Showing posts with label IPV6. Show all posts
Showing posts with label IPV6. Show all posts

Windows XP And Vista On The LAN Together

File and Printer Sharing in Windows Vista is not extremely different from File and Printer Sharing in Windows XP. There are new features, and wizard procedures, that work on top of Windows XP features and procedures. If you have a working network, with one or more computers that use Windows Networking, you probably know enough to get started.

There will be challenges though. One predictable challenge is the availability (or lack of availability) of drivers for devices that are operating system sensitive, like network adapters. This has inspired various attitudes, even rants, among the user community.

Computers running Windows Vista use the same layered network as previous versions of Windows, so start by reviewing the principles of layered network design and installation, and of layered network problem solving. And review various issues that affected Windows Networking on computers running Windows XP.

>> Top

System Updates Issues
With Windows Vista, as with Windows XP, Microsoft will issue periodic (and monthly) updates. Most updates are for security issues, and others for operability and / or stability. All updates are necessary, if recommended for your edition of Vista, and some may have a direct effect on your problem.

As an interim measure, possibly before an actual Service Pack, Microsoft has started issuing compatibility, performance, and reliability fixes, covering a variety of issues with Vista.

>> Top

Connectivity Issues
By default, computers running Vista will set the Broadcast flag, in the DHCP Discover packets, On. If your DHCP server (NAT router, or non-Microsoft dedicated server) doesn't support DHCP Broadcast, you'll have various problems - your computer may never get an IP address, or your IP connectivity may come and go unpredictably. To make your Vista computer compatible with Windows XP, (KB928233): turn the DHCP Broadcast flag Off. Besides the DHCP Broadcast difference, be aware of an interesting (KB931550): timing difference between the Windows Vista and XP DHCP clients.

One of the most interesting features in Vista (my opinion anyway) is the ability to dynamically determine Receive Window size for each individual Internet connection. Users of high speed broadband connections will be especially interested in this. Unfortunately, it appears that RWin AutoTuning may be a bit problematic. This setting has been observed to affect both LAN and WAN connectivity, and can cause instability, or lack of connectivity.

On laptop computers, and other computers with multiple network adapters, you'll see an inaccurate / inconsistent network status indicator, when the computer is first started.

Like every newer version of Windows, Windows Vista will use more resources on the host computer, and on any peripherally connected computers and routers. If your peripheral network equipment like routers are becoming aged, you'll be advised to upgrade or replace whatever you can.

The IPX/SPX Protocol is not provided in Windows Vista, though Novell does now provide a Netware client for Vista. NetBEUI, on the other hand, is now a part of history.

>> Top

Visibility Issues
One of the new features of Windows Vista is the Network Map, which runs at the Link Layer of the OSI Network Model, and offers functions similar to The Dude. The Network Map uses a discovery protocol called Link-Layer Topology Discovery (LLTD), which is not a normal part of Windows XP.

To be able to see a Windows XP server from a Vista client, using the Vista Network Map, you need to install (KB922120): the LLTD Responder on any Windows XP computers. The LLTD Responder isn't available for Windows 2000, so you won't be able to see a Windows 2000 server from a Vista client, using the Vista Network Map.

Even if you can't see a Windows XP or 2000 computer in the Network Map, though, you'll still be able to see it in Network Neighborhood / My Network Places, aka the Network window (Start - Network) in Windows Vista. And even if you can see a computer in the Network Map, you may still have to work on name resolution, or on sharing permissions, if you are going to actually access its resources.

The simplest visibility will be enjoyed with all computers in the same workgroup. By default, Windows Vista uses "Workgroup", while Windows XP uses "MSHome". If you leave workgroup names at default, the other computers will be visible in the Network (My Network Places aka Network Neighbourhood) wizard, but they won't be seen immediately, when you open the wizard. You may have to look under Entire Network - Microsoft Windows Network, for the different workgroups used by each set of computers. And with having multiple browse domains (workgroups), your browser infrastructure will be slightly more complex.

>> Top

Using A Windows Vista Client
Under Windows Vista, the personal storage (personal profile and other files and folders) container has been changed, from "C:\Documents and Settings", to "C:\Users". The folder "C:\Documents And Settings" will continue to exist, for backward compatibility, only as a junction point. On a mixed LAN, I would very carefully test sharing of either "C:\Documents and Settings" (with a Windows Vista client), or "C:\Users" (with a Windows XP client), before committing myself.

>> Top

Setting Up A Windows Vista Server
If you're adding a computer running Windows Vista to your network, you have to set it up as a server, so you can access it from your other computers. You do this using the Network and Sharing Center wizard, accessed by Start - right-click on Network, and select Properties. This is equivalent to running the Network Setup Wizard, in Windows XP.

  • Set the Network Location Type to "Private". This requires that your computers are secure, behind a perimeter firewall or a NAT router, and opens the standard Vista personal firewall to allow Server Message Blocks (SMBs) to pass between the computers. If your computer is directly connected to your Internet service, either get a NAT router, or leave the Network Location Type set to Public (which will prevent you from networking this computer).
  • Having set the NLT to "Private", you must now designate which services you wish for your server to provide or use. You should verify each setting before continuing, and change it if necessary.
    • File sharing.
    • Public folder sharing.
    • Printer sharing.
    • Password Protected Sharing (PPS) affects the above 3 services. Disabling PPS is the equivalent of enabling Simple File Sharing, in Windows XP.
  • Setup shared folders and printers. If you enabled PPS, you should setup access for individual users. If you disabled PPS, you setup access for "Guest" or "Everyone". Since Vista security is "deny by default (permit by demand)", "Everyone" doesn't automatically have access to newly created shares. Check the Security tab, for each share created, if you disable PPS.
  • Whether you setup the server with PPS Enabled (aka Advanced File Sharing, in Windows XP), or PPS Disabled, make sure that the account used for sharing is activated for network use.
    • If you Enable PPS, you can use either the Guest account, or a non-Guest account of your choice, but the chosen account has to be activated for network use.
    • If you Disable PPS, then the Guest account must be activated for network use. By default, Guest is disabled. If your server provides network access through the Guest account, be aware of its limitations.
    • Whether you use Guest, or a non-Guest account for access, the account used has to be added, explicitly, under Security, and under Sharing.
  • On a server running Windows Vista, the Administrative (Hidden) volume share of "C$ ("D$", etc) isn't defined, by default.

For an overview of the above, see Microsoft: File and Printer Sharing in Windows Vista

>> Top

Setting Up A Windows XP Server
If you have just one computer besides your computer running Vista, you may have to setup your first computer as a server too. On a computer running Windows XP, run the Network Setup Wizard. For a server connected behind a NAT router, select
This computer connects to the Internet through another computer on my network or through a residential gateway.
Running the NSW, and making that selection, is similar to setting the Vista NLT to "Private".

>> Top

Common Issues
Other than the network setup wizards used, Vista will be pretty similar to XP. You'll have the same challenges with Windows Networking.

>> Top

Editions Of Windows Vista and XP
There are 5 editions of Windows XP, which are basically 2 variants - Home and Pro.
  • XP Home is the equivalent of Vista Basic Home, with PPS permanently disabled.
  • XP Pro can use Advanced File Sharing (similar to PPS Enabled), or Simple File Sharing (similar to PPS Disabled).
  • The other 3 editions - Media Center, Tablet, and Pro x64 - are all variants of XP Pro, in terms of file sharing functionality.
  • With XP Pro, and with all editions of Vista, you can have Guest or non-Guest authentication. Note the limitations of Guest authentication carefully, some limitations aren't as obvious as they should be.
  • Whether you use the Guest account, or a non-Guest account, for authentication, make sure that the account used is properly prepared for network access.

There are also 5 well known editions of Windows Vista, plus several obscure ones which we probably won't encounter. The different editions of Windows Vista are completely different from Windows XP, in feature set differentation.

