Showing posts with label VPN. Show all posts
Showing posts with label VPN. Show all posts

Using The Internet As A WAN Link? Use A VPN.

Stable and secure Windows Networking depends upon properly designed, routed, subnets. IP routing was designed to make Local Area Networks connect, yet still observe geographical relationships. Using routers between LANs allows localisation of some domain services (browsing, name resolution), but wide spread availability of others.

When you route IP connectivity thru wiring that you own and control, that's behind a firewall, each connected LAN is as safe as any of the other LANs. Threats on the outside (Internet) stay on the outside. Two geographically separate LANs, connected by a dedicated, leased communication line, are as safe as each other is safe.

What if you have 2 LANs, distant from each other, and can't justify the expense (initial or ongoing) of a leased or owned communication line? If both LANs have Internet access, you can still connect them; just use the Internet as the WAN link.

But wait! I hope you know how dangerous the Internet can be. It's bad enough when accessing it as clients. Plain old web browsing is bad enough, how about running a server on the Internet? OK, how about running all of the computers on your LANs thru the Internet? Why not hold up a $100 bill, and stroll thru Times Square in New York City? See if you get anywhere alive.

But you can connect your LANs thru the Internet, if you design the connection properly. A controlled, encrypted tunnel between your LANs, using routers that support a Virtual Private Network (aka VPN) will do this fine.

A VPN will be a lot easier to setup, and more stable and secure, when properly planned.



>> Top

Each LAN Is Addressed By Its WAN Address.
The VPN routers setup static tunnels between each other. Setting up a VPN router requires identifying the other router(s), by its IP address as well as by a pre installed certificate (aka pre shared authentication key). If you can't provide a fixed IP address for each router, you'll have to use a domain name, registered with a dynamic DNS service like DynDNS, TZO, or the like.

>> Top

Hardware Compatibilty Is A Must.
There are various conventions and standards for establishing, and conducting, authentication and encryption in a VPN. Each router manufacturer will likely have some variation, however small. The easiest, and most stable, VPNs will use router hardware of the same make, model, and firmware level at each end of a VPN tunnel.

>> Top

LAN Subnets Must Be Unique.
A VPN provides a routed connection between LANs. In order for routing to work best, you have to have different subnets on each LAN. When you setup a VPN between LANs that were setup before being connected, you may have some LANs using the same subnet. You can't have stable LANs, each having the same subnet, connected by a router.

>> Top

Use DNS For Reliable Name Resolution.
On most small LANs, you'll use broadcasts for name resolution. Broadcasts aren't routable; each IP subnet is, by definition, a broadcast domain. If you want computers on one subnet to access computers on another (which is, presumably, why you're setting up a VPN), you'll find computer names more convenient than IP addresses. Some VPNs will, if configured, pass SMBs for name resolution and browsing, but this will likely slow down Windows Networking. DNS based name resolution is the best way to go, for anything more complex than a single local cluster of computers.

>> Top

Use Domains, Not Workgroups.
If you use Network Neighbourhood to identify and access other computers, you'll need browsing to work between the subnets connected thru the VPN. A properly designed domain structure will make browsing work much better.

>> Top

Connectivity Between Any LAN And The Internet Can Affect Its Connection With The Others.
A VPN connection between any two LANs requires regular interchange of control information, and irregular application data. Balanced connectivity makes both more predictable. If one LAN has a dual WAN business class DSL service, and the other has residential class dialup, how secure and stable will that VPN be?

>> Top

Security On Any LAN Can Affect The Others.
VPNs are used to connect geographically separate LANs, and imply some degree of trust between those LANs. The computers on any LAN, connected to a VPN, are only as secure as the computers on the LAN with the weakest security policies. Review, and synchronise security policies before setting up a VPN.

If you wish to setup a VPN between your home network and your work network, security at your work may be compromised. You should always get permission from LAN administration, before doing this. You may be legally at risk without such precautions.

>> Top

Increased Sophistication and Excess Bandwidth Mitigates These Issues.
As availability of VPNs has increased, with VPN capable hardware sold in WalMart and similar convenience stores, and as VPN firmware becomes more sophisticated, each endpoint in a VPN relationship will be better able to adjust to differences between its own environment and the environment present at the other end. Many of the above issues won't be quite as relevant in the future. But if you start out being aware of the issues, you will be prepared to deal with them when they do become relevant.

>> Top

Networking Your Computers

Setting up a computer network, whether to share files, or Internet service, can be a lot of fun. It's more fun, though, if you set it up properly, from the start. I'll try and make that possible, if you work with me.



>> Top

With the basic issues out of the way, you can get detailed instruction from plenty of websites, that will give you illustrated instructions. Here are but five, listed in alphabetical order.

If you have properly chosen and setup your equipment, advice from any one of the above should get your network in order. The various guides are written by different organisations, and each has a different style, so check them all out if possible. Find the one which works best for you.

>> Top

Solving Problems
If you're here because you have problems, please start by reading Solving Network Problems.

Now, what is your specific problem? Is it accessing the Internet? Then read Troubleshooting Internet Connectivity. Or is the problem with File Sharing? Then read Troubleshooting Network Neighborhood (Windows Networking).

One major issue that the websites listed above won't help you with, if your problem is with file sharing, is the browser. Now when I mention the browser, don't start with "My Internet access is not a problem". The browser is the program that provides the contents of Network Neighborhood on your LAN. It's frequently involved in problems when "I can't see the other computers", or "I get access denied when I try to access another computer". Please read my article Windows NT (NT/2000/XP/2003) and the Browser.

Do you have a LAN with both Windows 9x (95, 98, ME) computers and Windows NT (NT, 2000, XP) computers? Then you should read Windows 9x (95/98/ME) and the Browser.

>> Top

In Conclusion
All of the above articles link to dozens of other articles, so read carefully. And be patient with me, as I add to this blog occasionally. Check back here periodically. Or write to my Guestbook.

>> Top

Your Personal Firewall Can Either Help or Hinder You

One of the key elements in a layered defense strategy is a personal firewall on each computer. You need to protect each computer on your LAN from hostile Internet traffic, and sometimes, from hostile traffic coming from other computers on your LAN.

Unfortunately, if you don't setup your personal firewall properly, you can have problems.

A misconfigured or misbehaving personal firewall on one or more computers on your LAN can block access to the server, whether local (on your LAN) or remote (on the Internet), that you need to access. If your problems remain even after you configure your personal firewall, then you will need to try deactivating it, or un installing it.

