Showing posts with label IPX/SPX. Show all posts
Showing posts with label IPX/SPX. Show all posts

Windows Vista And The IPX/SPX Protocol

Along with providing IPV6 as a default network protocol in Windows Vista, Microsoft made another major change to the protocol stack there - they eliminated the optional IPX/SPX selection. Microsoft now does not support IPX/SPX, in any way.

Note:
Windows Vista does not provide a NetWare client or the IPX/SPX protocol.


You can get a Novell client, from Novell. We haven't confirmed that this is IPX/SPX, though.

>> Top

Knowing What's On Your LAN

Whenever you are diagnosing a network problem, whether it involves simple Windows Networking connectivity, or file sharing, you can run native Windows commands like "net view". This tells you what servers can be seen on the LAN.

Unfortunately, "net view" is an application level diagnostic, and requires Server Message Blocks aka SMBs. Lack of SMBs, frequently caused by a misconfigured or overlooked personal firewall, is a common symptom. When you're diagnosing a network problem, you have to start at the lower levels, and work upwards. What about some diagnostics at a lower level, just to verify IP connectivity?

For an immediate scan of the subnet, I rely upon two free products - AngryZiber Angry IP Scanner, and Softperfect Research Network Scanner. Both tools will start with the subnet that your computer is attached to, and scan each possible IP address on that subnet. For each IP address responding, you can find out host name, MAC address, and response time. This is a good start, for finding, and tracking, computers on your network.

Remember, though, both of these products list hosts using Internet Protocol. If your LAN uses alternate transports like IPX/SPX or NetBEUI, neither will be very useful.

If you need to associate a MAC address with its vendor, the IEEE OUI / Company_id Assignments database can be searched for this information.

>> Top

The Network Language That Your Computer Speaks

If you have Windows XP, and you just ran the Network Setup Wizard, your computer most likely uses NetBIOS Over TCP/IP (NetBT). If all of your computers use this same language, and were all setup properly, the chances are good that you will be able to share files with them.

There are other languages that your computers might speak.


  • NetBT uses IPV4, the current Internet addressing scheme of nnn.nnn.nnn.nnn. IPV6 will expand this to xxxx.xxxx.xxxx.xxxx.xxxx.xxxx, giving IPV6 almost infinitely more address space than IPV4.
  • NetBT is more completely known as "Server Message Blocks hosted over NetBT". SMBs over NetBT is most useful in small LANs that use broadcasts for name resolution. If you have a LAN with a DNS server for local name resolution, you can Disable NetBT, and use SMBs directly hosted over IP.
  • There are odd circumstances where SMBs hosted over alternate protocols such as IPX/SPX or NetBEUI may be advisable.

Windows XP will support any of the above languages, if you already have a LAN, and want to keep your existing computers as they are right now. If you have a portable computer, and intend to use it on different networks, or if you have a small LAN and want to have the most choices in design and support available, using SMBs hosted over NetBT makes the most sense.

It's your computer, and your choice. Just know what the choices are, and how they may affect you. You may select IPV4, IPV6, IPX/SPX, and NetBEUI from the Network Connection Properties wizard. You Enable SMBs hosted over NetBT from the TCP/IP Properties - Advanced wizard.

>> Top

Firewall Behaviour - And Windows Networking

The classical personal firewalls, which would be installed on most personal computers in a typical Small Office / Home Office environment, block only specific network traffic. By default, they are open, and pass all traffic.

Modern firewalls, used by more cautious network experts, permit only specific network traffic. By default, they are closed, and pass no traffic. After installing this type of firewall, you must run a manager and configure the firewall to pass your desired traffic.

My suspicion is that the nVidia nForce hardware firewall falls in the latter category. If you don't run the firewall manager, it will pass only a minimum of traffic, probably just enough for you to surf to the nVidia website and get software upgrades. This intentionally blocks SMBs (whether NetBT hosted, or directly hosted), and protects against the dangers offered by Windows Networking. If you're going to use Windows Networking over TCP/IP, you must run the firewall manager, and intentionally configure it for Windows Networking.

Short of configuring the firewall for Windows Networking over TCP/IP, you have no choice but to install an alternate transport such as IPX/SPX or NetBEUI, which bypasses the firewall completely.

For ongoing discussion about this issue, see these threads in the Microsoft Public WindowsXP Network_Web forum:


  • Selling my soul to the devil is the next step...
  • NVIDIA "hidden firewall" causes networking problem, by the Original Poster in the previous thread
    If you have the NVIDIA nforce networking controller with onboard LAN, you may have a "hidden firewall" interfering with your network connection. I'll describe my own situation and how I resolved the problem. I owe great gratitude to Chuck, frequent poster in this group, who worked with me for about a week, and had suggested the possibility of the NVIDIA "hidden firewall", but I was reluctant to accept that because, well, it really was hidden and I couldn't find it (and still can't). But it was there. (For those who want to review the original thread, it was posted in this group under the title "networking only works one way" on 08/04/06.)

  • Networking only works "one way", with only my part of the thread provided, because the Other Poster's content was not archived.


>> Top

Advanced Windows Networking Using Internet Protocol

Windows Networking is the subsystem that lets you share files and printers, between computers running the various versions of Windows. Server Message Blocks, also called SMBs, are the foundation of Windows Networking. SMBs provide several crucial functions.



(Note): If you're not familiar with the concept of network layers, take a few moments and read about the OSI Network Model.

SMBs are not transported directly over the various physical networking components, as Layer 1 or 2 traffic. SMBs may be transported over Internet Protocol (IP), as well as alternate protocols like IPX/SPX or NetBEUI.

Windows Networking has historically used NetBIOS Over TCP/IP (NetBT) as an intermediate transport for SMBs over IP. Windows 2000, XP, and Vista however, will transport SMBs over IP, without NetBT, using directly hosted SMBs.

To remain compatible with the older versions of Windows, a Windows Networking client, running Windows 2000, Windows XP, or Windows Vista, can use either directly hosted SMBs, or it can use NetBT. If any server supports directly hosted SMBs, the client computer in question will bypass NetBT, when communicating with that specific server.

This dual compatibility, which allows Windows 2000 / XP / Vista clients to communicate with computers running other editions of Windows, is not without cost. Trying for two communications channels, when establishing a connection with any server, increases program complexity and network traffic. In some cases, it may increase latency.

We need to resolve one major misconception. It may appear that when you Disable NetBT, you are disabling Windows Networking over IP. This is not correct. When you Disable NetBT, you are merely disabling hosting of SMBs over NetBT. You then end up with SMBs hosted directly over IP. But look at address resolution on your LAN, before trying this. Don't make this change blindly.