>> Top

Windows Vista and Older / Other Operating Systems
If you also have one or more computers running Windows 9x (95, 98, ME), you'll need to be aware of a significant difference between Windows XP and Vista, in Microsoft Windows And Authentication Protocols. But focus your mind on the future - Windows 95 / 98 / ME have a limited life span.

This will be a problem, too, if you have a Network Attached Storage (NAS) device. Many NAS devices, with unknown authentication abilities, will be a similar challenge. Some NAS devices will also try to act as a master browser on your network, and will cause master browser conflicts, and unreliable displays in Network (aka My Network Places).

>> Top

Windows Vista and Printers
If you are setting up your mixed LAN specifically to share a printer, note the additional challenges involved in sharing printers. Get file sharing working, first, then concentrate on getting working printer drivers that support Windows Vista. On a mixed network, the printer will have to support both Windows Vista, and Windows XP. And drivers for the client will probably differ from drivers for the server.

If you're having problems with printing from a computer running Vista, and the printer is shared by another computer, read Network Printing From A Windows Vista Computer.

>> Top

Windows Vista and Security
Depending upon what personal firewall you are using on your Windows Vista computer, you may have to set the firewall manually. It appears that Windows OneCare does not setup seamlessly, as Windows Firewall does, when you set the Network Location Type. And a recent change (September 2007) in Internet Explorer appears to affect Windows Networking access between computers.

>> Top

More References
For the above issues, and more, see

>> Top

Advanced Windows Networking Using Internet Protocol

Windows Networking is the subsystem that lets you share files and printers, between computers running the various versions of Windows. Server Message Blocks, also called SMBs, are the foundation of Windows Networking. SMBs provide several crucial functions.



(Note): If you're not familiar with the concept of network layers, take a few moments and read about the OSI Network Model.

SMBs are not transported directly over the various physical networking components, as Layer 1 or 2 traffic. SMBs may be transported over Internet Protocol (IP), as well as alternate protocols like IPX/SPX or NetBEUI.

Windows Networking has historically used NetBIOS Over TCP/IP (NetBT) as an intermediate transport for SMBs over IP. Windows 2000, XP, and Vista however, will transport SMBs over IP, without NetBT, using directly hosted SMBs.

To remain compatible with the older versions of Windows, a Windows Networking client, running Windows 2000, Windows XP, or Windows Vista, can use either directly hosted SMBs, or it can use NetBT. If any server supports directly hosted SMBs, the client computer in question will bypass NetBT, when communicating with that specific server.

This dual compatibility, which allows Windows 2000 / XP / Vista clients to communicate with computers running other editions of Windows, is not without cost. Trying for two communications channels, when establishing a connection with any server, increases program complexity and network traffic. In some cases, it may increase latency.

We need to resolve one major misconception. It may appear that when you Disable NetBT, you are disabling Windows Networking over IP. This is not correct. When you Disable NetBT, you are merely disabling hosting of SMBs over NetBT. You then end up with SMBs hosted directly over IP. But look at address resolution on your LAN, before trying this. Don't make this change blindly.

If your LAN
  • Has a domain.
  • Has computers running only Windows 2000, Windows 2002 (aka Windows XP), Windows 2003 (aka Server 2003), Windows 2006 (aka Vista), and Windows 2009 (aka Windows 7).
  • Uses DNS, properly setup, for name resolution.
then you may wish to Disable NetBT, and (KB204279): use directly hosted SMBs. If any of the above are not true, you should Enable NetBIOS Over TCP/IP. Be consistent on all computers.

In the TCP/IP Properties - Advanced wizard, WINS, select Disable NetBIOS Over TCP/IP. Alternately, if you have the Default NetBIOS setting selected (instead of "Disable" or "Enable") on your client computers, and you have a DHCP server (not a NAT router with DHCP), you can disable NetBT from a DHCP server setting.

If you use directly hosted SMBs, whether alternately or exclusively, be aware of the security implications.
  • NetBT uses TCP and UDP ports 137 - 139.
  • Direct hosted SMBs use TCP port 445.

Be sure that all personal firewalls have the proper ports opened.

Here are the relevant ports used by SMBs over NetBT, per IANA port number allocation:

netbios-ns 137/tcp NETBIOS Name Service
netbios-ns 137/udp NETBIOS Name Service
netbios-dgm 138/tcp NETBIOS Datagram Service
netbios-dgm 138/udp NETBIOS Datagram Service
netbios-ssn 139/tcp NETBIOS Session Service
netbios-ssn 139/udp NETBIOS Session Service

And the relevant ports used by directly hosted SMBs:

microsoft-ds 445/tcp Microsoft-DS
microsoft-ds 445/udp Microsoft-DS


Similar to the effect of a personal firewall, SMBs can be setup to use secure channel communication, by using SMB Authentication and Encryption. If you ever see
The account is not authorized to log in from this station.

then check SMB Encryption and Signing settings.

And, if you have an integrated security suite (previously sold as anti-virus protection), you may have an anti-worm component protecting you. Anti-worm protection, if not correctly configured, may interfere with any or all of the above NetBT traffic. Different brands of products will cause different problems.

For more information:

>> Top

NetBIOS Over TCP/IP

Microsoft Windows, in its default state, uses TCP/IP, and NetBIOS Over TCP/IP, for networking. Sometimes, we forget this detail. NetBT is so easily overlooked, yet it is essential.

If we are looking at the output from "ipconfig /all", and we see


IP Address. . . . . . . . . . . . : 192.168.1.50
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 192.168.1.11
192.168.1.33
NetBIOS over Tcpip. . . . . . . . : Disabled
Lease Obtained. . . . . . . . . . : Wednesday, April 16, 2003 11:19:12
Lease Expires . . . . . . . . . . : Wednesday, April 23, 2003 11:19:12


Obviously, we're going to correct that. But what if we simply see

IP Address. . . . . . . . . . . . : 192.168.1.50
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 192.168.1.11
192.168.1.33
Lease Obtained. . . . . . . . . . : Wednesday, April 16, 2003 11:19:12
Lease Expires . . . . . . . . . . : Wednesday, April 23, 2003 11:19:12

Do we see any problem there? Probably not. Look in the TCP/IP - Advanced Properties wizard, WINS tab. There are 3 possible settings for NetBIOS Over TCP/IP
  • Default.
  • Enable.
  • Disable.

The last setting, Disable, becomes apparent when we see the first example above. But what if if we see the second example above? Well, that display can result from either the "Default", or the "Enable" setting. If it's not showing Disabled, it could be either.

The Default setting, according to the wizard, is for

Use NetBIOS setting from the DHCP server.

If your LAN
  • Has a domain.
  • Has computers running only Windows 2000, Windows 2002 (aka Windows XP), and Windows 2003 (aka Server 2003).
  • Uses DNS, properly setup, for name resolution.
then you may wish to disable NetBT, and use directly hosted SMBs.

But what if your LAN has a NAT router providing DHCP services, and / or has no domain? NAT routers are Operating System independent, and NetBT is a Microsoft Windows Networking feature. NAT routers have no setting for NetBIOS Over TCP/IP. If you select "Default", and you have a NAT router, what network functionality do you get?

The challenge is that this one setting affects multiple functions between your computer, and other computers, in both directions.
  1. Browsing: Ability to see other computers.
  2. File sharing: Ability to access resources on other computers.
  3. Name resolution: Ability to find out the addresses of other computers.


Depending upon what network hardware and software you have, any or all of the above functions may or may not work, in either direction (incoming or outgoing), between any pair of computers. And each different pair of computers may yield a different set of symptoms. If you have a NAT router providing DHCP services, the only way to deal with this reliably is to Enable NetBT consistently, on all computers.

In the TCP/IP - Advanced Properties - WINS wizard for all relevant network connections,

  • Select the radio button "Enable NetBIOS over TCP/IP".
  • Hit OK 3 times.
  • Close Network Connections, after enabling NetBT on all relevant network connections.

If you still see

NetBIOS over Tcpip. . . . . . . . : Disabled
after Enabling NetBT, check the TCP/IP NetBIOS Helper service.