Deactivating a firewall isn't always an effective solution. Many personal firewalls do not react well to being deactivated - you have to either configure them properly, or un install them. Un installation, depending upon the brand, may require intensive work, and may involve more than running a simple script from Control Panel or All Programs - (Name Of Firewall Product).

Once you deactivate or un install the firewall, you are unprotected. If you must deactivate or un install your firewall, only do this temporarily. If you're connected directly to the Internet (which is simply not a recommended setup, even with a personal firewall on the computer), disconnect from the Internet BEFORE doing this. After you get things working, then re install, reactivate, and configure a firewall on each computer, before reconnecting.

Configuring a personal firewall, to enable access to the desired services, may involve changing one or more settings. Please spend some time reading the documentation for the firewall in question. After reading the documentation, check the appropriate settings. For Windows Firewall, see Windows Firewall and Windows Networking.


  • Select the appropriate Protection ("paranoia") level.

  • Make sure that exceptions are permitted.

  • Select a preset exception or rule.

  • Configure the Trusted Zone. Be sure that the router, the DHCP and DNS servers (if separate), and the other computers on the LAN, are all Trusted. Get this wrong, and you could have various symptoms.
    • Not all computers might be visible in Network Neighbourhood.
    • Other computers might be visible, but in the "Internet Zone".
    • Other computers might be visible, but attempting to access some will result in the much feared "Access Denied".
    • Attempting to access any computer, local or Internet, may return the equally disliked "Name not found" or similar error.

  • Open the appropriate ports.



Please don't make the mistake of running two or more personal firewalls. Running more than one firewall will not add protection, it will just cause confusion and system malfunctions. If you're going to run a third party firewall, you must chose one and only one. Make sure that you're aware of all software products on your computer, that could act as a personal firewall.

  • Do you have an antivirus product (and if not, get one immediately!)? Some antivirus products come bundled with personal firewalls. F-Secure Internet Security, McAfee Internet SecuritySuite, and Norton Internet Security, for example, each contain both antivirus and personal firewalls (F-Secure Personal Firewall, McAfee Personal Firewall and Norton Personal Firewall, respectively). A newly installed Microsoft (KB923157): Windows Live OneCare may be an issue here.

  • Even if your antivirus is NOT part of a bundle, it may have a component that acts like a firewall. Some antitrojan, antivirus, and antiworm products can install components that cause these problems. As every security package struggles to keep up with the bad guys, and with competing products, features are constantly being added. Examine any antitrojan / antivirus / antiworm product with suspicion, when researching any otherwise unexplained network problem.
    • Read the manual / owners guide for your security product.
    • Google / Yahoo for your security product name / version. See if there are any reported similar problems.

  • Recent changes to Internet Explorer (likely the September 2007 security updates) have caused changes in the My Network Places (Network in Windows Vista) display, and possibly access problems.

  • The Microsoft AntiVirus / Personal Firewall bundle, Windows OneCare, doesn't operate as seamlessly as Windows Firewall, under Windows Vista. You may have to check the NetBT setting, or open some ports manually, to get Windows Networking to work with OneCare under Vista.

  • Server Message Blocks, or SMBs, are the lifeblood of Windows Networking. Make sure that all firewalls are setup to pass SMBs properly - whether you're using SMBs directly hosted on IP, or SMBs hosted on NetBIOS Over TCP.

  • Do you have a VPN endpoint on the computer? Many VPN endpoints are bundled with personal firewalls.

  • What network card do you have? Does it have an nVidia chipset? The nVidia nForce is probably the first, but surely not the last, device of this type.

  • Is a NAT router in the center of your LAN?
    • Most NAT routers use only a switch, connecting the LAN ports. But look carefully for a "DMZ", "Isolation Mode", "Virtual Server", or "VLAN" setting - either on a single port, or affecting the entire LAN. These options are becoming more popular on NAT routers which emphasise sharing Internet access, and make peer-peer connectivity optional.
    • Did you just change to a different NAT router? If the router changed recently, check the subnet that it creates. If the subnet has changed, all computers on the subnet, with firewalls or other security components that assign trust by IP address, may have to be updated to reflect the new subnet.

Don't get surprised, and waste a lot of time looking for a solution that may be right under your nose - check for a bundled firewall first.

If you're going to run a third party firewall, you must disable Windows Firewall, but only from the appropriate Control Panel applet - do not make the mistake of stopping the Windows Firewall service. The Windows Firewall service breaks several network services, if it is stopped.

Stop Windows Firewall from either the Security Center, or the Windows Firewall, applet. Settings - Control Panel, then either:
  • Security Center, and select Firewall Off.
  • Windows Firewall, and select Off.

Please leave the Windows Firewall / Internet Connection Sharing (ICS) service Started and Automatic, at all times. See Microsoft Threats and Countermeasures Guide: Chapter 7 for more information. Also, see (KB889320): When you disable the Windows Firewall service... for a problem acknowledged by Microsoft with a Hotfix.

On the other hand, if you decide to un install your newly discovered third party firewall, please read and observe precautions.

>> Top

Troubleshooting Internet Service Problems


Next to "I can't access files on Computer B from Computer A", the complaint "My Internet service doesn't work" is almost as common. There's good news here, and there's bad news. The good news? A problem with your internet service, since it only depends upon TCP/IP, will be a lot easier for you to diagnose. The bad news? Since it depends upon something outside your house, and in some cases outside your city or state, many problems will be ones that you can't fix - you have to get your ISP involved.

This article, like Troubleshooting Network Neighborhood Problems, is structured like the OSI 7-Layer Network Model. If you have multiple problems with your network, you have to diagnose and fix the lower level problems first. If you don't, how can you diagnose the higher level problems?

Now before you start troubleshooting, note that you will enjoy it more, and frequently will be more successful, when you work on a properly designed and setup network. Once you've reviewed that, I recommend that you tackle the task at hand in this order.


So what are the differences between this article, and Troubleshooting Network Neighborhood Problems? Well, there is good new, and bad news. The good news - less protocols to deal with. The bad news - more distance and juridictional issues.