If your LAN
  • Has a domain.
  • Has computers running only Windows 2000, Windows 2002 (aka Windows XP), Windows 2003 (aka Server 2003), Windows 2006 (aka Vista), and Windows 2009 (aka Windows 7).
  • Uses DNS, properly setup, for name resolution.
then you may wish to Disable NetBT, and (KB204279): use directly hosted SMBs. If any of the above are not true, you should Enable NetBIOS Over TCP/IP. Be consistent on all computers.

In the TCP/IP Properties - Advanced wizard, WINS, select Disable NetBIOS Over TCP/IP. Alternately, if you have the Default NetBIOS setting selected (instead of "Disable" or "Enable") on your client computers, and you have a DHCP server (not a NAT router with DHCP), you can disable NetBT from a DHCP server setting.

If you use directly hosted SMBs, whether alternately or exclusively, be aware of the security implications.
  • NetBT uses TCP and UDP ports 137 - 139.
  • Direct hosted SMBs use TCP port 445.

Be sure that all personal firewalls have the proper ports opened.

Here are the relevant ports used by SMBs over NetBT, per IANA port number allocation:

netbios-ns 137/tcp NETBIOS Name Service
netbios-ns 137/udp NETBIOS Name Service
netbios-dgm 138/tcp NETBIOS Datagram Service
netbios-dgm 138/udp NETBIOS Datagram Service
netbios-ssn 139/tcp NETBIOS Session Service
netbios-ssn 139/udp NETBIOS Session Service

And the relevant ports used by directly hosted SMBs:

microsoft-ds 445/tcp Microsoft-DS
microsoft-ds 445/udp Microsoft-DS


Similar to the effect of a personal firewall, SMBs can be setup to use secure channel communication, by using SMB Authentication and Encryption. If you ever see
The account is not authorized to log in from this station.

then check SMB Encryption and Signing settings.

And, if you have an integrated security suite (previously sold as anti-virus protection), you may have an anti-worm component protecting you. Anti-worm protection, if not correctly configured, may interfere with any or all of the above NetBT traffic. Different brands of products will cause different problems.

For more information:

>> Top

Network Diagnostics Using Net Config

When you're having a problem accessing network resources, or displaying what network resources are available, Browstat is a good starting point. To check IP connectivity setting, you use IPConfig. Sometimes, though, neither "browstat status" nor "ipconfig /all" tells you what you need to know.

Starting from the lower level of the OSI Network Model, you look at an "ipconfig /all" log, and see a network connection, identified as:


Physical Address. . . . . . . . . : 00-04-76-D7-C5-6A

IP Address. . . . . . . . . . . . : 192.168.1.50


You suspect, but you can't tell for sure, that that same connection is identified in the accompanying "browstat status" log, as:

Status for domain WORKGROUP on transport NetBT_Tcpip_{B7E18D15-D9B1-4295-9DAD-C733C695294F}


To correlate the information provided by "browstat status" and "ipconfig /all", or in cases where IPConfig is irrelevant (such as where IPX/SPX must be used), you can use the "net config" commands:

net config server
net config workstation

As with any other command, you run it from a Command Window (or a command window in Windows Vista), which gives you the ability to redirect the output, to a text file, for analysis later. Since you're running 2 commands, one after the other, be sure to concatenate the output from the second after the first. Only type the command itself into a command window - do not type Start - Run - "net config...".

Let's look at "net config" from my mythical computer, "PChuck1".

First, "net config server".

Server Name \\PChuck1
Server Comment Primary

Software version Windows 2002
Server is active on
NetbiosSmb (000000000000)
NetBT_Tcpip_{B7E18D15-D9B1-4295-9DAD-C733C695294F} (000476D7C56A)


Server hidden No
Maximum Logged On Users 10
Maximum open files per session 16384

Idle session time (min) 15
The command completed successfully.


Next, "net config workstation".

Computer name \\PChuck1
Full Computer name PChuck1.martinez.cacroll.net
User name pchuck

Workstation active on
NetbiosSmb (000000000000)
NetBT_Tcpip_{B7E18D15-D9B1-4295-9DAD-C733C695294F} (000476D7C56A)

Software version Windows 2002

Workstation domain PChuck
Workstation Domain DNS Name pchuck.local
Logon domain PChuck

COM Open Timeout (sec) 0
COM Send Count (byte) 16
COM Send Timeout (msec) 250
The command completed successfully.

What does all of this tell us?

  • First,
    Computer name \\PChuck1

    PChuck1 is the name of the computer, which matches the browstat and ipconfig logs.
  • Next,

    Server is active on
    NetbiosSmb (000000000000)
    NetBT_Tcpip_{B7E18D15-D9B1-4295-9DAD-C733C695294F} (000476D7C56A)

    Shows us two key items:

    • The network connection is using NetBT and SMB. This is a normal binding list.

      • If there was only an entry for "NetbiosSmb", file sharing would work, but access by name will be a problem. Always Enable NetBT for best results.
      • If there was an entry for "NwlnkIpx" and / or "NwlnkNb", file sharing MAY work, but irregularly.

    • The entry
      NetBT_Tcpip_{B7E18D15-D9B1-4295-9DAD-C733C695294F}

      as shown in "browstat status", corresponds to MAC address
      000476D7C56A

      as shown in "ipconfig /all".

  • A small, but still important detail,

    Server hidden No

    tells us that the server is intended to be visible in Network Neighborhood.
  • And some more details,

    Maximum Logged On Users 10
    Maximum open files per session 16384

    Idle session time (min) 15

    may tell us why all of the computers in the workgroup can't access shares on the server simultaneously.
  • Finally,

    Workstation domain PChuck
    Logon domain PChuck

    Shows that this computer is a member of domain (or workgroup) PChuck, and is logged on to domain PChuck. If your domains and workstations are named with some thought, this likely indicates that the computer in question is logged in to domain PChuck. On the other hand, if we had

    Workstation domain PChuck
    Logon domain PChuck1

    then we know that this computer is a member of domain (or workgroup) PChuck; but, in this case, the computer is logged on locally, to PChuck1. Note that since you can generally logon locally to any computer, even if it's a domain member, we still cannot tell if it's a domain or workgroup member.

A Gratuitous Protocol
But look closely at the list of protocol bindings. If "net config server" shows us, for instance,

Server is active on
NwlnkIpx (000000000001)
NwlnkNb (0016f004143e)
NetBT_Tcpip_{747CE691-1460-4F27-AB2F-F19C2110CCFB} (0016f004143e)
NetbiosSmb (000000000000)

Here we see another example of the presence of IPX/SPX ("NwlnkIpx"), and of NetBEUI ("NwlnkNb"). If you're having problems, which I presume is why you're here, always start by removing IPX/SPX and / or NetBEUI.

A Set Of Simple Network Components Definitions

Many folks, when they start connecting their computers, get lost in the terminology. Justifiably so, I would think. I can hear the pain in their voice.