Be safe - don't settle for "Default".

>> Top

LSP / Winsock Analysis Using A Log From Autoruns

The LSP / Winsock component in the Internet Protocol network stack is complex. It's used by the Windows OS, and by malware and anti-malware alike, to allow, and to affect, your access to the network.

Problems with the LSP / Winsock layer can be a lot of fun to diagnose. Generally, the problem is termed "corruption", and you are urged to use any of several tools / procedures to simply reset it. But what if you suspect a problem, but a simple reset isn't possible? Or what if you want to make an educated decision about a problem, or to help somebody else do the same?

You might start by enumerating (inventorying) the system components registered in the stack. One tool for doing this is the SysInternals product, Autoruns.

Autoruns, like many SysInternals products, needs no complicated install process. Just download it, and run it. Make sure that "Verify Code Signatures", under Options, is enabled. It will present an incredibly detailed GUI inventory of all of the processes started by your computer automatically, in a tabbed display. One of the tabs, labeled "Winsock Providers", will list all components registered in the LSP / Winsock layer.

If you save an Autoruns log, you can extract the Protocol_Catalog9 portion of the log, which will contain a text based inventory of LSP / Winsock components. Each section of the log is headed by the complete path of the key to its root, in the case of Protocol_Catalog9, that's


HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9

Protocol_Catalog9, on my computers, is the next to last section in the log.

Below, in Attachment A, you will find an example of the relevant information, extracted from a log from one of my computers. A log from one of your computers may or may not contain the same entries - and the differences might point us towards a solution to your problem. If your log includes entries that are listed as "(Not verified)", check them out with Online Analysis (free).

If none of these details interest you, you are welcome to simply reset your LSP / Winsock, using any of the 6 recommended procedures and tools. It's your computer, and your dime.


Attachment A - Autoruns Log: LSP / Winsock Enumeration

HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
+ DiamondCS TCP/IP Layer [RAW] dcsws2 (Not verified) DiamondCS c:\windows\system32\dcsws2.dll
+ DiamondCS TCP/IP Layer [TCP] dcsws2 (Not verified) DiamondCS c:\windows\system32\dcsws2.dll
+ DiamondCS TCP/IP Layer [UDP] dcsws2 (Not verified) DiamondCS c:\windows\system32\dcsws2.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{4AA95793-B5DE-4179-8D2C-2469C3D63D3F}] DATAGRAM 2 Microsoft Windows Sockets 2.0 Service Provider (Verified) Microsoft Windows Publisher c:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{4AA95793-B5DE-4179-8D2C-2469C3D63D3F}] SEQPACKET 2 Microsoft Windows Sockets 2.0 Service Provider (Verified) Microsoft Windows Publisher c:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{64409384-CE61-4B92-ADFA-77A210FA4C80}] DATAGRAM 3 Microsoft Windows Sockets 2.0 Service Provider (Verified) Microsoft Windows Publisher c:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{64409384-CE61-4B92-ADFA-77A210FA4C80}] SEQPACKET 3 Microsoft Windows Sockets 2.0 Service Provider (Verified) Microsoft Windows Publisher c:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{7D8C1637-F016-494D-B66A-1BD865F1E19F}] DATAGRAM 7 Microsoft Windows Sockets 2.0 Service Provider (Verified) Microsoft Windows Publisher c:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{7D8C1637-F016-494D-B66A-1BD865F1E19F}] SEQPACKET 7 Microsoft Windows Sockets 2.0 Service Provider (Verified) Microsoft Windows Publisher c:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{9E8A31FA-5327-49A2-8091-E9C207367658}] DATAGRAM 8 Microsoft Windows Sockets 2.0 Service Provider (Verified) Microsoft Windows Publisher c:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{9E8A31FA-5327-49A2-8091-E9C207367658}] SEQPACKET 8 Microsoft Windows Sockets 2.0 Service Provider (Verified) Microsoft Windows Publisher c:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{AE574BAC-9E75-4917-B07E-EC7CB922CF5D}] DATAGRAM 1 Microsoft Windows Sockets 2.0 Service Provider (Verified) Microsoft Windows Publisher c:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{AE574BAC-9E75-4917-B07E-EC7CB922CF5D}] SEQPACKET 1 Microsoft Windows Sockets 2.0 Service Provider (Verified) Microsoft Windows Publisher c:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{B7E18D15-D9B1-4295-9DAD-C733C695294F}] DATAGRAM 0 Microsoft Windows Sockets 2.0 Service Provider (Verified) Microsoft Windows Publisher c:\windows\system32\mswsock.dll
+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{B7E18D15-D9B1-4295-9DAD-C733C695294F}] SEQPACKET 0 Microsoft Windows Sockets 2.0 Service Provider (Verified) Microsoft Windows Publisher c:\windows\system32\mswsock.dll
+ MSAFD Tcpip [RAW/IP] Microsoft Windows Sockets 2.0 Service Provider (Verified) Microsoft Windows Publisher c:\windows\system32\mswsock.dll
+ MSAFD Tcpip [TCP/IP] Microsoft Windows Sockets 2.0 Service Provider (Verified) Microsoft Windows Publisher c:\windows\system32\mswsock.dll
+ MSAFD Tcpip [UDP/IP] Microsoft Windows Sockets 2.0 Service Provider (Verified) Microsoft Windows Publisher c:\windows\system32\mswsock.dll
+ RSVP TCP Service Provider Microsoft Windows Rsvp 1.0 Service Provider (Verified) Microsoft Windows Publisher c:\windows\system32\rsvpsp.dll
+ RSVP UDP Service Provider Microsoft Windows Rsvp 1.0 Service Provider (Verified) Microsoft Windows Publisher c:\windows\system32\rsvpsp.dll

Solving Network Problems - A Tutorial

Networking computers is a pretty complex process, and there are a lot of possibilities for problems. When you have a problem, the symptoms may not always point immediately to the problem. You may be able to avoid solving the problem - maybe you can blame it on somebody else, or maybe you can use a different network technique. But you're better off, in the long term, with finding and solving the problem.

One of the more common symptoms of a networking problem is the dreaded "access denied" error, which is where I started this website long ago. Now access denied, as reported by Windows, can be caused by anything from "I can't identify the address of the resource (server or file) requested" to "The server says that I may not access this file".

Sometimes you have multiple problems, causing your inability to access the other computer. Maybe the cable between your computer and the other computer is bad, AND the other computer is setup so you may not access the file. You have to solve each problem, one at a time.

If you see "access denied", you check the server, and notice that your account is specifically set to not have access, fine. You fix the "you may not have access" setting, try again, and still get "access denied". So now, there are 3 scenarios.
1) You just fixed one problem, and there is another problem.
2) You truly found a problem, but didn't fix it properly.
3) You didn't find the problem, and may have caused another problem by the change you just made.

With scenarios 2 and 3 weighing heaviest in your mind, you reverse the change you just made, since "that didn't fix anything". You then start looking for other possibilities, and find a broken network cable. You buy a new cable, try that, and still get "access denied". Now totally frustrated, you get into the forum of your choice, and whine about "I tried everything, and still have a problem". And you're right - you do have a problem. And the biggest one is that you don't know how to solve problems.


  1. Solve Network Problems From The Bottom Up
  2. Test Each Component, and Problem, Individually
  3. Test Using Previously Tested Components
  4. Look For Relational Patterns
  5. Look For Historical Patterns
  6. Use Diagnostic Aids and Tools
  7. Research The Problem
  8. Exercise Patience and Persistence, and Publicise Your Results


>> Top

Rule One - Solve Network Problems From The Bottom Up

Computer networking is best defined in layers, as you can see from the OSI Network Model. Logical networking, like TCP/IP, connects to physical networking, like Ethernet or WiFi. Server Message Blocks (aka SMBs) provide file sharing, which is what you frequently need help with; and SMBs connect to the logical network in a variety of ways.