With Windows Networking, if there's a problem, it's yours (or maybe the vendor of the hardware that you own, if the problem involves hardware failure on a component under warranty). With Internet Service, the responsible party could be:

  1. You.
  2. Your ISP.
  3. If your ISP leases the connection between you and their offices, the Local Exchange Carrier (your local phone service if you have DSL) might be involved.
  4. The vendor, if the problem involves hardware failure on a component under warranty.
  5. Any number of individual network and server operators. Except in special cases, you will never know these parties, let alone contact them with any chance of getting useful results.

Physical Network Problems
Your problem could be caused by a simple physical network problem.

Of course, the card, cable, port, any other network component, could be one owned by your ISP, or by the LEC, if not your ISP. Or by any of the other parties described above.

Try and diagnose physical network problems from the bottom up.

>>Top

Logical Network Problems

Did you just connect a new router, or a different computer, to your broadband modem? You can't do that casually - you may have to reset your Internet service, to register a different network device with the service.

Given a little preparation (have the correct device drivers available), you should be able to re install the drivers for the network adapter without too much trouble. This is usually one of the last things tried, but can be one of the easiest.

TCP/IP is the language of the Internet, and proper TCP/IP settings are essential. If you're unfamiliar with IP configurations and networking, ask for help.

Also, a corrupt LSP / Winsock layer can have an effect any TCP/IP connectivity. If you've just removed adware / spyware, this is always a possibility.

Did you already run the Network Setup Wizard? You have to read the wizard selections carefully.

  • If your computers all connect to a NAT router (My absolute recommendation), select Option 2 for all computers.
  • If you have a host sharing Internet service to the other computers, select Option 1 for the host, and Option 2 for the clients.


Finally, if you have a problem accessing only some websites, but not others, or if this problem seems to come and go, you may have an MTU setting problem.

>>Top

Address Resolution Problems
With Windows Networking, you have the process of Address Resolution (Local Computer Name to Address). With Internet service, you have the process of Address Resolution (Distant Computer Name to Address). Address resolution is essential.

In addition to preventing an LSP / Winsock problem from interfering with address resolution, you need to ensure that you have access to an active Domain Name System (DNS) server for address resolution. You can have a DNS server for resolving addresses on your LAN, if you wish, but your Internet access will depend upon another DNS server somewhere outside your LAN.

If your Windows XP computer is part of a domain, make sure that the domain is setup properly to provide both internal addresses and external (Internet) addresses.

The DNS infrastructure is pretty transparent to us, when it works, but sometimes it doesn't work. Right now, the bad guys are exploring ways to use DNS to get us to surf to their malicious websites. There have actually been 3 attacks, in the early months of 2005, where folks have surfed - without their intention or permission - to a malcious website - and in some cases, have downloaded software that they didn't want, nor realise. This practice is called pharming, and it is an ongoing possibility for problems.

Besides DNS resolution, you may have your Hosts file to consider.
>>Top

Security Problems
You need a personal firewall on each computer, but your personal firewall has to be properly setup and used. A misconfigured or misbehaving personal firewall, on your computer, can block access to the Internet. Your personal firewall may need setup, to trust the host - either an ICS server, or a router - providing Internet service to your computer.

If you disable your personal firewall, and the problems stop, then you at least know where to start working. But if the problems don't stop, don't assume that the firewall is not the problem. Many personal firewalls do not react properly to being disabled, and will continue to cause problems after being disabled. And look for a previously overlooked firewall, such as one bundled with your antivirus protection.

Besides a personal firewall causing problems, there are security features in your browser that can cause problems, if misconfigured.

>>Top

Network Components and Services
This section, as I hinted above, is relatively simple. Your computer requires TCP/IP. You must have "Internet Protocol (TCP/IP)", in the network items list in Local Area Connection - Properties.

If your computer is going to be supplying Internet service to other computers (using ICS), you'll need ICS running. Check that the service supplying ICS, under one of two possible names, is Started and Automatic.

  • For XP SP2, check the Windows Firewall / Internet Connection Sharing (ICS) service.
  • For XP pre-SP2, check the Internet Connection Firewall / Internet Connection Sharing (ICS) service.


If your computer is going to be supplying Internet service to other computers (using ICS), and ICS isn't running, rerun the Network Setup Wizard, and choose Option #1, This computer connects directly to the Internet. If there's a problem with the NSW, or if running the NSW doesn't produce acceptable results, check the Event Viewer for diagnostic messages.

>>Top

Virtual Private Networking
Internet usage, in general, involves casual connectivity. Any client, within reason, is encouraged to connect to any server. This is many to many connections.

What if you have two offices, located at distance from each other, and want to use the Internet to provide communications between the two? This would be a point to point connection, formally setup between the two offices. A Virtual Private Network is a pre-configured, secure communications tunnel, through an otherwise insecure network (aka the Internet), between two locations.

Setting up a VPN isn't done casually, or between changing locations; a VPN has to be deliberately designed and setup, from both ends.

>>Top

Asking For Help
If you're reading this article because you need help, please start by reading my Privacy Statement.

Spend a few minutes reading about How To Solve Network Problems.

Provide some background information about the problem, and about your network in general.

Ensure that each computer is Physically, and Logically, connected to your network, to your best ability.

>>Top

Diagnose the problem, on each computer involved, using my test outlined in Identifying A DNS Problem In Your Internet Service. Note, and report, the results of the tests.

Localise the problem (Where is it happening?), and identify its time scope (When is it happening?). If the problem is NOT in your LAN, and you have to go to your ISP for support, having solid time of day / day of week documentation could be very helpful.

How long has the problem been happening? Contrast that with how long have you had this computer setup as it is right now (And how was it setup previously?). And what was changed (hardware / software) just before the problem started?

I use PingPlotter (free) to document all my network issues, and have it running on at least one computer on my LAN, on a 24 x 365 basis. Set PingPlotter up regularly pinging a server outside your LAN, say your ISPs DNS server. If you see the trace stop somewhere when your problem is happening, where does it stop? Does it show loss of contact with your router, or with the ISPs DNS server? Make a file, if appropriate, and send it to the tech support at your ISP. A picture (or PingPlotter graph in this case) could be worth a thousand words.

>>Top

Finally, provide ipconfig information for each computer. You'll do this from a Command Window.