  • I want to connect my computers. One guy in the store showed me a hub. Somebody else told me to buy a switch. And in the forum, I was told that a router was the only way to go. Help!
  • I want to connect my computers, but avoid using cables everywhere. One guy told me to buy a wireless router. Somebody else recommended an access point. And I hear about bridges, and repeaters.



Introduction to Networking
To learn about network components, and what each one does, you first need to learn the concept of the OSI network model. All network components are defined in term of the network layer which they work in. Components in any one layer connect to other components in that layer, or to components in the layer above or below.

A network cable would be an example of a component in the Physical, or bottom, layer. Ethernet, which is one of the most common network standards in use today, incorporates both the Physical Layer, and the Data Link Layer. An Ethernet cable, then, connects thru both the Physical (Layer 1) and Data Link (Layer 2) layers, and can connect to a Network device, such as a router.

Routers, which operate at Layer 3, connect networks that use Internet Protocol (IP). For intensive instruction in IP networking, see Microsoft TCP/IP Fundamentals for Microsoft Windows.

WiFi, which is not a totally physical medium, is similar to Ethernet, excepting that it uses a radio channel, instead of cable.

>>Top

Wired Devices - Bridges, Hubs, Routers, and Switches

Hubs, routers, and switches are devices used to connect computers, that are physically attached (using cables), or logically attached (using WiFi).

>>Top

A hub is one of the most basic network components; like a cable, it is a Physical (Layer 1) device. It is not addressable, it connects passively to a group of Ethernet (or other media) cables.

A hub effectively connects a group of computers in one big conversation, much like an old fashioned telephone party line. With all computers in a network connected by hubs, only one computer will be able to transmit, to another computer, at any time. Computers connected in this way must use a communications technique called Carrier Sense Multiple Access/Collision Detection (CSMA/CD).

CSMA/CD is a pretty inefficient protocol. If you are chatting with a friend, maybe over the telephone, do you ever notice that sometimes one of you wants to speak when the other is still talking? How about if both of you start talking simultaneously? What if a group of you, and many friends, try to carry on a conversation that way? Sometimes, you have to spend as long deciding who's going to speak next, as actually speaking.

In effect, with a hub connecting your computers, the more computers that get connected, the less productive network work will get done. Hubs are just not scalable - that is, you can't keep adding computers to a hub, and get any decent production out of a network.

Since the purpose of networking computers is to transmit massive amounts of data between those computers, the switching hub was developed.

>>Top

A switch is a Data Link (Layer 2) device. A switch, which was originally called a switching hub, connects specific computers to each other selectively, much like a telephone switch, for individual conversations. Individual computers are addressed (selected), by a switch, using their MAC addresses.

With a switch, individual pairs of computers can carry on simultaneous conversations. Essentially, a switch is to private line telephone (which is the telephone service we all take for granted) as a hub is to party line telephone (if any of you are old enough to remember that). A switch operates in full duplex mode (each computer can send and receive simultaneously), where a hub operates in half duplex mode.

>>Top

A bridge is a type of switch. Where a switch, in general, connects two or more networks that use identical media (such as Ethernet), a bridge may connect networks that use different media. In Internet connectivity, a modem will act as a bridge, and connect:

  • The Public Switched Telephone Network (PSTN) to a serial cable, leading to a computer or router (or connect as an internal component in your computer). A properly selected NAT router (though not all NAT routers) can connect to a properly selected external modem.
  • A cable broadband network to Ethernet, or USB cable.
  • A DSL broadband network to Ethernet, or USB cable.

A WiFi Bridge connects (bridges) Ethernet to WiFi.

There is one other difference between a bridge and a switch. A switch, by definition, connects multiple computers, and has 4 or more ports. A bridge generally connects only 2 different networks, and has 2 ports. A bridge with more than 2 ports generally has a hub or switch attached to one of the bridge ports.

Since the MAC address is factory assigned, and intentionally unique in all circumstances, it would be practically useless to designate groups of computers by MAC address. Switches are more effective than hubs for connecting large groups of computers, but the groups need to be local to each other for efficiency.

To associate groups of computers, where not all groups are local to each other, you need the ability to associate computers in location based groupings. This is where Internet Protocol addressing comes in to use - the IP address is assigned by physical grouping of computers.

>>Top

A router is a Network (Layer 3) device, that connects networks that use Internet Protocol. A router connects specific computers to each other selectively, like a switch. Unlike a switch, which addresses individual computers by their MAC addresses, a router addresses computers by their IP addresses.

Since a router addresses computers by their IP addresses, a router only transports Internet Protocol traffic. IPX/SPX and NetBEUI, which are alternate transports, do not produce routable traffic. Networks which use either alternate transport must be connected by hubs or switches, they won't work with routers.

Since Ethernet connects thru both the Physical (Layer 1) and Data Link (Layer 2) layers, an Ethernet cable can connect either a hub (Layer 1), a switch (Layer 2), or a router (Layer 3). A group of computers, connected by Ethernet or WiFi, thru a collection of hubs, switches, and routers, makes up a Local Area Network (LAN), or a Wide Area Network (WAN). Since the IP address is assigned to each group of computers based upon their physical location, all computers in one physical location can be easily identified by IP address grouping, or subnet.

A router is essentially a big switch, with multiple connections, each connection leading to one or more subnets. A subnet can be locally attached (by Ethernet), or distantly attached (by a long distance communications line). By knowing what subnet is accessible (immediately, or distantly), from any connection, a router can decide which connection should be used for a packet destined for any given IP address or subnet.

Now if you are buying, or just bought, a router for your home or small office, you probably are looking at a NAT router. A NAT router has the functionality of a regular router, and more. For a description of a NAT router, please see my article What Is A NAT Router?.

>>Top

Wireless Devices - Access Points, Bridges, Repeaters, Routers, and Switches

A WiFi channel is similar to a hub, in that all computers using a single WiFi channel have to share it with each other. They can choose not to listen to the conversations of their neighbors (properly designed software won't participate in conversations which don't apply to the network that it connects to), but you should not assume this to be true in all cases. You absolutely must practice WiFi security.

And whether or not a WiFi device listens to a conversation on another network, it won't be able to use the channel, while the other network is using the channel. The WiFi channel can only be used by one conversation at any time. All WiFi devices, within range of each other (able to detect radio from each other) have to share the channel, and only one device can transmit at any time. This is why we say that WiFi is a half duplex medium.

>>Top

A WiFi router is similar to a wired router, but with one extra component - a radio connected to the LAN switch. The computers that connect by WiFi become peers to the computers connected to the Ethernet LAN ports.

All computers connected directly to the Ethernet switch have the capability of multiple simultaneous, full duplex, communications, with all other computers connected directly to the Ethernet switch. All computers that connect by WiFi, though, have to share the channel with all other nearby WiFi devices.