If there's a problem with your Ethernet connection, you have to fix that first. In order to fix it, you have to be able to test it. Don't just replace the Ethernet cable, wait a few minutes, and look in Network Neighborhood for everything to become visible. That might work once, but it won't work that way all of the time.

Always diagnose a network problem, one layer at a time.

>> Top

Rule Two - Test Each Component, and Problem, Individually

When you have a network problem, test each component individually. A physical connectivity test may be simple, such as observing the lights on the router and the network card. Or you may have to get a network tester. Those pretty blinking lights are functional, so use them. And Read The Manual, to find out what diagnostics are available for any product.

But please don't test a physical network problem by looking at Network Neighborhood. There are dozens of possible problems with Network Neighborhood - and physical problems are just one possible cause.

Find out what diagnostics are available for each network component. Test each component, one by one.

>> Top

Rule Three - Test Using Previously Tested Components

If you have more than one computer, having a spare (never used) network cable, and other components, is not at all a waste of money. Having a spare cable, which you can try at 2:00 in the morning, or when your friends drop by unexpectedly, is well worth the extra expense.

Unfortunately, any unused (totally new) component may not always work - anything you buy may be defective. Worse yet, it may work partially - it may send but not receive. Whenever possible, use components that you have tested. Buy a new cable, if you wish, but take a known good cable from another setup, and put it into the problem setup. Put the new cable into the currently working setup, and test it there first.

If the known good cable (used, from the previously working setup) doesn't work, when used in the currently not working setup, put it back where you got it. Make sure that it continues to work in the previously working setup. It's always possible that you broke it when removing it from the previously working setup. If you now have TWO non working setups, you're going to have to apply these principles to both problems, but separately. Be aware of the possibilities here.

Take the new (previously spare) cable, and test IT in the previously working setup. If it works now, then you can use it in the current problem setup for testing. Then you'll need a second spare, and this discussion could go on still further.

Maybe you have multiple problems. A defective router port, and a bad network cable, is always a possibility. Use known good components, and test one component at a time, when troubleshooting a problem.

>> Top

Rule Four - Look For Relational Patterns

Diagnosing a network problem can be tricky. If two computers can't communicate, how do you know where the problem is? Is it the first computer, that isn't sending? Or is it the second computer, that isn't receiving? Or could it be both computers (again, compound problems)?

If you have three computers, you're much better off. With three computers, which computer is working differently? Can you access Computer A from Computer B, but not from Computer C? Then look at Computer C first. Or, if Computer A can't be accessed from either B or C, look at Computer A first.

If the problem is intermittent, and involves connectivity interruption, use PingPlotter, running on all computers simultaneously, to look for relational patterns. For Internet Service problems, set PingPlotter pinging a host on the Internet, maybe your ISPs DNS server, or www.yahoo.com. For a LAN problem, ping your router. Compare the output from all computers, periodically. Look for similarities in connectivity interruption.

>> Top

Rule Five - Look For Historical Patterns

When did the problem start? Did you just apply system upgrades? DOHH. Google for "885250", as an example, to see where this leads.

Does the problem come and go? Is there any pattern there? A time of day, or day of week pattern? Maybe a problem is connected to the weather. Broadband connectivity is not weather transparent - all of the wires involved can be affected by cold / heat, and by dryness / moisture. Maybe the problem is related to your electrical use in your house - coming home, and running the microwave oven, for instance.

One way to look for historical patterns, objectively, is to use Ping Plotter. For Internet Service problems, set PingPlotter pinging a host on the Internet, maybe your ISPs DNS server, or www.yahoo.com. For a LAN problem, ping your router. Examine the output from PingPlotter, and see when and where the problems are occurring.

If PingPlotter shows loss of connection between your router and your IPSs gateway, you have to get your ISP involved. And you don't have to listen to them telling you to fix your computer, because the problem is not between your computer and the router. A picture can be worth a thousand words, if you have to deal with your ISP.

>> Top

Rule Six - Use Diagnostic Aids and Tools

In order to diagnose a problem, you have to have tools to help. I have a small, carefully chosen suite of software tools, which I inventory in My Personal Toolbox. Other helpers have their own favourites. Find which ones work for you, and always look for others.

Besides software tools, use diagnostics provided by the equipment, and hardware tools, if you have them. The lights on the router, and on the network cards, are a start. Having a network tester is a good idea too.

One of the simplest tests for Internet Protocol connectivity is the ping utility. Whenever you have a problem, almost any expert will eventually ask you to "Ping one computer from the other".

I use CDiag for comprehensive and repetitive testing between multiple computers. CDiag performs simple tests, in combination, between each computer and each other on the LAN, and makes it simpler to assemble all of the symptoms into one report. CDiag is pretty simple - but it can be very useful.

>> Top

Rule Seven - Research The Problem

With a computer problem, you have a major advantage over a non-computer problem. Computer owners frequently use the web to get help. Unless you live totally on the edge, the chances are that any problem YOU have has already been experienced, and written about, by somebody else. So Google for it. Or ask for help - but ask intelligently.

>> Top

Rule Eight - Exercise Patience and Persistence, and Publicise Results

If you have a problem, be patient when dealing with other people who help, and in with yourself as you learn. You won't solve any problem by giving up, nor will you get help any faster from someone else. Trust those who try and help you, and provide the diagnostic information that they request, and as they request it. Be tolerant of the diagnostic process, and work with the helpers.

But be persistent too. Followup with anybody who promises to help you. Don't just ask for help, and go away. Wait a while, and ask again.

And be objective - whether you are getting help from a volunteer online, a Tech Support person employed by your employer, or a vendor of a product or service.

If you follow this guide, and you find and fix one problem, but everything still doesn't work, be persistent. Start again from the beginning, and question everything. Go thru this guide in more detail, and look for another problem. And ask for help again, maybe in a different forum.

Come back here from time to time. I write, and rewrite, this blog constantly. That's the advantage of a web document (website) over a book - this is a dynamic medium, and this blog is constantly changing.

And publicise your results. When you get results, or when you don't, let folks know. Everybody benefits from collaboration, and sometimes knowing what doesn't work is as useful as knowing what does.

The Internet is huge, and growing all of the time. Keep at it until everything works, and don't give up. Well, persist to a limit, anyway.

>> Top

Windows Networking And Alternate Transports

Windows Networking is the suite of programs that provide file and printer sharing between computers running Microsoft Windows (and compatible Operating Systems, such as Linux). Windows Networking runs at the Application level of the OSI Network Model, and, in its default configuration, uses NetBIOS Over TCP/IP (NetBT) and TCP/IP, for logical connectivity. It can be customised to use alternate transports, like IPX/SPX or NetBEUI.

Microsoft supports only NetBT and TCP/IP, though you may use IPX/SPX or NetBEUI, if you're prepared to deal with the support issues. There are advantages and disadvantages to using either alternative. (Update): Windows Vista will not support NetBEUI.

Similar in effect to IPX/SPX / NetBEUI, we have a commercial product called Network Magic. Network Magic requires no complicated configuration, you just install it and it works. Unfortunately, nobody that I know knows how it works, or if it's OSI Network compliant. And, just as the disadvantages of IPX/SPX / NetBEUI, if there's a problem with the network outside its scope of effect, you may not be able to diagnose such a problem as reliably as with IP.

Advantages Of Alternate Transports


  • No filtering problems. A misconfigured or overlooked personal firewall can cause problems with IP based networks. Neither IPX/SPX nor NetBEUI is affected by firewall problems.
  • Segments are isolated. Any separate networks, connected by routers, won't pass IPX/SPX or NetBEUI based traffic between them. Windows Networking simply won't leak onto any networks connected by routers, such as the Internet.
  • Easier to setup. There's no need to configure TCP/IP settings, both IPX/SPX and NetBEUI attach directly to the hardware, and both setup automatically.