  1. Type "ipconfig /all >c:\ipconfig.txt" (less the "") into a command window (or a command window in Windows Vista). Note the spaces in the command, and note the difference between the "/" and "\" characters! Only type the command into a command window - do not type Start - Run - "ipconfig /all".
  2. Type "notepad c:\ipconfig.txt" (again, less the "") into the same command window.
  3. In Notepad, make sure that Format - Word Wrap is NOT checked!.
  4. Copy (Ctrl-A Ctrl-C) from the Notepad window, and paste (Ctrl-V) the entire contents of the ipconfig log, into your next posted message, properly formatted.
  5. Identify operating system (by name, version, and Service Pack level) with each ipconfig listing.
  6. Please don't munge or omit any detail, as there is nothing provided by ipconfig that could provide help, to any bad guy, in identifying an entry point to your LAN. The good guys, on the other hand, may need any or all of the details, to accurately diagnose your problem. Help Us To Help You.

Did you just run ipconfig, and get good output (similar to what's described in the ipconfig article?). Ok, fine, continue and examine the output as instructed below. If you ran it, and got no response, or no output, or if a window opened and closed so quickly you couldn't read anything, please read my article on Using The Command Window.

With IPConfig logs in hand, you may take a look at Reading IPConfig and Diagnosing Network Problems, if you're interested.

>>Top

Troubleshooting Network Neighborhood Problems

When you try to access a shared folder from Network Neighborhood / My Network Places, and get the dreaded "Access denied..." error, or when other computers don't show up there at all, you could have any one (or more than one) of several problems. Look closely at the complete and exact text, in any observed error messages; this can help diagnose many problems more effectively.

This article, like Troubleshooting Internet Service Problems, is structured like the OSI 7-Layer Network Model. If you have multiple problems with your network, you have to diagnose and fix the lower level problems first. If you don't, how can you diagnose the higher level problems?

Now before you start troubleshooting, note that you will enjoy it more, and frequently will be more successful, when you work on a properly designed and setup network. Once you've reviewed that, I recommend that you tackle the task at hand in this order.


So what are the differences between this article, and Troubleshooting Internet Service Problems? Well, there is good new, and bad news. The good news - this problem is one you can solve yourself, without involving your ISP, or LEC. The bad news - there are a lot more network details that you will have to deal with.

>> Top

Physical Network Problems
The content of Network Neighborhood / My Network Places is cached on your computer, and what you see there could have been placed there as much as an hour ago. Since then, the server that you're trying to access could have been:

  • Turned off.
  • Disconnected, intentionally or unintentionally.
  • Moved out of range, if on a wireless LAN.

Make sure that you don't have a simple physical network problem. And make sure that all computers are directly connected, on the same LAN segment, if at all possible.

Try and diagnose physical network problems from the bottom up.

>> Top

Logical Network Problems

Given a little preparation (have the correct device drivers available), you should be able to re install the drivers for the network adapter without too much trouble. This is usually one of the last things tried, but can be one of the easiest.

The content of Network Neighborhood / My Network Places comes from messages ("Server Message Blocks", aka "SMBs") sent from computer to computer. In Windows Networking, SMBs are most frequently transported over TCP/IP, and proper TCP/IP settings are essential. If you're unfamiliar with IP configurations and networking, ask for help.

Note that SMBs are generally sent over NetBIOS Over TCP/IP, aka NetBT. In large LANs, with a properly setup domain structure, SMBs can be bound directly to IP; this is known as directly hosted SMBs.

Also, a corrupt LSP / Winsock layer can have an effect on Network Neighborhood, just as it affects any network activity. If you've just removed adware / spyware, this is always a possibility.

Are all of the computers on the same subnet, physically and logically? Or did you, for some reason, setup a LAN with 2 routers?

>> Top

Address / Name Resolution Problems
In Windows Networking, using SMBs over NetBT, properly configured name resolution is important. Run "ipconfig /all" and verify the Node Type. An inappropriate Node Type will prevent name resolution, or slow it down.

Any time you run a diagnostic like browstat, ipconfig, ping, or anything else that lists a computer name, and the name is garbaged or contains non alphanumeric characters, a corrupt LSP / Winsock layer is a very good possibility. A problem in the Hosts or LMHosts file can have the same effect.

If an actual "error = 53" message is one of your symptoms, this literally means "host name not found", but there are several possible causes for this scenario. Name resolution configuration is just one of the possible causes.

Most of these instructions are written to focus on the needs of workgroup infrastructures, though domains also apply in most cases. If you're using directly hosted SMBs, consider the needs of domain based name resolution.

>> Top

Security Problems
You need a personal firewall on each computer, but your personal firewall has to be properly setup and used. A misconfigured or misbehaving personal firewall, on a computer, can block access to the server that it's protecting.

If you disable your personal firewall, and the problems stop, then you at least know where to start working. But if the problems don't stop, don't assume that the firewall is not the problem. Many personal firewalls do not react properly to being disabled, and will continue to cause problems after being disabled. And look for a previously overlooked firewall, such as one bundled with your antivirus protection. There could even be a hardware firewall, sitting inside your computer. The nVidia nForce is probably the first, but surely not the last, device of this type.

Misbehaving and misconfigured firewalls, and overlooked firewalls, are probably the most common root cause of problems with Windows Networking, in the cases where I have been able to provide assistance.

And remember that, if you're using an alternate transport such as IPX/SPX or NetBEUI, a firewall will provide no protection.

>> Top

Network Components and Services
Windows Networking depends heavily upon half a dozen key networking components and services. Depending upon the role played by any computer, it may require some, or all, of these components and services, to work properly.

If you add or change any network components, run the Network Setup Wizard before continuing.

If you're using a NAT router as the DHCP server (and most of you will be), please Enable NetBT explicitly, except for specific circumstances. Make this setting consistent across your entire LAN.

If your LAN
  • Has a domain.
  • Has computers running only Windows 2000, Windows 2002 (aka Windows XP), and Windows 2003 (aka Server 2003).
  • Uses DNS, properly setup, for name resolution.
then you may wish to disable NetBT, and use direct hosted SMBs.

If TCP/IP can't be used properly, SMBs using an alternate protocol such as IPX/SPX or NetBEUI may provide immediate access to shares, but still cause "access denied" errors here. If you are using an alternate protocol (listed in the network items list in Local Area Connection - Properties), you may have problems with Network Neighborhood / My Network Places. Please remove both IPX/SPX and NetBEUI, unless one is absolutely needed. You certainly should not need both.

There is one exceptional circumstance where IPX/SPX may be needed. Please follow the complete instructions precisely - using TCP/IP here won't help the browser, and it will cause major security problems.