>>Top

A WiFi bridge is similar to a wired router, but with one extra component - a radio connected to the WAN port. Like the wired router, all client computers connect to the bridge by Ethernet.

All computers connected directly to the Ethernet switch have the capability of multiple simultaneous, full duplex, communications, with all other computers connected directly to the Ethernet switch. Connection to the rest of the network, thru the WiFi WAN port, will have to share the WiFi channel with all other nearby WiFi devices.

You can buy WiFi bridges made for that purpose, and some WiFi NAT routers can be converted to bridge configuration. The Linksys WRT54G, with third party firmware, can be configured as a bridge.

>>Top

A WiFi access point is a wired switch, with a radio. As with a WiFi router, the computers that connect by WiFi become peers to the computers connected to the Ethernet LAN ports on the switch.

The computers connected to the Access Point - both wired and wireless - will have the same capabilities and restrictions as those connected to a WiFi router.

>>Top

A WiFi repeater is, simply, a radio that alternately receives and sends. Placed at a distance from a WiFi router (at a midpoint between the router and the clients), a repeater can extend the range of the router. A repeater that operates on one channel, though, will be very slow. It has to:

  • Receive a packet from one WiFi computer, that's intended for another.
  • Retransmit (repeat) the same packet.
  • Wait for a reply from the computer that the packet was intended for.
  • Pass that reply back to the sending computer.
  • Receive another packet from the sending computer.


Summary and References
All equipment, excepting the NAT Router component of any device, operates at Layer 2 of the OSI network model. Excepting the NAT Router component, all equipment will transport IPX/SPX and NetBEUI network traffic, in addition to IP traffic.

Any configuration of equipment, done thru your browser, will typically require Internet Protocol though. Most network components, when designed to be managed thru the network, is addressed (managed) by IP address. Both WiFi routers, and Wired Routers, will only transport IP traffic.

For additional discussion about wired components, see Hard Forum Networking FAQ Q1.

>> Top

Irregularities In Workgroup Visibility

Let's say you connect 2 computers, running any of the many versions and editions of Windows, with default configurations, in a network. To find each computer from the other, you open Windows Explorer (don't confuse this with Internet Explorer, please), and look in My Network Places (aka Network Neighborhood). On a fully working LAN, this will work just fine. In your case, it may not.

In your case, Computer A shows both Computers A and B, as it should, and files on Computer B are accessible. On Computer B, either you don't see Computer A, or when you try to access Computer A, you get an error. You may, or it may not, see Computer B. This visibility problem may be observed constantly, or it may come and go.

This visibility problem is possible on LANs with Windows 2000, Windows XP, and / or Windows Vista, in any combination.

Now before you start, you should be aware that you will enjoy this more, and frequently will be more successful, when you work on a properly designed and setup network. After you review that tutorial, I recommend that you tackle the task at hand in this order.



Basic Diagnostics

  1. Check for a personal firewall problem. A misconfigured or malfunctioning personal firewall, on either computer, can block browser access. Do you have antivirus protection? Make sure that your antivirus is not part of a package that contains a personal firewall, and does not contain a component that acts as a firewall.

  2. Look carefully for a hardware firewall, sitting inside your computer. The nVidia nForce is probably the first, but surely not the last, device of this type.

  3. Some newer, WiFi routers, have a complete firewall between ALL client computers, connected wired or wireless. Look for an "Isolation Mode" setting, if no computers are visible to each other. Each vendor uses a different name for this feature, so read your user guide carefully, if you suspect that this is a problem.

  4. Make sure that NetBIOS Over TCP is consistently set, in TCP/IP Properties for each computer in your network.

  5. Does your LAN include any computers running Windows Vista? If so, be aware of the additional issues involved in Windows Vista and Windows Networking.

  6. Do you have a share setup on each computer? With Windows XP / Vista, only computers with non-administrative shares (not ending in "$") will be visible in My Network Places (aka Network Neighborhood).

  7. Make sure that all computers are in the same workgroup, if you expect to see them in the root of Network Neighborhood (My Network Places).

  8. Check for several well known and lesser known registry settings, which will affect visibility of, and access to, your server.

  9. Look at the content of the error message. Do you see either "error = 5" (aka "access denied"), or "error = 53" (aka "name not found")? Read the appropriate article.

  10. Look again at the complete and exact text in any observed error messages. Some very obscure errors have very simple resolutions.

  11. Run, and examine output from, "browstat status", "ipconfig /all", and "net config server" and "net config workstation", for each computer.

  12. Post output from the above step for expert interpretation and advice. Include relevant background details in your post. When including diagnostic logs, such as "browstat status", "ipconfig /all", or background details, format them properly when you post them.


Intermediate Diagnostics

  1. Make any changes in your network per the advice of the helpers in the forums. Retest as advised.

  2. Run, and examine, CDiag output for each computer. If you have more than 3 computers, post diagnostics for at least 3, and try and include some computers which show no symptoms of the problem (if any exist), as a control. The more data here the better.

  3. Post output from the above step for expert interpretation and advice. Again, format CDiag logs properly when you post them.

  4. Check that all necessary network components and services are provided. The necessary protocols and transports must be loaded and activated. The necessary services should be Started and Automatic.

  5. Run, and examine, CPSServ output for each computer. Try and do this on the same computers that you ran CDiag (above) on, to make the diagnostics more effective.

  6. Post output from the above step for expert interpretation and advice. Again, format CPSServ logs properly when you post them.

  7. Check for, and remove, unnecessary protocols and transports, like IPV6, IPX/SPX, and NetBEUI. Unnecessary protocols and transports can block Server Message Blocks, and cause problems. Check "browstat status" logs for evidence of IPX/SPX or NetBEUI. Check "ipconfig /all" logs for evidence of IPV6. Remove any protocols found. If you solve your immediate problems, you can re in stall any protocols removed, later.

  8. Check for LSP / Winsock / TCP/IP corruption. The LSP / Winsock layer in the network, on either computer, can malfunction, and drop SMBs. If you have more than 2 computers, the computer causing your problems may not be immediately apparent. Use CDiag to identify the computers to work on first.


Advanced Diagnostics

  1. Learn how to solve network problems.

  2. Try my comprehensive troubleshooting guide, Troubleshooting Network Neighborhood Problems. Use CDiag and / or CPSServ logs, to identify the computers to work on first.

  3. Read about The NT Browser and Windows Networking.

  4. Read about File Sharing Under Windows XP.


NOTE: The comprehensive troubleshooting guides, referenced in Advanced Diagnostics, contain all of the other sections and more, sequenced by network design (ie, physical connectivity issues first, and file sharing permissioning last). The last article talks about problems specific to File Sharing, such as authentication and authorisation, and it is most useful when all other problems (such as are discussed in the previous step) are resolved. This article, as a whole, emphasises the most productive procedures for resolving your symptoms. You are free to try any of the above steps, in any order which pleases you - it is, after all, your network.

