Browsing Across Subnets

One of the causes of browser problems, and the constant complaint "I can't always see all of my computers in My Network Places!", is a backup browser server becoming separated from the master browser. As I stated in my main Browser article, The NT Browser...


Anytime that a backup browser realises that there is no master browser present on the domain, the browser is authorised to hold an election to determine a new master browser.

This behaviour is for 2 reasons.

  1. There must be a master browser available at all times, for browsing to work.
  2. There must be a master browser available on each subnet, for browsing to work.

Why is this relevant? It's because browser relationships, in general, do not pass from subnet to subnet. Browser communications, from a server to a backup or master browser, are by broadcasted datagrams. Broadcasted datagrams are sent to all computers on a subnet, but nowhere else. Routers drop broadcasted datagrams, so server advertisements, which are what the master browser depends upon to know that a server exists, stay on each subnet.

The master browser on the subnet assembles all of the server advertisements into the browse list for the subnet. If a domain is segmented, by either multiple subnets or just having multiple master browsers, it is the job of the domain master browser to collect the browse list from each segment master browser, aggregate the lists, and pass the aggregated list back to each segment master browser.

Here is one instance where a workgroup will not perform as well as a domain. If a workgroup is segmented, there will be no domain (workgroup) master browser, and no ability for servers on one segment to be seen from another segment. Segmented workgroups simply can't be browsed across segment boundaries.

Do you maybe have two (or more) routers, but would prefer to have one subnet? If so, then read about File Sharing On A LAN With Two Routers.

Re Install Your Network Hardware

Sometimes, even after repairing the network connection, repairing the LSP / Winsock stack, and / or re setting / re installing the network protocols, your problems continue. The next step is to fix a problem which may be in the bindings between the protocols and the network hardware.

First, always check with the hardware vendor, and find out if there's any driver updates available. Your problem may be something just resolved by the vendor, so download and install any driver updates, from the vendor.

If driver updates aren't available, or if installing them didn't fix the problem, then it's time to re install the hardware. Make sure that you have a good copy of the drivers, in an available location, before starting this procedure. If this is your only computer, back up any network resources, maybe print key articles in this blog, before taking your computer offline.


  1. Un install the drivers for the network hardware.
  2. Restart the computer, with the new drivers easily available.

    • Let the system discover the hardware again, or
    • Restart Device Manager yourself, and re install the drivers.

  3. Restart the computer once more.


>> Top

Un Install Security Products Carefully

If you decide to un install any personal firewall or security product, please be aware that many products may create components in the operating system itself, that are not easily removed by a simple un install wizard. Symantec and Zone Labs products (Norton and ZoneAlarm, respectively) are well known for this. If you have any antivirus or personal firewall product, and wish to un install it as part of a diagnostic procedure, please include these steps in your procedure:


  1. Research un install procedures with the vendor of the product in question.
  2. Enable firewall before un installing. Do not un install a firewall while it's disabled.
  3. Carefully follow all instructions from the vendor.
  4. Check for LSP / Winsock corruption after un installing, if any more problems are seen.

Setting Up A Domain Or A Workgroup? Plan For The Future

If you have just one computer, you have the beginnings of a network. With two computers, you definitely have a network. With three computers, you have a workgroup. Beyond that? Consider the benefits of a domain.

Look at the members (people) in your workgroup. Remember that the purpose of networking computers is to share resources (data and / or printers). Do you have a group of people who trust each other, totally, with all shared resources? If so, then you can setup an open workgroup, with no reservations. And you can, generally, use Guest authentication.

If you can't trust everybody with all shared resources, you will have to setup non-Guest authentication (who is this person?) and authorisation (should this person access this resource?). Without a domain to provide authentication, you have to setup an account for each person on both one or more clients, and one or more servers. With a domain, it's simply a matter of adding one more domain account.

Account and password maintenance, in a workgroup environment, can be a real experience.


  • You have to create an account, with an identical password, on each client and on each server.
  • You have to change a password on each client, and each server, simultaneously. The account owner has to be logged off on each client, while you do this, or face password conflicts.
  • When somebody leaves the group, you have to delete their account on each client and server.

With a domain, again just add an account, change the password, or delete the domain account.

Will you possibly have people sharing each others computer from time to time? Will you have people accessing shared resources on more than one computer? Will you have group turnover, where one person leaves the group, and is replaced by somebody else? Will you have staff sharing each others account / password (you know folks shouldn't share passwords, but eventually they will).

For that matter, how does a workgroup member change his / her password, on the servers? Surely you wouldn't want each person walking up to the server, and logging themself in, locally, for a simple password change?

And how about the need for one person to have unrestricted access to each computer? Any LAN of any size needs an administrator. The administrator account has to be on each computer. Proper security procedures demand regular changing of the administrator password - but how do you do that on each computer?

Besides the people related issues, how about the network layout? Is your workgroup likely to span multiple subnets? If so, you will need a domain. Be aware of issues involved with Browsing Across Multiple Subnets.

There is one show stopper here. If you have computers running XP Home, you might as well stick with the workgroup. Computers running XP Home can't join a domain.

Now, setting up a domain shouldn't be done casually. The initial expense, and setup, of a domain, is significant. Minimally, you need:

  • A dedicated server (not shared as somebody's desktop computer).
  • A server Operating System.
  • Server administration techniques. Since the server is depended upon by each person, it is proportionally more important to keep it secure and stable.


Setting up Server 2003, and a domain, is a lot more work than setting up a single Windows XP host. Maintaining a server is a little more work than maintaining a single personal computer. But, as soon as you see how simple it is to add or update a new person in a domain, compared to adding or updating multiple clients and servers in a workgroup, you'll see that it's worth the initial and ongoing complications.

In short, a workgroup setup makes sense for a group that is:

  • Trusting of each person.
  • Small.
  • Doesn't share multiple resources.
  • Static.
  • Mostly computers running XP Home.


My personal experience? If you have more than 4 or 5 computers or people, you will, eventually, end up with one or more problems with the limitations listed above. You can maybe work around each of those limits procedurally; and if you have enough time and patience (by the staff, and whoever maintains the LAN), none of them will matter too much. If you need to move somebody from one computer to another, you can use the File and Settings Transfer Wizard to make the process almost scriptable.

But, if you have ever administered a workgroup of any size, with any staff turnover, secreting of data, and / or sharing of computers, you will know that a domain, with a simple procedure to setup and maintain each account, makes more sense in the long run.

If You Ever Feel Like Experimenting


  1. Setup 2 computers, a client and a server. Use NBT and TCP/IP, initially, on both.
  2. Get file sharing working (opening files from the client) using NBT only, no NetBEUI.
  3. Install Zone Alarm on the server, and configure it so the client can access shared files on the server, and can ping the server.
  4. Engage the ZA lock, so the client can NOT access files on the server, nor ping the server.
  5. Unbind File Sharing from NBT on the server, and install NetBEUI. Leave TCP/IP working, but NBT disabled.
  6. See if the client can ping the server.
  7. See if the client can access files on the server.
  8. Disengage the ZA lock on the server.
  9. See if the client can ping the server.
  10. Change the ip address of the server to a different subnet.
  11. See if the client can ping the server.
  12. See if the client can access files on the server.