And sometimes when you run the Network Setup Wizard, you may end up with IPV6 aka Teredo Tunneling, which is not compatible with Windows Networking. You must remove IPV6, at least to diagnose the problem.

>> Top

Browser Problems
The content of Network Neighborhood / My Network Places comes from a subsystem known as the browser. At least one computer must be running the browser service, but having too many browsers can result in a browser conflict.

A master browser conflict can cause various problems in Network Neighborhood. A master browser conflict can have numerous causes. Running Browstat is a good way to start looking for browser related problems.

With Windows XP, computers only display in Network Neighborhood if there is actually a share (and not an administrative $ share either) created. Servers with no shares don't get enumerated by the browser, so they won't be seen in Network Neighborhood.

Available and visible shares, on servers in the same workgroup as your computer, will get listed in the root of Network Neighborhood (My Network Places). Other workgroups, with their computers, will be listed under Entire Network - Microsoft Windows Network. If another computer isn't visible where you think it should be, verify the workgroup name (of the other computer, and of your computer) in System Properties - Computer Name.

An "access denied" message, or inability to see a server in Network Neightborhood, can be caused by the restrictanonymous setting. And a totally invisible server can also be caused by the Hidden setting.

A "network path was not found" message, when referring to the master browser in a browstat log, can be caused by the Remote Registry Service not running on the master browser. Running a server with XP Home, as the master browser, is a bad idea - XP Home does not have the Remote Registry Service, as it does not provide for any administrative access thru the network.

Do you have a network with computers running both Windows 9x (95, 98, ME) and Windows NT (NT, 2000, 2003, XP)? If so, you'll need to check for browser conflicts between computers running the two different operating system families.

Does your domain / workgroup occupy multiple subnets? If so, you need to know about Browsing Across Subnets.

The browser can be a tricky problem to tackle. If you're unsure about how to deal with it, ask for help.

>> Top

Sharing - Naming and Permissions Problems

The names used for the shares, and other factors, can make a difference in their accessibility.

Windows 95 / 98 clients will have a problem with (KB160843): share names with more than 12 characters.

Windows NT / 2000 browser servers will have a problem with (KB231312): server comments greater than 48 characters.

You can get "access denied", and other symptoms, from actual lack of permissions to access the desired share. Shares with name ending in a "$" (Administrative shares) won't be accessible, if the server is depending upon Guest authentication, since Guest doesn't have administrative access.

Either the restrictanonymous setting, or the RestrictNullSessAccess setting, can cause lack of access to a share, if you're attempting Guest authorised access. The latter can even affect shares selectively - some may be accessible, others not.

>>Top

Virtual Private Networking
Windows Networking, in general, involves local connectivity. Resource sharing is more effectively done when client and server are physically located near each other.

What if you have two offices, located at distance from each other, and want to use the Internet to provide communications between the two? This would be a point to point connection, formally setup between the two offices. A Virtual Private Network is a pre-configured, secure communications tunnel, through an otherwise insecure network (aka the Internet), between two locations.

A VPN has to be deliberately designed and setup, from both ends. An improperly designed VPN may cause more problems than it solves.

>> Top


Identifying the Scope of the Problem.

I've developed two simple utilities for checking your network, to identify the scope of a network problem. Both utilities are most useful when run from each computer, with output from all runs aggregated, and compared in masse.

The first utility, CDiag, examines your network by knowing the name and address of each computer. CDiag uses native Windows commands only, and runs from each computer without any explicitly granted network access to other computers.

The second utility, CPSServ, examines your network by automatically discovering each computer. CPSServ requires prior download of PSService, which is part of the free SysInternals PSTools utility. Neither CPSServ nor PSTools require any effort to install. PSService does require administrative access to each computer, so it won't be terribly useful on a network with XP computers running XP Home.

Documentation of both utilities is in progress, so be patient. Limited CDiag documentation is currently available.

>> Top

Asking For Help
If you're reading this article because you need help, please start by reading my Privacy Statement.

Spend a few minutes reading about How To Solve Network Problems.

Provide some background information about the problem, and about your network in general.

Ensure that each computer is Physically, and Logically, connected to your network, to your best ability.

>> Top

Next, provide ipconfig information for each computer. You'll do this from a Command Window (or a command window in Windows Vista).

  1. Type "ipconfig /all >c:\ipconfig.txt" (less the "") into a command window (or a command window in Windows Vista). Only type the command into a command window - do not type Start - Run - "ipconfig /all...".
  2. Type "notepad c:\ipconfig.txt" (less the "") into the same command window.
  3. In Notepad, make sure that Format - Word Wrap is NOT checked!.
  4. Copy and paste entire contents of the file into your next message, properly formatted.
  5. Identify operating system (by name, version, and Service Pack level) with each ipconfig listing.
  6. Please don't munge or omit any detail, as there is nothing provided by ipconfig that could provide help, to any bad guy, in identifying an entry point to your LAN. The good guys, on the other hand, may need any or all of the details, to accurately diagnose your problem. Help Us To Help You.

Did you just run ipconfig, and get good output (similar to what's described in the ipconfig article?). Ok, fine, continue and examine the output as instructed below. If you ran it, and got no response, or no output, or if a window opened and closed so quickly you couldn't read anything, please read my article on Using The Command Window.

Take a look at Reading IPConfig and Diagnosing Network Problems, if you're interested. Or, given a complete and unmunged set of "ipconfig /all" logs, I'll simply plan to use CDiag for the next step.

Next, provide "net config server", and "net config workstation", for each computer. You'll do this from a command window (or a command window in Windows Vista).

  1. Type "net config server >c:\netconfig.txt" (less the "") into a command window (or in Windows Vista). Only type the command into a command window - do not type Start - Run - "net config...".
  2. Type "net config workstation >>c:\netconfig.txt" (less the "") into that command window (or in Windows Vista). Note the ">>" here! Only type the command into a command window - do not type Start - Run - "net config...".
  3. Type "notepad c:\netconfig.txt" (less the "") into the same command window.
  4. In Notepad, make sure that Format - Word Wrap is NOT checked!.
  5. Copy and paste entire contents of the file into your next message, properly formatted.


Finally, provide browstat information for each computer. You'll do this from a Command Window (or a command window in Windows Vista). Note that, as indicated in the article, you must download browstat (it's free, and small), as browstat.exe is not a normal component in Windows. Read the article, please.