Disadvantages Of Alternate Transports

  • Network complexity. You'll likely have redundant system components in use by each computer, and redundant network traffic between each computer.
  • Lack of diagnostics. The ipconfig and ping utilities can identify logical and physical connectivity problems on an IP network. This is not available on non-IP networks, and may not give consistent results when you deal with problems on mixed networks.
  • Lack of filtering. Firewalls only filter IP network traffic.
  • Limited effect. Using alternate transports provides a workaround only for TCP/IP configuration problems, or filtering problems. It does nothing for physical problems, or for problems caused by authentication / authorisation.
  • Only TCP/IP can link multiple segments. Any separate networks, connected by routers, won't pass IPX/SPX or NetBEUI based traffic between them. If your network is segmented, for physical reasons, you'll have to bridge the segments (which is, by design, what NBT does).
  • Have to be setup properly. If just one computer on the network attaches Windows Networking to NBT, convenience and security gains are eliminated.


>> Top

Filtering
IP traffic, by design, can be filtered by personal firewalls and routers. IPX/SPX and NetBEUI, which attach directly to the physical transport and in parallel to TCP/IP, are not affected by IP based filtering. This has its good side and its bad side.

If you're having a problem with a personal firewall on a computer, you can work around that problem. IPX/SPX and NetBEUI are not affected by personal firewalls.

However, if you depend upon a personal firewall providing protection against malicious network traffic, you won't have that. Any malicious network traffic, IPX/SPX or NetBEUI based, won't be filtered.

>> Top

Segmentation
IP traffic, by design, passes thru routers; IPX/SPX and NetBEUI traffic doesn't. This has its good side and its bad side.

If you have a network in a single segment, and you use IPX/SPX or NetBEUI to provide a transport for Windows Networking, all Windows Networking traffic will stay on that segment. All shares will be totally safe from malicious access from other network segments, including the Internet.

If your network includes multiple segments, connected by routers, and you use IPX/SPX or NetBEUI as a transport for Windows Networking, all Windows Networking traffic will stay on each segment. Computers on separate segments will be unable to access each other, unless you build bridges between the segments. NBT was designed as that bridge.

>> Top

Setup
A network, using IPX/SPX or NetBEUI, is easy to setup. It's not so easy to setup properly though.

A simple IPX/SPX or NetBEUI network, in a single segment, requires no configuration. Both transports essentially set themselves up. There's no subnetting or other complicated TCP/IP settings to make.

If you want to access the Internet from your computers, though, you will still have to have TCP/IP on each computer. If you do not separate Windows Networking from TCP/IP on even one single computer, your entire Windows Networking environment may be exposed. And without protection by personal firewalls, all computers may be at risk more than if they were using NBT.

>> Top

Complexity and Use of Network and System Resources

IPX/SPX and NetBEUI are not significantly more chatty than NBT, and do not use significantly more network or system resources. If your computers only use IPX/SPX or NetBEUI, there is no complexity or resource problem.

But, if your computers will be accessing the Internet too, you'll need TCP/IP on each computer. IPX/SPX, NetBEUI, and TCP/IP, although each run under the same operating system, use different system components. And while they each generate traffic on the same network, the content of that traffic is different. So, with multiple combinations of IPX/SPX, NetBEUI, and TCP/IP operating on your network, your computers will have to work harder (to use multiple protocols), and your network hardware will have to work harder (to transport multiple protocols, with a higher volume of traffic).

If Windows Networking functions like browsing, or name resolution, run thru dual protocols on one computer, or if all computers on the LAN aren't identically setup and different computers run services thru different protocols, you'll really have problems. And some problems might not be immediately obvious either.

Separating Internet traffic (using TCP/IP) from Intranet (Windows Networking) traffic (using IPX/SPX or NetBEUI) has an effect similar to using a Virtual LAN. But using a common protocol (TCP/IP) with a properly designed layered security strategy is more efficient in the long run.

>> Top

Network Diagnostic Tools

With any network, any time there's a problem, such as an "access denied" error, you'll want to first look for a possible physical problem (by observing the lights on the network devices, and by running Device Manager diagnostics). Having dismissed the physical possibility, on a TCP/IP network, you'll be looking at IPConfig, and pinging one computer from the other. You have to eliminate lower level problems, before you can diagnose higher level problems.

If you have TCP/IP on each computer, for Internet access, you can still use ipconfig and ping. But if Windows Networking is using a separate transport, neither ipconfig or ping will be conclusively valid.
  • Just because you have IP connectivity (valid ping results), that doesn't mean that you have IPX connectivity.
  • Just because your computers are on separate subnets (from a bad IP configuration, indicated by ipconfig), you can't expect to find a NetBEUI connectivity problem.
  • If you don't install TCP/IP on each computer (or if you completely detach it from any computer), then ipconfig, ping, and other IP based diagnostics won't provide consistently relevant results.


>> Top

Limitations of Effectiveness

If you have problems with either IP configuration, or with a personal firewall, either IPX/SPX or NetBEUI will provide a good workaround. But, if the problem causing the "access denied" error is a bad cable or connection, or if you haven't setup file sharing authentication / authorisation properly, you'll have the same problem with IPX/SPX or NetBEUI. But now you won't have diagnostic tools to identify the problem.

>> Top

File Sharing Under Windows XP / Vista

Depending upon your specific needs, you can get Windows XP in any one of five editions. Of those five, the choice of the two best known ones - XP Home and XP Pro - will differently affect your ability to share files. Both the Home and Pro editions have their advantages and disadvantages. There are also 5 well known editions of Windows Vista, though the distinctions between the Home and Business (not Professional) edition groups will be less relevant to Windows Networking issues.

This article will focus on how Windows XP and Vista are similar, with specific differences noted. In Windows XP And Vista On The LAN Together, I focus on differences in Windows Vista.

Please spend a few minutes deciding how you wish to use your computer, and whether you wish others to use your computer. If your computer is running Windows XP, make sure that you know which edition of Windows XP it is.

Windows XP Home has few options, and is easier for the typical home user to setup. Windows XP Pro / Vista (in its various editions) is more versatile, and can be used in different ways, depending upon what other computers are on the LAN, and how secure you want your shared data to be.


Simple File Sharing

If your computer runs XP Home, then it has Simple File Sharing already. SFS, which only uses Guest authentication, cannot be disabled under XP Home, without some work.

If your computer runs XP Pro, or XP Media Center Edition, it may have SFS. If you want to enable Simple File Sharing on a computer running XP Pro or MCE, from Windows Explorer:

  • Select Tools - Folder Options.
  • On the Views tab, scroll to the end of the long Advanced settings list.
  • Check "Use simple file sharing".

To use Simple File Sharing on any XP server, Home or Pro, make sure that the Guest account is properly activated, and the password is consistently set (blank or non-blank), on both the client and the server.

On a computer running Windows Vista, you disable Password Protected Sharing, giving the equivalent of Simple File Sharing.

Please note the limitations of Guest authentication, when working with Simple File Sharing / PPS Disabled.

>> Top

Advanced aka Classic File Sharing

Advanced aka Classic File Sharing is available, as an alternative to Simple File Sharing, on XP Pro or MCE. To use AFS to it's full advantage, you need to have formatted the drives, on the server, with NTFS. You then need to disable Simple File Sharing. From Windows Explorer:

  • Select Tools - Folder Options.
  • On the Views tab, scroll to the end of the long Advanced settings list.
  • Uncheck "Use simple file sharing".

On a computer running Windows Vista, you enable Password Protected Sharing, giving the equivalent of Advanced File Sharing. Unlike Windows XP, the option to enable PPS is available in all editions of Windows Vista.

Next, identify a folder that you want to share on the network, but share selectively.

  • Setup and use an account (with matching password) on both the client and the server.
  • Make sure that the account is properly activated on the server.
  • In Windows Explorer, right click on the folder in question, and select Properties.
  • On the Sharing tab, select "Share this folder" and give the share a name.
  • Hit Permissions, and make sure Everyone has full rights.
  • On the Security tab, find and select your account in the "Group or user names" list. If your account isn't in the list, Add it.
  • In the Permissions list, make sure your account has the appropriate permissions. And make sure that no other accounts have inappropriate permissions.