These are simply the procedures which currently seem to produce the best results. So become familiar with them, because, if you ask for help and I am involved, I will likely ask you for the diagnostics discussed above. And, if we don't get immediate results here or elsewhere, I'll ask you to repeat each step above, one by one, as I examine the results. Read each linked article.

Now I'm a Networking and Security advisor, and I don't provide advice on security issues casually. Using the Internet, without considering the privacy and security implications, makes trouble for a lot of innocent people. When you're considering the necessity of providing requested details about your computer network, in an open Internet forum, please read this brief Privacy Statement. Help us to help you.

Networking Your Computers

Setting up a computer network, whether to share files, or Internet service, can be a lot of fun. It's more fun, though, if you set it up properly, from the start. I'll try and make that possible, if you work with me.



>> Top

With the basic issues out of the way, you can get detailed instruction from plenty of websites, that will give you illustrated instructions. Here are but five, listed in alphabetical order.

If you have properly chosen and setup your equipment, advice from any one of the above should get your network in order. The various guides are written by different organisations, and each has a different style, so check them all out if possible. Find the one which works best for you.

>> Top

Solving Problems
If you're here because you have problems, please start by reading Solving Network Problems.

Now, what is your specific problem? Is it accessing the Internet? Then read Troubleshooting Internet Connectivity. Or is the problem with File Sharing? Then read Troubleshooting Network Neighborhood (Windows Networking).

One major issue that the websites listed above won't help you with, if your problem is with file sharing, is the browser. Now when I mention the browser, don't start with "My Internet access is not a problem". The browser is the program that provides the contents of Network Neighborhood on your LAN. It's frequently involved in problems when "I can't see the other computers", or "I get access denied when I try to access another computer". Please read my article Windows NT (NT/2000/XP/2003) and the Browser.

Do you have a LAN with both Windows 9x (95, 98, ME) computers and Windows NT (NT, 2000, XP) computers? Then you should read Windows 9x (95/98/ME) and the Browser.

>> Top

In Conclusion
All of the above articles link to dozens of other articles, so read carefully. And be patient with me, as I add to this blog occasionally. Check back here periodically. Or write to my Guestbook.

>> Top

Windows Networking And Alternate Transports

Windows Networking is the suite of programs that provide file and printer sharing between computers running Microsoft Windows (and compatible Operating Systems, such as Linux). Windows Networking runs at the Application level of the OSI Network Model, and, in its default configuration, uses NetBIOS Over TCP/IP (NetBT) and TCP/IP, for logical connectivity. It can be customised to use alternate transports, like IPX/SPX or NetBEUI.

Microsoft supports only NetBT and TCP/IP, though you may use IPX/SPX or NetBEUI, if you're prepared to deal with the support issues. There are advantages and disadvantages to using either alternative. (Update): Windows Vista will not support NetBEUI.

Similar in effect to IPX/SPX / NetBEUI, we have a commercial product called Network Magic. Network Magic requires no complicated configuration, you just install it and it works. Unfortunately, nobody that I know knows how it works, or if it's OSI Network compliant. And, just as the disadvantages of IPX/SPX / NetBEUI, if there's a problem with the network outside its scope of effect, you may not be able to diagnose such a problem as reliably as with IP.

Advantages Of Alternate Transports


  • No filtering problems. A misconfigured or overlooked personal firewall can cause problems with IP based networks. Neither IPX/SPX nor NetBEUI is affected by firewall problems.
  • Segments are isolated. Any separate networks, connected by routers, won't pass IPX/SPX or NetBEUI based traffic between them. Windows Networking simply won't leak onto any networks connected by routers, such as the Internet.
  • Easier to setup. There's no need to configure TCP/IP settings, both IPX/SPX and NetBEUI attach directly to the hardware, and both setup automatically.


Disadvantages Of Alternate Transports

  • Network complexity. You'll likely have redundant system components in use by each computer, and redundant network traffic between each computer.
  • Lack of diagnostics. The ipconfig and ping utilities can identify logical and physical connectivity problems on an IP network. This is not available on non-IP networks, and may not give consistent results when you deal with problems on mixed networks.
  • Lack of filtering. Firewalls only filter IP network traffic.
  • Limited effect. Using alternate transports provides a workaround only for TCP/IP configuration problems, or filtering problems. It does nothing for physical problems, or for problems caused by authentication / authorisation.
  • Only TCP/IP can link multiple segments. Any separate networks, connected by routers, won't pass IPX/SPX or NetBEUI based traffic between them. If your network is segmented, for physical reasons, you'll have to bridge the segments (which is, by design, what NBT does).
  • Have to be setup properly. If just one computer on the network attaches Windows Networking to NBT, convenience and security gains are eliminated.


>> Top

Filtering
IP traffic, by design, can be filtered by personal firewalls and routers. IPX/SPX and NetBEUI, which attach directly to the physical transport and in parallel to TCP/IP, are not affected by IP based filtering. This has its good side and its bad side.

If you're having a problem with a personal firewall on a computer, you can work around that problem. IPX/SPX and NetBEUI are not affected by personal firewalls.

However, if you depend upon a personal firewall providing protection against malicious network traffic, you won't have that. Any malicious network traffic, IPX/SPX or NetBEUI based, won't be filtered.

>> Top

Segmentation
IP traffic, by design, passes thru routers; IPX/SPX and NetBEUI traffic doesn't. This has its good side and its bad side.

If you have a network in a single segment, and you use IPX/SPX or NetBEUI to provide a transport for Windows Networking, all Windows Networking traffic will stay on that segment. All shares will be totally safe from malicious access from other network segments, including the Internet.

If your network includes multiple segments, connected by routers, and you use IPX/SPX or NetBEUI as a transport for Windows Networking, all Windows Networking traffic will stay on each segment. Computers on separate segments will be unable to access each other, unless you build bridges between the segments. NBT was designed as that bridge.

>> Top

Setup
A network, using IPX/SPX or NetBEUI, is easy to setup. It's not so easy to setup properly though.

A simple IPX/SPX or NetBEUI network, in a single segment, requires no configuration. Both transports essentially set themselves up. There's no subnetting or other complicated TCP/IP settings to make.

If you want to access the Internet from your computers, though, you will still have to have TCP/IP on each computer. If you do not separate Windows Networking from TCP/IP on even one single computer, your entire Windows Networking environment may be exposed. And without protection by personal firewalls, all computers may be at risk more than if they were using NBT.

>> Top

Complexity and Use of Network and System Resources

IPX/SPX and NetBEUI are not significantly more chatty than NBT, and do not use significantly more network or system resources. If your computers only use IPX/SPX or NetBEUI, there is no complexity or resource problem.