  1. Type "browstat status >c:\browstat.txt" (less the "") into a command window (or a command window in Windows Vista). Only type the command into a command window - do not type Start - Run - "browstat status...".
  2. Do you have any Windows 9x (95, 98, ME) computers? If so, type "browstat listwfw >>c:\browstat.txt" into the command window (NOTE the ">>").
  3. Type "notepad c:\browstat.txt" (less the "") into the same command window.
  4. In Notepad, make sure that Format - Word Wrap is NOT checked!.
  5. Copy and paste entire contents of the file into your next message, properly formatted.

Did you just run browstat, and get good output (similar to what's shown in the article?). Ok, fine, continue and examine the output as instructed below. If you ran it, and got no response, or no output, or if a window opened and closed so quickly you couldn't read anything, please read my article on Using The Command Window. If you ran it, and got "invalid command", "'browstat' is not recognized as an internal or external command...", or similar, please read my article on Using The Path.

See The Browstat Utility from Microsoft, for information on downloading, installing, running, and interpreting logs from, browstat.

Both browstat, ipconfig, and net config produce a lot of output - and if you're unfamiliar with networks, it may look like gobbledegook. But all of it may be useful to the folks who want to help you, so be generous and precise. And please provide the information in text, don't make a picture attachment. Attachments are not appreciated in the forums where serious help is given, and some helpers won't be very courteous if you send attachments.

And, if you truly want serious and well thought answers for your problems, learn how to ask serious and well thought questions. Again, Help Us To Help You.

>> Top

What Is A NAT Router?

A router is a very specialised computer, that connects two or more separate networks, and directs network traffic from one network to the other as necessary.

A normal (infrastructure) router has just one simple task - to route traffic from one network to another, simply by knowing what networks are connected to each interface on the router. This requires you to know what networks are connected, and to create and input rules defining those networks.

A Network Address Translation, or NAT, router has multiple jobs.

  • DHCP Server (Assigns and passes network settings to computers on the LAN).
  • Firewall Functionality (Protects the computers on the LAN, from computers on the Internet).
  • Internet Client (Acts like a single computer to the Internet on the WAN).
  • Internet Gateway (Provides internet service to the computers on the LAN).
  • Network Address Translation.


Basic Setup
With a NAT router, you only have to make settings regarding one network - the WAN side (which connects to the internet), to get started. You set that up according to what service your ISP provides.
  • Fixed IP address.
  • Dynamic IP address.
  • Point to Point Over Ethernet, aka PPPoE.

And, you will need to setup the addresses of the DNS servers. Your ISP should provide you with those. They are essential.

The default settings on the LAN side (where all of your computers connect) should work OK to get you started. The DHCP server on the router, by default, provides all the necessary settings to each of your computers. Connecting each computer, one at a time, to a NAT router is relatively simple:
  • Set the computer to automatically get settings (DHCP client).
  • Restart the computer.


Assuming that all your computers are simply used for browsing, or similar client initiated internet activities (which is frequently the case), a NAT router needs no further configuration.

NAT Functionality
An infrastructure router has a relatively simple task - to simply pass packets from one computer to another. Computer A sends a request to Computer B. The router simply passes packets from Computer A (on router connection A) to Computer B (on router connection B). It's possible, but not certain, that the reply from Computer B to Computer A might return thru the same router.

A NAT router has a more complicated task:
  1. Opens a port when requested by a local computer, identifying the local and remote computers.
  2. Passes a series of packets thru that port to the remote computer.
  3. Waits for the reply from that remote computer.
  4. Identifies the port by the IP address of the remote computer.
  5. Passes the reply from the remote computer, thru that port, back to the local computer.


With the infrastructure router, both Computers A and B know of each others existence, as both computers use public (routed) ip addresses. With a NAT router, the remote computer actually sends its reply back to the router. The router performs Network Address Translation, and relays each packet back to the local computer.

The benefit here is that, even if the router does not have a firewall feature, the computers on the LAN are still protected. Only requested traffic, from known computers on the Internet, gets routed to a computer on the LAN. Any traffic originating from any unknown computer, or directed to an unrequested port, simply gets dropped. No original request = no delivery.

What A NAT Router Is Not
With all of that, let's get straight about what a NAT router is not. A NAT router, which may or may not provide firewall functionality between the WAN and the LAN, is not a firewall. And not all NAT routers provide firewall protection between the computers on a LAN. All computers connected to the LAN, on most NAT routers, are simply connected to a switch. Some WiFi NAT routers may have a feature called "Isolation Mode", which blocks all network traffic between all computers connected to the LAN.

To put it simply - a NAT router is not a firewall.

And there is a major difference in hardware too, between a NAT (Consumer grade) and Infrastructure (Business grade) router. Besides quality of design and manufacture, the design itself has a major difference.

A NAT router has 2 distinct sides to it - the WAN (where you connect the Internet service), and the LAN (where you connect all computers). The ports on the LAN are connected by a switch - there is no routing functionality. Routing is simply between the WAN port, and the switch.

With an Infrastructure router, all ports are labeled, and routed, identically. If you have 2 LAN segments, each connected to a router port, and a WAN segment connected to a third port, all traffic between any 2 of the 3 will be routed symmetrically.

Some NAT routers will, upon option, let you disable NAT. This may be called "Infrastructure" or "Router" mode. This will not give you a true Infrastructure router, as the ports connected to the LAN will still go through a switch. A NAT router will, at best, be the equivalent of a 2 port Infrastructure router. Very few Infrastructure routers contain only 2 ports.

Extended Setup
Although the default settings on a NAT router are very simple, there are plenty of additional settings to allow for specific needs of each individual local network. With many functions that a NAT router provides to its clients, in addition to simple web surfing, they can be quite complex to setup.

Many security experts advise changing all default settings that deal with the LAN settings of a NAT network. In case a NAT related exploit ("hacking" technique) ever becomes reality (and that will happen one day), the exploit will not be quite so easy. Specifically, there are certain default LAN settings which vary by router manufacturer, but can be improved upon by the owner of the router. For a Linksys router, for instance, the LAN defaults to 192.168.0/24, with gateway 192.168.0.1. And the DHCP server defaults to issuing addresses in the range 192.168.0.100 - 192.168.0.150. All of those settings can, and should, be changed.

Other settings which are advisable:
  • Change the administrative password. Use a non-trivial (non guessable) value. Change it regularly.
  • Disable remote (WAN) management. There is no need for anybody to make changes to the router except from a computer connected to the LAN (ie in front of the router itself).
  • Enable the security log. Review the log regularly, know what is normal, and take action when something abnormal happens.


