42188/solving-a-web-site-access-problem.html
AVG 8.0 is not working too well with SBS since latest updates. Monitor their site for further updates. Diasable AVG just to see if it helps.
Please Install SP2 for exchange server.
Olaf

PS: yOU NEED TO FIX AT LEAST EDNS AND TASKOFFLOADING

ASKER CERTIFIED SOLUTION
Avatar of paulhead
paulhead

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Olaf

I have now run the exchange update but the problem continues not sure where to go from here do you have any further ideas or should i repost the question. Tnak you for your assistance so far.

Paul