But, if your computers will be accessing the Internet too, you'll need TCP/IP on each computer. IPX/SPX, NetBEUI, and TCP/IP, although each run under the same operating system, use different system components. And while they each generate traffic on the same network, the content of that traffic is different. So, with multiple combinations of IPX/SPX, NetBEUI, and TCP/IP operating on your network, your computers will have to work harder (to use multiple protocols), and your network hardware will have to work harder (to transport multiple protocols, with a higher volume of traffic).

If Windows Networking functions like browsing, or name resolution, run thru dual protocols on one computer, or if all computers on the LAN aren't identically setup and different computers run services thru different protocols, you'll really have problems. And some problems might not be immediately obvious either.

Separating Internet traffic (using TCP/IP) from Intranet (Windows Networking) traffic (using IPX/SPX or NetBEUI) has an effect similar to using a Virtual LAN. But using a common protocol (TCP/IP) with a properly designed layered security strategy is more efficient in the long run.

>> Top

Network Diagnostic Tools

With any network, any time there's a problem, such as an "access denied" error, you'll want to first look for a possible physical problem (by observing the lights on the network devices, and by running Device Manager diagnostics). Having dismissed the physical possibility, on a TCP/IP network, you'll be looking at IPConfig, and pinging one computer from the other. You have to eliminate lower level problems, before you can diagnose higher level problems.

If you have TCP/IP on each computer, for Internet access, you can still use ipconfig and ping. But if Windows Networking is using a separate transport, neither ipconfig or ping will be conclusively valid.
  • Just because you have IP connectivity (valid ping results), that doesn't mean that you have IPX connectivity.
  • Just because your computers are on separate subnets (from a bad IP configuration, indicated by ipconfig), you can't expect to find a NetBEUI connectivity problem.
  • If you don't install TCP/IP on each computer (or if you completely detach it from any computer), then ipconfig, ping, and other IP based diagnostics won't provide consistently relevant results.


>> Top

Limitations of Effectiveness

If you have problems with either IP configuration, or with a personal firewall, either IPX/SPX or NetBEUI will provide a good workaround. But, if the problem causing the "access denied" error is a bad cable or connection, or if you haven't setup file sharing authentication / authorisation properly, you'll have the same problem with IPX/SPX or NetBEUI. But now you won't have diagnostic tools to identify the problem.

>> Top

Windows Networking

Windows Networking is the suite of programs that provide file and printer sharing between computers running Microsoft Windows (and compatible Network Operating Systems, such as Linux). If you reference the OSI Network Model, Windows Networking runs at the Application level. It uses Server Message Blocks over the lower network layers, such as Ethernet or WiFi, for connectivity.

By default, Windows Networking uses SMBs over NetBIOS Over TCP/IP (NetBT), and TCP/IP, for logical connectivity. It can be customised to use alternate transports, like IPX/SPX or NetBEUI, if you're prepared to deal with the support issues. On a large LAN with a dedicated DNS server for local name resolution, it can use SMBs directly bound to ("hosted on") Internet Protocol.

Whatever transport that you choose, though, all computers need to use the same one.

There are five concepts, which you need to understand, to deal with Windows Networking problems.


Domains / Workgroups
Computers are grouped in domains or workgroups, with membership in either grouping providing benefits.

We can browse My Network Places (known sometimes as "Network Neighborhood"), and see all nearby computers. The workgroup that we are in is the part of My Network Places that is nearest to us - those are the computers that we need access to the most. A workgroup provides a way of identifying the computers that relate closely to our computer.

A domain, on the other hand, is a collection of computers that trust each other. When your computer is joined to a domain, it sets up a two way trust, where the computer and the domain are trained to trust each other.
  1. You authenticate (login as a local administrator) to your computer.
  2. You allow a domain administrator to authenticate to the domain from your computer.
  3. Your computer learns to trust the domain. A "certificate" from the domain is added to your computer.
  4. The domain learns to trust your computer. A "certificate" from your computer is added to the domain.


The domain membership also gives workgroup visibility. You see the other members of "your" domain. as you would see the other members of "your" workgroup. But the two way trust in the domain is special.
  • You gain access to your computer thru domain authentication - you trust the domain, based upon the certificate from the domain that's now on your computer, and upon the credentials (domain account / password) that you supply.
  • You gain access to domain resources in a similar way, from the certificate from your computer that's now in the domain, and from the credentials that you supply.
  • Other people in your work area, and presumably in your domain, can potentially access your computer, as you access theirs.
  • For an allegorical description of two factor (certificate / credential) authentication, see Designing an Authentication System....


Most small LANs will use workgroups, although small domains are worthwhile. Domain membership provides two components - Authentication / Authorisation, and Browsing. Workgroup membership provides one component - Browsing. Workgroup membership provides no authentication / authorisation; that must be provided by redundant accounts setup on both the client and the server.

Outside of becoming invisible in Network Neighborhood, by changing your domain / workgroup membership, you are not adding to your security at all. Becoming invisible is simply a form of Security By Obscurity. If you're on a network with untrustable computers or people, making yourself invisible won't protect you; you need Layered Protection, including a perimeter and / or personal firewall.

>> Top

Name To Address Resolution
You might call the computer in your kitchen "Kitchen Computer", but it's a safe bet that your equipment will call it something more definitive, like "192.168.0.101" (an IP address), or "06-04-7A-D7-EF-BA" (a MAC address). The IP address, and the MAC address, are used by the various operating systems and network devices, to send message from computer to computer.

The process of translating a name like "Kitchen Computer" to an IP address like "192.168.0.101" is called name resolution. Name resolution is provided independently of domain / workgroup membership. A domain may contain a DNS or WINS server, but that's not a given. Less likely, but still possibly, a workgroup may contain either. Without a name resolution server, all computers use peer-peer name resolution. Please don't confuse peer-peer resolution with Node Type "Peer-Peer", which is just the opposite.

If your network (domain or workgroup) is setup properly, but does not contain a DNS or WINS server, all computers will use peer-peer broadcasts to resolve names. Using IP addresses to refer to computers should not be necessary, except in extreme situations. And, if you're using an alternate protocol, an IP address won't work at all.

>> Top

Browsing
Each domain / workgroup uses a browser server to tell it what resources are out there. For every domain / workgroup on a network, there should be at least one browser server in that domain / workgroup.

You can have computers in a workgroup, sharing a network with a domain. If a workgroup has its own browser server, the computers in the workgroup can see each other, and can see the computers in the adjoining domain.

If a workgroup has no browser server, its members will still be able to see each other, and the computers in the domain, if you make the workgroup name identical to the domain name. If you have a computer that's not a domain member, AND you give that computer a workgroup name identical to the domain name, the browser servers in the domain will provide visibility between that computer and the computers in the domain.

In order for browsing to work properly, several essential relationships have to exist between the various computers on the LAN in question.