Other configurations that you might need to make (not available on all routers):
  • DMZ. To bypass NAT functionality for individual computers on your LAN.
  • Isolation. Blocks all network traffic between all computers connected to the LAN. Provides shared Internet service, with no security risk, for WiFi clients, as in a WiFi Hotspot.
  • Packet Filter. Block specific application traffic in and out of the LAN.
  • Port Forwarding. To provide for Internet server applications.
  • Port Triggering. To allow for Internet server applications, with special needs that can't be met by Port Forwarding.
  • Stateful Packet Inspection. Complements packet filtering, and is another function provided by a full featured firewall.
  • UPnP. Similar to port triggering, but more versatile. Allows applications on your computer to control the router.
  • VPN Endpoint or Passthru. To allow for secured communications with remote networks.

All of these features may not be available on all NAT routers. Each feature requires memory, and processor time; both resources may be in short supply in a typical (inexpensive) NAT router. Some NAT routers may have these features, but disable them when excessive network traffic is experienced. When an excessive volume of network traffic is experienced, and the router can't keep up, there are only two possible actions which the router can take.
  • Fail closed. Stop filtering, simply pass traffic, unexamined.
  • Fail open. Drop traffic that exceeds a certain volume.

Obviously, neither possibility is desirable. Like any physical device, NAT routers are limited in feature set, by their components and design. When you're comparing NAT routers, compare carefully.

For additional configuration information, and endless hours of discussion about what I have summarised above, visit the Usenet discussion groups alt.computer.security, or comp.security.firewalls.

>> Top

The NT Browser (or Why can't I always see all of the computers on the LAN?)

When you use your computers, how do you know which servers are on the network, providing shared data for you to access? When you look in Network Neighborhood (aka My Network Places, or simply Network in Windows Vista), and see a list of servers (or don't), where does the list come from (or why are some servers or shares not always listed)? The list is provided by the browser subsystem, and any omissions from the list are the fault of the browsers (or problems related to the browsers).

When you ask for help with the browsers, many experts will tell you to turn the browsers off. If you turn the browser off on enough computers, the problems go away, and you can always see all computers from all other computers.

In any large office (enterprise domain) environment, you have dozens, if not hundreds of computers. You don't have to turn the browser service on or off there. How does that work, and why doesn't a Small Office / Home Office (SOHO) workgroup environment work the same way?


>> Top

Very Simple Network Terminology
A workgroup is similar to a very simple domain, in a limited context. In reality, though, there are an almost infinite number of differences between the two. Knowing the differences is a key to understanding how the browser works (or doesn't).

>> Top

So What Does The Browser Do?
You can't have every server on the network constantly advertising its presence to every client - that would create chaos. The browser subsystem tames the chaos. The servers are listed by the browser servers, and the browser servers ("browsers") provide the server list to the clients.

Just as having every server advertise to every client is bad, so would be having one server provide the server list to all of the clients. The official recommendation from Microsoft calls for 1 browser for every 32 computers in the domain (workgroup). If you have more than 32 computers, you have multiple backup browsers.

If you have more than one computer, you should have a browser. If you have more than two computers, you should have a backup browser, and a master browser. With just two computers, the backup and master browser might be the same computer.

The servers, and the backup browsers, have their activities coordinated by a master browser. The master browser maintains a count of client computers, and for every 32 clients, accepts the offer of one server, directing it to run as a backup browser.

The master browser receives all of the server advertisements, aggregates all of the advertisements into one master list, and distributes the list to each backup browser. The backup browsers distribute the browse list to the clients, which then have something to display in Network Neighborhood / My Network Places / Network (in Vista).

In a domain, the domain controller generally acts as the master browser. The domain controller is always online, and always accessible. There are major problems in a domain environment, if the domain controller isn't available. The domain controller functionality, and the browser functionality, both include failover mechanisms, so there will always be a domain controller, and a master browser, available if the server providing that functionality becomes unavailable for any reason.

In a domain that occupies multiple subnets, the domain controller also becomes the domain master browser, and makes Browsing Across Subnets possible.

>> Top

Why Does The Browser Work Better in a Domain?
There are many differences between a domain environment, and a workgroup environment.

In a domain, for instance:
  • You have a Domain Controller, which does nothing but validate (authenticate and authorise) access to the other servers.
  • If there are multiple subnets in the domain, the domain controller acts as a domain master browser, and aggregates browsing from all subnet master browsers.
  • The role of any computer, as a client or server, is very formal.
  • Servers generally run a server operating system.
  • Servers are traditionally fixed in location, and stay connected and online, constantly.
  • Clients typically only need to know (see) the presence of servers.
  • Clients typically don't become browsers, because there are usually at least 2 servers present on the domain, acting as browsers.
  • The configuration of a server is very carefully maintained, generally by a server administrator. The performance and stability of a server is carefully guarded.


The master browser role, and the browser role, are generally chosen for a computer running as the domain controller, and for a computer running a server operating system.

Contrast all that with your typical workgroup, where you have 2 or more computers, all sharing data with each other in a web of shares.
  • You have no Domain Controller. Access to any server is validated by local accounts installed, activated, and maintained on each client, and on each server.
  • With no domain master browser, if you have multiple subnets in the workgroup, you'll have master browsers that won't communicate.
  • The role of any computer, as a client or a server, is casual.
  • Most computers run a client operating system, though acting as servers.
  • Some computers, wirelessly or otherwise connected, may move around. Many computers are casually disconnected from the network, or turned off, at the whim of the owner.
  • All computers need to know (see) the presence of other computers in Network Neighborhood.
  • All computers become browsers, unless otherwise configured.
  • Many computers have software or settings changes made at the whim of the owner, which may hamper performance or stability, as a client or as a server.


The master browser will be one of the workgroup computers, and be subject to the treatment of a workgroup computer.

Regardless of all of the above considerations, there is expected to always be a master browser in any workgroup (domain). "Always" is a relative term, subject to the browsers checking for a master browser periodically, not every second.

Short of there being a domain controller in your workgroup (there won't be), or a computer running a server operating system (there may not be), the server chosen to be the master browser will probably be the server that's been up the longest (though not necessarily online, to the other computers, the longest).

>> Top

What's The Problem Then?
Anytime that a backup browser realises that there is no master browser present on the domain, the browser is authorised to hold an election to determine a new master browser.