Note that, if you want some openly available shares also, this can be done quite easily.

  • On the Sharing tab, select "Share this folder" and give the public share a name.
  • Hit Permissions, and make sure Everyone has full rights.
  • On the Security tab, find and select the group "All Users", "Everyone", or "Users", in the "Group or user names" list.
  • In the Permissions list, make sure the group selected has the appropriate permissions.
  • Setup Guest, (with matching or no password) on both the client and the server.
  • Make sure that Guest is properly activated on the server.

Please note the limitations of Guest authentication, when setting up any share for non-selective access. And if you have a LAN with both XP Home and XP Pro systems, be careful when enabling Advanced File Sharing on an XP Pro system. Unbalanced authentication can have complex results.

>> Top

Get The Terminology Right Here

When you look at the Welcome screen, and you have multiple users setup on your computer, you'll see a list (or group) of users, identified by User Name. When you change a password, or the picture associated with that user, you'll use the User Accounts wizard in Control Panel. Here too, you'll see a list of users, identified by User Name.

If you rename a user, or if you use any advanced procedures or wizards, there is another very relevant term - account. When you setup a user, using the User Accounts wizard in Control Panel, Account = User Name. For each account / user, a set of subfolders, under "C:\Documents and Settings" is created. This is the user profile.

  • You can change a User Name at any time, but the account, and the user profile, stays the same.
  • You can make much more versatile changes using the Control Panel - Administrative Tools - Computer Management - Local Users and Groups - Users wizard. Here you can change the account name, and profile path.
  • If you disable the Welcome screen, you login using the account name and password.

So, if you ever rename a User, and see elements of the previous name, you now know why.

>> Top

Activate An Account Properly For Network Access

Whether you're depending upon the Guest account, or a non-Guest account, for authentication, the account that you use has to be properly activated. You use the Control Panel - User Accounts applet, to activate (or deactivate) an account for local use.

There are two possible ways to activate (or deactivate) an account for network access:

  • Run the "net user" command. Enter, in a command window (which will be slightly different, for Windows Vista):

    net user AccountName /active:yes

    • (Substitute actual account name for "AccountName").
    • (Substitute "no" to deactivate).


    NOTE:There are 4 "words" (sequences of non-blank characters, separated by spaces) in the command. If you have any doubt about where a space is needed, copy and paste as above (substituting the account name, and "no" or "yes", as appropriate).
  • Alternatively, for Vista Business or Ultimate, or XP Pro, run (Control Panel - Administrative Tools - ) Computer Management. Under System Tools - Local Users and Groups - Users, find the account (Guest or non-Guest) in question. Doubleclick (or rightclick, and select Properties), and clear (or check) "Account is disabled".

Finally, for XP Home, for XP Pro using Simple File Sharing, or for Vista with PPS Disabled, make sure that Guest, in addition to being activated, has the appropriate rights.
>> Top

Synchronise Passwords On Accounts

Always synchronise passwords (for the Guest or non-Guest account) on all computers - make them identical (or blank) on each. For best results, make your password policy consistent throughout your network.

To set the password, you need to run the UserPassword applet.

  • Enter, in a command window, "control userpasswords2" (less the "").
  • Select the account of interest in the User Accounts list.
  • Hit the Reset Password button.
  • Type either a blank, or non blank password, identically, into both "New password" and "Confirm new password" fields.
  • Hit OK twice.

Synchronising passwords can be tricky in a mixed LAN (home and business/pro operating system editions together). With home editions (Vista or XP Home), the default is to have no password on the Guest account (it is, after all, anonymous). With business / professional editions (Vista Business / Enterprise / Ultimate, XP Pro), you have to Disable the Local Security Policy setting, under Security Options, "Accounts: Limit local account use of blank passwords to console logon only", if your server is going to allow network access using accounts with blank passwords.

>> Top

Making File Sharing Work

Once you get past the issues involved in accessing the server, such as browsing and name resolution, there are the issues of accessing the data itself - authentication ("Who are you?"), and authorisation ("Do we want you to have access here?").

What authentication method are you using?


The message

Logon failure: the user has net been granted the requested logon type at this computer.

is easy to resolve under XP / Vista Pro, but may require extra effort under a home edition. Remember, the edition of the operating system on the server is what's relevant here.

With XP / Vista Pro, there are a pair of Local Security Policy lists, under User Rights Assignment.

  1. "Deny access to this computer from the network".

  2. "Access this computer from the network".




Authentication varies depending whether this is a domain or a workgroup.

  • In a domain, you need an activated account on the domain controller.
  • In a workgroup, you need identical, activated accounts, with identical passwords, on both the client and the server.


Authorisation is described in Server Access Authorisation.

If the files and folders in question have been properly setup and shared as above, and you're getting only partial access (maybe Read, although you intend to grant Write access), check both the Share and NTFS Authorisation lists.

Remember that if you grant access, to the share in question, to "Everyone", that refers to Everyone who is properly authenticated. Either a properly setup Guest account (on the server), or non-Guest account (for a workgroup, on both the client and server, with matching passwords), is still required.

Note: Vista uses deny by default, so if you want "Everyone" (Guest) to have access, you have to explicitly add permission - new shares don't give Full permission automatically (though in some cases, "Everyone" may have read access by default). Always check Security and Sharing, when there is a question.

With XP / Vista Home, you don't have the Local Security Policy Editor. And Simple File Sharing doesn't give you the ability to set access rights either. In that case, you'll have to use extra software and procedures.

If you're using Guest authentication, and still getting "access denied" after all of the above steps, check the restrictanonymous setting.

Even with all of the above advice, there are known scenarios, with varying symptoms, with but one common factor - recent (or not) application of certain Windows Updates.

Next, look at the complete and exact text in any observed error messages. Some very obscure errors have very simple resolutions.

And finally, repeat Troubleshooting Network Neighborhood.

>> Top

Windows XP / Vista In A Domain

If you have a network with more than 3 or 4 computers, running Windows XP or Vista, a domain is worth considering. Both Windows XP Home and XP Pro (and their related editions), and the various editions of Vista, can be used in a domain, but in different ways.

A Windows XP / Vista Home edition computer can only join a workgroup, it can not join a domain. Windows XP Media Center has the same internal components as XP Pro; however, XP MCE 2005 (KB887212): will not join a domain either.

If a Home edition client computer is on the same network with a domain, the computers in the domain should be visible, in Network Neighborhood, under Entire Network - Microsoft Windows Network - (name of domain). The Home edition computer(s) will not, however, be visible from other clients, or from the servers, in the domain, unless there is a browser server available for the workgroup of which the computer is a member (or if that computer is running the browser on its own).

If a Home edition client computer is on the network with a domain, the computer can be made a Member of a workgroup, with the workgroup name the same as the domain name. This will allow the servers in the domain to be visible, in Network Neighborhood, and will make the client visible from other clients, or from the servers, in the domain.

Users on a Home edition client will have to authenticate to any domain servers as they would in a workgroup - using accounts defined locally on each client and server.

A Windows XP Professional computer can join a domain, just as any other Windows NT based computer, and can access domain resources in the same way. However, several XP features will be unavailable:

  • Fast User Switching.
  • Simple File Sharing.
  • Logon Welcome Screen.


Depending upon how your domain is setup, an XP / Vista computer may have problems logging in to the domain, and may require changes in the domain itself.

>> Top

Guest Authentication

Guest authentication is an option under Windows XP Pro with Advanced File Sharing, and for Windows Vista with Password Protected Sharing Enabled. For Vista with PPS Disabled, XP Pro with Simple File Sharing, and XP Home, Guest is the only available authentication. Guest authentication is part of the authentication decision process, in general.

With Guest authentication, you have normally two choices for any otherwise shareable folder: whether to allow access to it, and whether to allow read-only or read-write access. All shared folders and files are equally accessible by everybody who has access to the network.