Does your domain / workgroup occupy multiple subnets? If so, you need to know about Browsing Across Subnets. Do you maybe have two (or more) routers, but would prefer to have one subnet? If so, then read about File Sharing On A LAN With Two Routers.

>> Top

The Total Picture
Browsing is, arguably, not essential in a small LAN. Without the use of a browser server, a common workaround is to make an adhoc mapping to a share.

  • Hit the Start button.
  • Hit the Run button.
  • Type "\\OtherComputerName" (substituting the Other Computer Name, and less the ""), and hit Enter.


Or, you may make a persistent mapping from Windows Explorer.
  • Select Tools, then Map Network Drive, from the Windows Explorer menu.
  • Substitute the Server, and Share, into "\\Server\Share" as entered into the Folder: box.
  • Select "Reconnect at logon", if desired.
  • Select the Finish button.


Name resolution is not essential either. Without the use of name resolution, you can map a resource by substituting the ip address of the server for the name (again, if you're using NetBIOS Over TCP/IP as the transport).
  • Hit the Start button.
  • Hit the Run button.
  • Type "\\OtherComputerIPAddress" (substituting the Other Computer IP Address, and again less the ""), and hit Enter.


But, when you use Network Neighborhood (My Network Places) to provide a neat list of all the shared folders and printers on your network, you select and double click on a share, and you get a connection, you are using, in turn,

If you're having a problem with Network Neighborhood:
  • Network Neighborhood is empty, or lacks an entry for one or more computers that you know are there.
  • Computer A shows in Network Neighborhood for Computer B, but Computer B doesn't show in Network Neighborhood for Computer A.
  • You get an error "(Workgroup) is not accessible..." when opening Network Neighborhood.
  • You get a variant (and there are many variants here) of "not accessible / name not found ... access denied" when clicking on an entry in Network Neighborhood.

then you likely have a problem with either browsing, or name resolution. Diagnose Windows Networking first. If, and only if, you can't find any problems with Windows Networking, look at File Sharing. Whenever working on problems with Windows Networking, work from the bottom up.

You may also benefit from reading about Server Message Blocks, and Windows Networking.
>> Top

Authentication and Authorisation
Whether or not you do use the browser to list resources, and / or name resolution to locate the resources, you will still have to setup authentication and authorisation properly, if you wish to actually connect to, access, and change those resources. You can avoid use of the browser, and of name resolution; you cannot avoid authentication and authorisation.

>> Top

The Mysterious "Error = 53" aka "Name Not Found"

Next to an "error = 5" ("access denied"), I don't know of too many diagnostic messages that can cause so much confusion or uncertainty in the heart of your desktop / network support tech.

An error = 53 ("0x80070035" in Windows Vista) message comes in a number of circumstances.



The literal meaning of "name not found" is "I can't resolve the name of this host to an address". There are a number of possible reasons for this.

One of the most obvious is lack of physical connectivity between you (this host), and the target. Maybe that host doesn't even exist. How many times have you mistyped the name of a host that you're pinging? I've done that a few times.

I've been working with Windows Networking, and browser issues, for several years. I've come to associate "error = 53" ("name resolution") problems with several possible causes that don't come from either CKI or hardware faults.

  • Corrupted LSP / Winsock.
  • Firewall problem.
  • Registry settings.
  • Invalid node type.
  • Network components and services not started, or missing.
  • Excessive protocols.


The first three are identified only from experimentation. A corrupted LSP / Winsock is only diagnosed after its been fixed. Many times, you try everything, and I mean everything, to fix a problem. Sometimes you spend days, then somebody says "Try LSP-Fix". You run it, and that's the solution. But there are 5 possible solutions for the corrupted LSP / Winsock - LSP-Fix is just one of the 5, and not all 5 work every time.

A firewall problem you only identify after you disable a personal firewall (assuming it disables successfully, which does happen about 1/2 the time). The other half, you go thru the bit with everything else, and even try LSP-Fix and its siblings, to no avail. Then someone discovers a misconfigured or overlooked firewall, and the light goes on in your head. You un install a personal firewall, and your problems are gone.

Registry settings, which are designed for security, can cause many problems, including interfering with name resolution. Here the oddly ubiquitous restrictanonymous setting has been observed to cause problems.

Run "ipconfig /all". The value of Node Type will tell you if you have a problem. If the Node Type is "Peer-Peer", and you're on a small LAN (ie no DNS or WINS server), Peer-Peer won't work, though any other setting will, though with varying success.

Also in the log from "ipconfig /all", if you saw the line

NetBIOS over Tcpip. . . . . . . . : Disabled

you would hopefully know to correct that. But even if that line does not show, NetBT might not be enabled, and that will cause this symptom, "error = 53". Please, explicitly Enable NetBT, except for specific network conditions.

An "Error = 53", when referring to the master browser in a browstat log, can be caused by the Remote Registry Service not running on the master browser. Running a server with XP Home, as the master browser, is a bad idea - XP Home does not have the Remote Registry Service, as it does not provide for any administrative access thru the network.

Finally, if you spot IPX/SPX or NetBEUI protocols in a "browstat status" log, or IPV6 aka Advanced or Teredo Tunneling in an "ipconfig /all" log, you'll need to un install that - at least to diagnose the problem. Having unnecessary protocols will hamper name resolution. Name resolution is generally by broadcast - the computer sends out a message to all computers, thru all transports bound to that computer, asking what address the target computer is using. The computer has to wait for each transport to timeout, when no response is received, before trying the next transport, on each query.

Microsoft Unable to Reach a Host or NetBIOS Name discusses other possibilities.

>> Top

Using The Network Setup Wizard in Windows XP

There are a lot of network settings in any Windows operating system. The many settings can affect how your computers connect to each other, and to the Internet. The Network Setup Wizard is provided as a part of Windows XP, to make the more common settings, for you. In Windows Vista, you'll use the Network and Sharing Center wizard.

The Network Setup Wizard is most useful when run on a properly designed, setup, and prepared network.

  • Make sure the following network components are installed, in the network items list in (Name of connection) Connection - Properties.
    • Client for Microsoft Networks.
    • File and Printer Sharing for Microsoft Networks.
    • Internet Protocol (TCP/IP)
  • Make sure that the DHCP Client service is running - Started and Automatic.
  • Make sure that the Internet Connection Firewall / Internet Connection Sharing (ICS) (pre-SP2), or Windows Firewall / Internet Connection Sharing (ICS) (SP2) service is running - Started and Automatic.
  • Configure your firewall setup, including installing any third party firewalls, after you run the wizard.