What happens if any server loses contact with another? If a browser server loses contact with the master browser, it may elect itself a master browser. This gives you a workgroup with 2 master browsers, neither able to see the other. This is where many browser problems start.

Differences between operating system, and configurations, of the various servers, combined with changing the identity of the master browser, will make for an ever changing workgroup, as seen in Network Neighborhood. And complaints that "I can't always see all the computers in my workgroup" become natural (Here we get "always", and "all", again).

What happens if the master browser is rebooted? While it's being rebooted, a master browser election may be held, and when the server that was the master browser comes back up and online, it may find that it's no longer the master browser. Or it may not. The more servers online at any time, the more backup browsers to notice the absence of the master browser when it's rebooted.

Timing is a major issue here. In any domain (workgroup), as I said, there has to always be a master browser visible to any backup browser. Any time any backup browser can't contact the master browser, it assumes that there's a problem with the master browser, and elects a new master browser. The greater number of backup browsers that there are on the network, the greater the chance that one backup browser will realise the absence of the master browser, and start an election.

What if you, on your home workgroup, casually unplug the network cable on the master browser? Depending upon how long you leave it unplugged, the master browser may be replaced. If you simply plug the cable back in, you will have a workgroup with two master browsers. Some servers may still recognise the old master browser, others the new one.

What if you carry your laptop (networked using WiFi) away (out of radio range) from the router / WiFi Access point, and it loses network connectivity? If it's a backup browser, and it realises that contact with the master browser has been lost, it may elect itself master browser. When it reconnects to the network, the above situation may apply.

There are also challenges when you have computers running Windows 9x (95, 98, or ME) on the same network with computers running NT (NT, 2000, XP, Server 2003 / Vista). For more discussion about browser issues related to Windows 9x, see Windows 9x (95/98/ME) and the Browser.

The browser depends upon Server Message Blocks ("SMBs"), both from the server to the browser server, and from the browser server to the clients. System configurations, and personal firewalls, may affect the transport of SMBs. The restrictanonymous registry setting may prevent any server from being enumerated ("seen") by a browser. And a totally invisible server can also be caused by the Hidden parameter.

Any personal firewall, depending upon configuration, can block SMBs. Be sure that you haven't overlooked a firewall bundled with your antivirus protection, or your VPN. Make sure that the Windows Firewall service is running - see (KB889320): When you disable the Windows Firewall service..., for discussion about this problem, and a possible solution.

Here's where the difference in browser functionality, between a domain and a workgroup, becomes important. If you have a domain with an extra master browser, that master browser will eventually communicate with the domain master browser, and its browse list will become integrated with the domain browse list. With the extra master browser on the same subnet as the domain master browser, or on a different subnet, a domain with multiple browser segments will not be a major problem.

On the other hand, a workgroup with multiple browser segments will leave you with two master browsers that won't be able to see each other. Master browsers communicate only with their known backup browsers, with the domain master browser, and with master browsers for other domains or workgroups. They can't communicate with other master browsers for the same workgroup, even if on the same physical segment.

With no domain master browser, the two browser segments will remain separate. Some servers will report their presence to one master browser, and others to another. Some clients will get their browse list from one browser, and others from another. And you will have different browse lists (Network Neighborhood displays) all over the workgroup.

>> Top

How Can I Prevent Browser Problems?
Please start with a clean (uncluttered) protocol stack. The more protocols there are, to transport the SMBs, the more chaotic the browser service will be. With a normal LAN, Internet Protocol (with or without NetBT enabled) is all that's needed.

In a workgroup, if you can't control the chaotic environment, which is unlikely, the best thing to do is to restrict the number of browsers on the network. By doing that, you lessen the possibility of master browser changes and conflicts. So the advice given is generally to use one (or two, with the second being the backup) browsers, and turn the service off on all others.

To stop the Windows 9x Browse Master:
  • From Control Panel - Network, double click on "File and printer sharing for Microsoft Networks".
  • In "File and printer sharing for Microsoft Networks Properties", change the Value for Browse Master to Disabled.
  • Hit OK, and restart the system.


To stop the Browser on a Windows NT/2000/XP system, Stop then Disable the Computer Browser service, using the Services Wizard, or the Services Controller CLI. Similarly, if you wish the browser to run on any computer, Start then Enable the service on that computer.

Any time you change the browser setup on your LAN, you may have to wait for up 51 minutes, before all computers are synchronised. If this latency period is unacceptable, you may restart each computer. For maximum reliability, power all computers off; when all computers are off, power each one back on again, starting with the one which you want to serve as the master browser.

Of course, even with just two browsers on the LAN, you could (as noted above) end up with a browser conflict. And if both browsers should be offline, or separated from the rest of the LAN, you will have no browser service in the rest of the LAN. So reducing your browser population to two is not a cure all, nor is it guaranteed to produce success all of the time.

You can at least identify any browser related problems, using Microsoft's Browstat utility, my troubleshooting guide, Irregularities In Workgroup Visibility, and my brief tutorial, The NT Browser and Windows Networking.

For more information about the browser subsystem, which is a very intricate component of Windows, you might want to read Microsoft's articles

>> Top

Summary Rules for Dealing With the Browser
  1. Diagnose the problem before making changes to the browser infrastructure. As I said, the complaint "I can't always see all of the computers from every computer" is a good symptom of a browser conflict. Lack of "always" or "all" in the complaint may indicate a different cause. Don't go changing the browser setup without having some chance of producing results.
  2. Browstat, which only works on Windows NT systems, is a good diagnostic tool, when only computers running Windows NT / 2000 / 2003 / XP / Vista are involved.
  3. It is generally best to run the browser service on every wired server on the LAN, and let the browser subsystem elect a master browser as necessary.
  4. If you have a small LAN with no computers running a server OS, all servers are potential master browsers. If you take any server offline, and it is powered up, you need to power it off before reconnecting it (or at least restart it while reconnecting it). Or be prepared to diagnose browser conflicts.
  5. If you have a small LAN with no computers running a server OS, and any of the servers are wirelessly connected, disable the browser service on all wirelessly connected servers. Or be prepared to diagnose browser conflicts.

The NT Browser does its job pretty well, when properly designed and maintained. Use common sense, and the above rules, and you will have a much more controlled browser infrastructure, and a more reliable Network / My Network Places / Network Neighbourhood display.

>> Top