If your server only uses Guest authentication, any shared data is offered, on the network, based upon the status of the Guest account on the server. Other accounts on the server, and on any clients, will not be relevant. Make sure that the Guest account is properly activated for network access.

The Guest account, by definition, is a limited access account, and is similar to anonymous access under Windows. If your server only uses Guest authentication, your computer can't be accessed with administrative authority, thru the network.

Shares which require administrative access, such as C$, "C:\Program Files", and "C:\Windows", can't be accessed thru the network, if shared using Guest authentication. No matter what authority you are logged in with, to a client computer, when you access any server using the Guest account, those shares, and any folders and files within those shares, will be inaccessible. Any files that you want to be accessible thru the network should be kept in the Shared Documents folder, and they will be accessible to everybody.

Remember that the various folders in "C:\Documents and Settings" ("C:\Users" in Windows Vista) contain the personal data for each user of that computer. Those folders, by design, can only be accessed by the owner of the data, or by an adminstrator. Guest is neither of those, and shouldn't be expected to have access. The public portions of "C:\Documents and Settings" ("C:\Users"), if at all accessible to Guest, may be read only.

If a computer using Guest authentication is providing browser services for other computers, those other computers, when running browstat, and having no other errors, will show an "error = 5" (access denied) when trying to access the registry on the browser.

Master browser name is: PChuck1
could not open key in registry, error=5 unable to determine build of browser master:5


Other network related tasks, like remote registry access, and remote shutdown, won't work either. Those tasks require administrative access. Utilities like CPSServ won't be able to diagnose problems on a computer using Guest-only access, through the network.

The Guest account may not provide network access if the restrictanonymous setting has the wrong value. The Guest account may not provide network access to specific shares, if the RestrictNullSessAccess setting has the wrong value.

For more information about the Guest account, see Microsoft: Description of the Guest account in Windows XP.

If you need to do so, you can give additional authority to Guest. How to add authority will depend upon your edition and file sharing.

>> Top

Non-Guest Authentication

Non-Guest authentication is much more granular than Guest authentication, on a server using NTFS. It is possible on a server running Windows 2000, Windows XP Pro, with Advanced File Sharing, or Windows Vista with Password Protected Sharing (PPS) enabled. If your server has XP Home, XP Pro with Simple File Sharing, or Vista with PPS disabled, you'll be using Guest authentication. Like Guest authentication, it's part of the same decision process.

Once you're authenticated, whether with a Guest or a non-Guest account, you need to be authorised. Authorisation, under AFS / PPS, is much more granular than Guest authorisation under SFS.

>> Top

The Authentication Process - Step By Step

You authenticate in 4 possible scenarios, based upon the status of both the client and the server

  1. If
    • The client is running Windows Vista Pro (Business, Enterprise, or Ultimate), XP Pro, or Windows 2000.
    • You previously logged in to this server from this client, and selected "Reconnect at login".
    your computer will have cached a token for server access. Your computer will supply the token, and you will be given server access transparently ("transparent token caching").
  2. IfYour computer will supply the token, and you will be given server access transparently ("transparent first time login").
  3. If automatic non-Guest authentication is not possible, the server is checked for the Guest account having been activated for network access. If Guest is activated, and has no password, you will be given automatic Guest access.
  4. If neither automatic non-Guest, nor Guest, access is possible, you will have to supply the token manually. You will have to login to the server, interactively, using an account that is activated for network access on the server, with correct password. You may have the opportunity, here, to select "Reconnect at login" (based on Rule 1).
  5. If there is no account activated for network access, you will see the old
    ... access denied.
    or similar well-known error.


>> Top

Windows XP And Other Operating Systems

Windows XP was designed to allow the merger of the two older operating system families - Windows 9x (Windows 95 / 98 / ME - predominantly home systems), and Windows NT (NT / 2000 / 2003 - predominantly business systems). By carefully choosing Advanced vs Simple File Sharing on your computer, it can better operate on the LAN with your computers running older systems. And, looking forward, it can operate fine on the LAN with your computers running Vista.

Simple File Sharing, which is selectable under XP Pro but not under XP Home, uses Guest authentication only. It makes it easier to setup sharing with Windows 9x systems, by simply creating openly available shares.

Advanced aka Classic File Sharing is directly compatible to file sharing under Windows NT / 2000 / Server 2003. It can use Guest, or it can use non-Guest, authentication.

Windows XP will share files with an XBox 360, given a small amount of work.

For additional details describing file sharing issues relevant to Windows XP and to other operating systems, see:

>> Top

Authentication Protocols

As described above, any connection created between a client and a server involves some form of authentication. The person using a client computer must prove who he / she is, so the server can decide whether to allow access. The simplest form of authentication is a simple account / password exchange. The user inputs the account (public secret) and password (private secret), these are passed to the server, which matches the two against its database.

Original versions of Windows, before NT V4.0, used LAN Manager Authentication, which used this strategy. Starting with Windows NT V4.0, authentication protocols of increasing complexity have been used.

>> Top

Local Access Issues

If you follow recommended procedures, and setup your accounts to allow file sharing, you will have identical, non-blank passwords on the accounts. As I said above, by default, Windows XP Pro requires non-blank passwords for accounts used for network access.

Maybe you're accustomed to not logging in at all when you turn your computer on - just start it, it comes up with the desktop, and you get to work. Or maybe you'd like to do this, but don't know how. Well, Ramesh, another MVP, has written up the procedure for making your computer login automatically, in his article Configure Windows XP to Automatically Login.

>> Top

Reading IPConfig and Diagnosing Network Problems

Both Internet Service and Windows Networking rely upon the Internet Protocol being properly configured. The IPConfig utility tells us the various settings on any computer using Internet Protocol. This is a good place to start, when diagnosing any networking problem.

Please note that the examples shown here are from a computer setup in a workgroup, which is almost identical to a domain. There is one major difference for a domain; the DNS server entry, for a computer in a domain, should point to the IP address of the domain controller, as indicated in Windows XP / 2000 On A Domain.

This is a problem, as the ipconfig listing will not give a clue as to where the domain controller points (forwards its DNS queries). If you have DNS problems, in a computer on a domain, ipconfig will not help diagnose any such.



To get ipconfig data for immediate examination, simply type "ipconfig /all" into a command window (or a command window in Windows Vista). Only type the command itself into a command window - do not type Start - Run - "ipconfig /all...".

If you want the data so it is easily compared between computers, you need to export the data into a text file.

  • Type "ipconfig /all >c:\ipconfig.txt" (less the "") into a command window (or a command window in Windows Vista).
  • Then,

    • Type "notepad c:\ipconfig.txt" (less the "") into the same command window, for immediate examination.
    • Or, copy file c:\ipconfig.txt to another computer, for comparative examination.


A Normal IPConfig

Here's an example of IPConfig ("ipconfig /all") from a pair of computers on a LAN.


Windows IP Configuration
Host Name . . . . . . . . . . . . : PChuck1
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Broadcast
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : pchuck.net
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Physical Address. . . . . . . . . : 00-04-76-D7-C5-6A
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.1.50
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 192.168.1.11
192.168.1.33
Lease Obtained. . . . . . . . . . : Wednesday, April 16, 2003 11:19:12
Lease Expires . . . . . . . . . . : Wednesday, April 23, 2003 11:19:12

Windows IP Configuration
Host Name . . . . . . . . . . . . : PChuck2
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : pchuck.net
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Physical Address. . . . . . . . . : 00-04-76-D7-76-BC
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.1.51
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 192.168.1.11
192.168.1.33
Primary WINS Server . . . . . . . : 192.168.1.1
Lease Obtained. . . . . . . . . . : Wednesday, April 16, 2003 11:53:45
Lease Expires . . . . . . . . . . : Wednesday, April 23, 2003 11:53:45


What does this tell us?


Host Name . . . . . . . . . . . . : PChuck1

This is the name of the computer, as seen by Internet Protocol.

