Category Archives: General

Firewalling Problem

OK, I think I’ve found the culprit. Zone Alarm does seem to be blocking UDP between host and client, and I can’t figure out how to stop it without completely disabling my Internet firewall. It thinks that the ethernet adaptor for the LAN is to the internet, and it won’t allow me to edit or change that. It’s the only firewall I have, so I can’t take it down.

I may have to upgrade from the free version to Zone Alarm Pro, because while the Help menu says that there’s an option for setting it up for ICS, it doesn’t seem to display it for the version I have.

[Update a few minutes later]

I finally figured out how to change the zone for the adaptor from “Internet” to “Trusted.” My LAN is working properly now, but clients are still not seeing the internet.

[Late afternoon update]

I’m having trouble thinking that it’s a Zone Alarm problem at this point, because I’m watching the log, and I’ve seen no activity on the LAN being blocked, even when I attempt an internet connection from a client.

I can ping the host machine, but I can’t ping anything on the internet, either by name or IP.

This is most frustrating.

[Update a couple hours later]

At Ian Woollard’s suggestion, I momentarily disabled Zone Alarm, and that was the problem. It seems to work if I reduce the security level for the Internet Zone from “High” to “Medium.”

I’m not sure that I can configure it more specifically without getting the full version, though.

Now the question is, do I spend the forty bucks on Zone Alarm Pro, or on a router…?

I’m inclined to the former, because I can buy it on line, and it will be a good belt-suspenders system for when I get a good hardware firewall up.

I Want To Share

My internet connection, that is.

Until I complete the move from California, and bring my Linux firewall and wireless router to Florida, I need to set up a quick’n’dirty router and port forwarder for the network here. I had a spare switch, so I just went out and picked up a second NIC for my main Windoze 2000 machine. The instructions for sharing the internet connection are seemingly simple, but they don’t seem to work. I’ve got the new network set up in DHCP mode, and the machines are talking to each other, but I can’t see the internet from the client (i.e., pinging a known IP address times out, though I can do internal network pings). I tried turning off the Zone Alarm firewall for the LAN, but it didn’t seem to help. I’m obviously posting this from the machine with the working connection.

Anyone have any ideas?

[Update on Thursday morning]

OK, when I do ipconfig on the host machine, I get this:

***************************************
Windows 2000 IP Configuration

Ethernet adapter Interglobal LAN:

Connection-specific DNS Suffix . :
IP Address. . . . . . . . . . . . : 192.168.0.1
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :

Ethernet adapter AT&T DSL Connection:

Connection-specific DNS Suffix . :
IP Address. . . . . . . . . . . . : 67.101.124.115
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 67.101.124.115

Ethernet adapter Local Area Connection 2:

Connection-specific DNS Suffix . :
Autoconfiguration IP Address. . . : 169.254.163.94
Subnet Mask . . . . . . . . . . . : 255.255.0.0
Default Gateway . . . . . . . . . :

*******************************************

Note that “Local Area Connection 2″ is the physical ethernet connection for the DSL (called here AT&T DSL Connection”)

netstat -n yields:

*******************************************

Active Connections

Proto Local Address Foreign Address State
TCP 127.0.0.1:445 127.0.0.1:3093 ESTABLISHED
TCP 127.0.0.1:3093 127.0.0.1:445 ESTABLISHED

*******************************************

I’m having trouble talking to client machines right now–the LAN seems to be flaky. I can ping client from host, but I can’t ping host from client. More when I get one of more of the in communication.

Shop Goggles?!

Well, I guess later was sooner than I thought.

I repeat for emphasis (including obligatory whiz bang): Shop goggles?!

I always knew (well, as long as I’ve known him, which is getting to be a disturbingly long time) that Instapundit was a geek, but I never realized he was such a girlie boy.

Massachussetts

I made it safely to Wood’s Hole after driving for nine hours. A good stereo system is a bulwark against madness.

One observation I’ve made every time I come here (this is the fourth summer) – Massachussetts drivers suck. It’s not that they are incompetent a-holes like the drivers in DC. It’s that they yield with absolutely no rhyme or reason. For some reason the basic principle that safety in traffic is enhanced by everyone behaving in a predictable manner is just lost on them[*]. My sample is pretty biased, so maybe this is just a Cape Cod phenomenon, but I’ve already had two incidents in which a dangerous situation was created by someone deciding that despite the fact that they have right of way, they’ll stop and let me go. They are trying to be nice, oblivious to the fact that the people behind them think they are turning, so move to pass, just as the benevolent dimwit is waving me to move into a position to be T-boned. Perhaps its that this area is a vacation spot, so there are people from all over the place, each bringing their own local interpretation of how to behave in traffic.

[*] Incidentally, if you ever get a chance to drive in Brazil – don’t do it. At least don’t do it until you’ve aclimatized to the local driving customs. I thought Africa was bad, but Brazilians drive according to an unwritten set of rules which are universally understood by other Brazilian drivers and which bear only a passing relationship to the written traffic laws. The lack of carnage on the streets is due to the fact that everyone knows the unwritten rules, knows what to expect, and knows how other drivers will react.

Off to Wood’s Hole

I’m going on vacation for a week, so I may not post anything for a while. OTOH, I’m going to Wood’s Hole, where my wife is doing research at the Marine Biological Institute and there are all kinds of fascinating people to talk to, so there may be interesting stuff to blog about when I get back.

Off to Wood’s Hole

I’m going on vacation for a week, so I may not post anything for a while. OTOH, I’m going to Wood’s Hole, where my wife is doing research at the Marine Biological Institute and there are all kinds of fascinating people to talk to, so there may be interesting stuff to blog about when I get back.