I know of several ways to start the wizard.
  • From (Start - Programs - Accessories - Communications - ) Network Setup Wizard.
  • From Windows Explorer, with Common tasks enabled.
    • In Network Connections, look under Network Tasks.
    • Select
      Setup a home or small office network.
  • From the Help and Support Center.
    • Start Help and Support.
    • Search on "Network Setup Wizard".
    • Under "Pick a task", select "Start the Network Setup Wizard".
      To start the Network Setup Wizard
      You must be logged on to this computer as an administrator to complete this procedure.
      1. Start the Network Setup Wizard.
      2. Follow the instructions on your screen.
    • Select the shortcut in "Network Setup Wizard".


The Network Setup Wizard will run on your computer only if
  1. You are logged in with administrative authority.
  2. Your computer is not joined to a domain.


When you run the Network Setup Wizard, you are given a total of five choices, on two screens, which identify how you connect your home or small office network to each other, and / or to the Internet. See Practicallynetworked XP ICS - Starting the Network Setup Wizard for more graphical instructions.

Alternatives
The Network Setup Wizard is a Windows XP component. If you have a computer running another version of Windows, like Windows 98 or ME, you can run NetSetup. Copy NetSetup.exe from "C:\Windows\System32" to a CD or a USB flash drive, carry the CD or flash drive to the target computer, and run it from there. You are under no obligation to copy anything to any device or drive; any settings that you make on this computer, using the Network Setup Wizard, you can make on another computer, manually. The Network Setup Wizard is simply a convenience tool.

You can do just what NetSetup.exe, or the Wizard, does, on any computer running Windows XP, 2000, 98, or ME.
  • Install any missing network components, from Network Neighbourhood - Properties - Configuration.
    • Client for Microsoft Networks.
    • File and Printer Sharing for Microsoft Networks.
    • TCP/IP.
  • Set the Computer Name, and Network Name, from My Computer - Properties - Computer Name, or Network Neighbourhood - Properties - Identification.
  • Set TCP/IP to obtain IP and DNS server addresses automatically, from Network Neighbourhood - Properties - Configuration - TCP/IP Properties.


Note that the Network Setup Wizard only makes very basic system settings, and doesn't check for the presence and configuration of other computers on the network. If you run the Wizard, and you don't get the results that you expect, you'll need to read either Troubleshooting Network Neighborhood Problems (for local access problems), or Troubleshooting Internet Service Problems (for Internet access problems). You may also benefit from reading Solving Network Problems. Be persistent.

If you cannot run either NetSetup.exe or the Network Setup Wizard, on any computer, you can still setup your network. On a computer with Windows 2000, or in any other case where neither netsetup nor the wizard can be used, you can make all settings manually.

ICS Host
This computer connects directly to the Internet. The other computers on my network connect to the Internet through this computer.

This network configuration uses (KB306126): Internet Connection Sharing (ICS) to share this computer's Internet connection with the rest of the computers on your network. Communication to and from the Internet to all the computers on your network are sent through this computer, called the ICS host computer.

If you're going to use an ICS host to provide Internet service for your network, please use (KB283673): Internet Connection Firewall (Windows pre-SP2), Windows Firewall (Windows SP2), or a third party personal firewall at all times. Please don't ever connect an unprotected computer to the Internet.

Note the other disadvantages and requirements of ICS. You'll have to have two separate network connections (one might be a modem, directly connected). You'll indicate which connection is to be used to connect to the Internet. Other connections on the computer will then be used for sharing the service.

As an ICS Host, the wizard will perform steps 1 - 11, from the list of Actions below.

Gateway (ICS or NAT Router) Client
This computer connects to the Internet through another computer on my network or through a residential gateway.

This computer is part of a home or small office network that connects to the Internet through another computer on the network or using a residential gateway (i.e., a NAT router). If you have another computer on your network that shares its Internet connection, called the ICS host computer, this computer will be able to send and receive e-mail and access the Web, as if it were connected directly to the Internet.

A residential gateway is a hardware device that works similarly to a host computer. Typically, a DSL or cable modem connects to the Internet service, and the residential gateway connects to the modem. Internet communication is shared by the residential gateway to all of the computers on your network.

As a NAT Client, the wizard will perform steps 1-5, then 10-11, from the list of Actions below.

Multiple Direct Internet Connections
This computer connects to the Internet directly or through a network hub. Other computers on my network also connect to the Internet directly or through a hub.

This network configuration typically has an external DSL or cable modem connected to an Ethernet network hub. The other computers on your network are also connected to the network hub. Each computer on the network has a direct connection to the Internet by means of the network hub and DSL or cable modem.

If you are using this configuration for your home or small office network, I highly recommend that you disable file and print sharing on the TCP/IP protocol and enable it on the IPX/SPX protocol. If you share files and folders on your computers using the TCP/IP protocol, they could be seen on the Internet. Only enable IPX/SPX for file and printer sharing if you are using this network configuration for your home or small office.

I do not recommend this network configuration. It exposes all computers on the network directly to the Internet, creating potential security problems. I highly recommend that you use a secure host device, such as a computer running Windows XP with ICS and Windows Firewall enabled, or using a residential gateway.

As a Directly Connected Client, the wizard will perform steps 1-5, then 10, from the list of Actions below.

Single Direct Connection To The Internet
This computer connects directly to the Internet. I do not have a network yet.

Select this option if you only have one computer and it has an Internet connection. The Network Setup Wizard configures this computer to use Windows Firewall, to protect your computer from intrusions from the Internet.

Networked Locally But Not To The Internet
This computer belongs to a network that does not have an Internet connection.

Select this option if you have two or more computers networked together, but don't have an Internet connection. You can have a home or small office network, using Ethernet, a home phoneline network adapter (HPNA), or wireless adapters. If you have different network adapter types, such as Ethernet, HPNA, or wireless devices, installed in your Windows XP computer, the Network Setup Wizard can create a network bridge to allow all of the computers in your network to communicate.

If you're lucky and have Ethernet on both computers, you can use a hub and Ethernet cables to connect your computers. This is, by far, the best choice in your case. If you're connecting just 2 computers, you can even use a cross-over cable, instead of a hub.

Actions Taken By The Wizard

Depending upon the Option selected, the wizard will do any of the following:
  1. Set the computer name, computer description, and workgroup name that you specify.
  2. Install these network components if they're not already present:
    • Client for Microsoft Networks.
    • File and Printer Sharing for Microsoft Networks.
    • TCP/IP.
  3. Share any printers connected to the computer.
  4. Create the "Shared Documents" folder, if it doesn't exist.
  5. Share the "Shared Documents" folder.
  6. Enable Internet Connection Sharing, on the network connection that you specify.
  7. Enable the Internet Connection Firewall (pre-SP2) / Windows Firewall (SP2), on the shared network connection.
  8. Create a Network Bridge, if more than one local area network connection exists.
  9. Configure the local area network connection (or Network Bridge), using IP address 192.168.0.1/24.
  10. Configure the local area network connection, to obtain an IP address automatically.
  11. Install software, to allow the client to control the host's Internet connection.


>> Top