Primary Dns Suffix . . . . . . . :
DNS Suffix Search List. . . . . . : pchuck.net

Most small LANs don't have a DNS server setup, so you probably won't use DNS for name resolution. If you do have a DNS server (not the one which your ISP provides, either), you should setup both DHCP and DNS carefully.


Node Type . . . . . . . . . . . . : Broadcast

The Node Type tells us how this computer identifies the address of another computer on the LAN. Broadcast is the best setting for a small LAN, although anything but Peer-Peer will work. If you do not have a WINS server, and you see Peer-Peer here, you do have a problem.

If you have a LAN with its own DNS server, you will want to setup your LAN, and the DNS server, properly.


Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes

If DHCP is enabled, this computer should get it's IP settings from a DHCP server (either a NAT router / ICS Host, or a dedicated server running the DHCP service).

If Autoconfiguration is enabled, this computer did get its IP settings from a DHCP server. If DHCP is enabled, but Autoconfiguration is not enabled, a DHCP server was not available. If the latter, it is very likely that the computer now has an APIPA address, and may display the message "limited or no connectivity".



Physical Address. . . . . . . . . : 00-04-76-D7-C5-6A
IP Address. . . . . . . . . . . . : 192.168.1.50
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 192.168.1.11
192.168.1.33
Primary WINS Server . . . . . . . : 192.168.1.1

These are the most basic settings. You must get the addressing right, before the other components will be of much use.

The Physical Address is the MAC address for this network card. If this is the Vendor Assigned address, it is unique for this device. All Vendor Assigned addresses are unique, for every device in the world. If this is a User Defined address, it was set using tools provided by the vendor. For NT compliant network hardware, this was likely the device properties wizard, accessed from Local Area Connection Properties in Network Connections.

The IP Address for each computer must be unique. Taking the IP Address and the Subnet Mask, and subnetting the IP address, we see that this subnet is 192.168.1.0/24, and the Host Address is 50. On any LAN segment, all hosts (computers) must have the same subnet, and all computers must have a different host address.

While the Subnet and Host addresses together determine which computers on a LAN can communicate, the Default Gateway determines if the computer can communicate with any hosts outside the subnet. The Default Gateway must be the IP address of another host, on that same subnet, that also connects outside the LAN. With no default gateway value, or with an invalid IP address here, your computer won't have access outside the LAN.

If the IP address is 169.254.x.x, you have an APIPA address. Having one or more computers with APIPA addresses - 169.254.0.0/16 (169.254.0.0 / 255.255.0.0) could have various causes.

  • If you're connecting 2 computers directly, using a cross-over cable, then the APIPA addresses are perfectly normal.

  • If you're connecting a computer to an ICS server, or to a NAT router, and it's getting a 169.254.x.x address, then either you have a physical network problem, or the DHCP server (ICS server) is disabled.

  • If your network connection is WiFi, and you're seeing "Connected to XXXXXXX ... Connection quality zzzzz ...", you simply have a radio connection. Your WiFi client has to supply the right credentials (WEP, WPA, ...) before you actually get an IP address.


Note here that most of my advice is about using your computer on your network, or at least on a trusted network. If you're connecting your computer to an unknown or untrusted network, exercise common sense. If you're connecting thru WiFi, your connection isn't working, yet you are not seeing an APIPA address, you could be connecting to a honey pot.

The DHCP Server identifies the network device that issued the IP settings to this computer. If you have two computers which can't communicate, and they have incompatible IP settings, checking the DHCP Server might show settings from two different DHCP servers.

There are two possible reasons for having two different DHCP servers.

  • If you're paying your ISP for two ip addresses, you may be getting two addresses on different subnets, which is a perfectly expectable situation for cable broadband. The solution for this may be to not use IP on your LAN.
  • You also might have an unknown (rogue) DHCP server on your LAN. In that case, knowing the IP addresses of both servers should help you identify each server.

The Physical Address, IP Address, Subnet Mask, and Default Gateway are settings which describe how this computer connects to the network. DNS Servers, on the other hand, provide the ability to resolve the IP address of another computer on the network.

WINS is a legacy Microsoft name resolution protocol, used with Windows NT V4.0, and Windows 2000 (aka Windows NT V5.0). With Windows XP (aka Windows NT V5.1), Microsoft elected to use DNS, as the rest of the world has been doing for a while. But we still have the possibility to use WINS built in to Windows XP.

If your host configuration specifies a WINS server, you better have one. If a WINS server is configured, and WINS is queried, Windows XP will wait for a query against it to timeout. Depending upon the value of Node Type, you will have various problems.

  • If Node Type is Broadcast, the WINS entry will be ignored.
  • If Node Type is Hybrid, name resolution by Broadcast will be tried only AFTER WINS resolution is tried and times out. This will significantly increase latency in many file sharing processes.
  • If Node Type is Mixed, name resolution by Broadcast will be tried first. If the requested computer does not respond to a Broadcast (maybe you typed in the name wrong), name resolution will try WINS next. The WINS query will have to timeout before reporting "name not found" aka "Error = 53".
  • If Node Type is Peer-Peer, only the WINS server will be tried. This is a common problem on small LANS.
  • If Node Type is Unknown, it will be treated as Hybrid.

Note that any or all of the above settings can come from automatic configuration (the Network Setup Wizard), or manual configuration (the TCP/IP Properties wizard).

A Bridge

When you run the Network Setup Wizard, you may end up with a bridge. Bridges cause problems with file sharing, and with Internet service sharing. You can get a bridge from having any of the following:

  • Two network cards, connected to two different subnets.
  • Dialup Internet service, with a modem and a network card.
  • PPPoE Internet service, with a PPPoE modem and a network card.
  • One network card and a 1394 Firewire device.


Windows IP Configuration
Host Name . . . . . . . . . . . . : MyComputer
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : Yes
WINS Proxy Enabled. . . . . . . . : No
Ethernet adapter Network Bridge (Network Bridge):
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : MAC Bridge Miniport
Physical Address. . . . . . . . . : 02-2F-CC-91-84-FF
Dhcp Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.0.1
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :

If you don't intentionally want a bridge, get rid of it. If you need a bridge, please refer to Steve Winograd PracticallyNetworked XP ICS - Network Bridge.

You can avoid ending up with a bridge, if you follow the advice from Microsoft How to prevent the Network Setup Wizard from creating a bridge in Windows XP.

IPV6
When you run the Network Setup Wizard, you may end up with IPV6, aka Automatic Tunneling, aka Teredo Tunneling.

Windows IP Configuration
Host Name . . . . . . . . . . . . : PChuck1
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Broadcast
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : myhome.net
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Physical Address. . . . . . . . . : 00-04-76-D7-E2-BA
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.1.50
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 10.201.99.11
10.201.99.33
Lease Obtained. . . . . . . . . . : Wednesday, April 16, 2003 11:19:12
Lease Expires . . . . . . . . . . : Wednesday, April 23, 2003 11:19:12
Tunnel adapter Automatic Tunneling Pseudo-Interface:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Automatic Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : C0-A8-00-03
Dhcp Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : fe80::5efe:192.168.1.50%2
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1
fec0:0:0:ffff::2%1
fec0:0:0:ffff::3%1
NetBIOS over Tcpip. . . . . . . . : Disabled

The presence of IPV6, aka Automatic / Teredo Tunneling, may hamper the diagnosis of your problems. Please remove IPV6 while we are working on your problems; if you truly need it, you can re install it later. You must remove IPV6.

A Hardware Firewall

This may become a common observance in the future.

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : NVIDIA nforce Networking Controller

This is a hardware firewall, sitting inside your computer. The nVidia nForce is probably the first, but surely not the last, device of this type.

IPConfig Command not recognised

And here's an odd result. You type "ipconfig", and get

'ipconfig' is not recognized as an internal or external command, operable program or batch file.

In this case, you have still more work to do. There are several possibilities.

  • Check the Path. The entry ";%systemroot%\system32" may be missing.
  • You may need to reload TCP/IP (if this is not Windows XP), or reset TCP/IP (if this is Windows XP).


>> Top