Troubleshooting Internet Service Problems


Next to "I can't access files on Computer B from Computer A", the complaint "My Internet service doesn't work" is almost as common. There's good news here, and there's bad news. The good news? A problem with your internet service, since it only depends upon TCP/IP, will be a lot easier for you to diagnose. The bad news? Since it depends upon something outside your house, and in some cases outside your city or state, many problems will be ones that you can't fix - you have to get your ISP involved.

This article, like Troubleshooting Network Neighborhood Problems, is structured like the OSI 7-Layer Network Model. If you have multiple problems with your network, you have to diagnose and fix the lower level problems first. If you don't, how can you diagnose the higher level problems?

Now before you start troubleshooting, note that you will enjoy it more, and frequently will be more successful, when you work on a properly designed and setup network. Once you've reviewed that, I recommend that you tackle the task at hand in this order.


So what are the differences between this article, and Troubleshooting Network Neighborhood Problems? Well, there is good new, and bad news. The good news - less protocols to deal with. The bad news - more distance and juridictional issues.

With Windows Networking, if there's a problem, it's yours (or maybe the vendor of the hardware that you own, if the problem involves hardware failure on a component under warranty). With Internet Service, the responsible party could be:

  1. You.
  2. Your ISP.
  3. If your ISP leases the connection between you and their offices, the Local Exchange Carrier (your local phone service if you have DSL) might be involved.
  4. The vendor, if the problem involves hardware failure on a component under warranty.
  5. Any number of individual network and server operators. Except in special cases, you will never know these parties, let alone contact them with any chance of getting useful results.

Physical Network Problems
Your problem could be caused by a simple physical network problem.

Of course, the card, cable, port, any other network component, could be one owned by your ISP, or by the LEC, if not your ISP. Or by any of the other parties described above.

Try and diagnose physical network problems from the bottom up.

>>Top

Logical Network Problems

Did you just connect a new router, or a different computer, to your broadband modem? You can't do that casually - you may have to reset your Internet service, to register a different network device with the service.

Given a little preparation (have the correct device drivers available), you should be able to re install the drivers for the network adapter without too much trouble. This is usually one of the last things tried, but can be one of the easiest.

TCP/IP is the language of the Internet, and proper TCP/IP settings are essential. If you're unfamiliar with IP configurations and networking, ask for help.

Also, a corrupt LSP / Winsock layer can have an effect any TCP/IP connectivity. If you've just removed adware / spyware, this is always a possibility.

Did you already run the Network Setup Wizard? You have to read the wizard selections carefully.

  • If your computers all connect to a NAT router (My absolute recommendation), select Option 2 for all computers.
  • If you have a host sharing Internet service to the other computers, select Option 1 for the host, and Option 2 for the clients.


Finally, if you have a problem accessing only some websites, but not others, or if this problem seems to come and go, you may have an MTU setting problem.

>>Top

Address Resolution Problems
With Windows Networking, you have the process of Address Resolution (Local Computer Name to Address). With Internet service, you have the process of Address Resolution (Distant Computer Name to Address). Address resolution is essential.

In addition to preventing an LSP / Winsock problem from interfering with address resolution, you need to ensure that you have access to an active Domain Name System (DNS) server for address resolution. You can have a DNS server for resolving addresses on your LAN, if you wish, but your Internet access will depend upon another DNS server somewhere outside your LAN.

If your Windows XP computer is part of a domain, make sure that the domain is setup properly to provide both internal addresses and external (Internet) addresses.

The DNS infrastructure is pretty transparent to us, when it works, but sometimes it doesn't work. Right now, the bad guys are exploring ways to use DNS to get us to surf to their malicious websites. There have actually been 3 attacks, in the early months of 2005, where folks have surfed - without their intention or permission - to a malcious website - and in some cases, have downloaded software that they didn't want, nor realise. This practice is called pharming, and it is an ongoing possibility for problems.

Besides DNS resolution, you may have your Hosts file to consider.
>>Top

Security Problems
You need a personal firewall on each computer, but your personal firewall has to be properly setup and used. A misconfigured or misbehaving personal firewall, on your computer, can block access to the Internet. Your personal firewall may need setup, to trust the host - either an ICS server, or a router - providing Internet service to your computer.

If you disable your personal firewall, and the problems stop, then you at least know where to start working. But if the problems don't stop, don't assume that the firewall is not the problem. Many personal firewalls do not react properly to being disabled, and will continue to cause problems after being disabled. And look for a previously overlooked firewall, such as one bundled with your antivirus protection.

Besides a personal firewall causing problems, there are security features in your browser that can cause problems, if misconfigured.

>>Top

Network Components and Services
This section, as I hinted above, is relatively simple. Your computer requires TCP/IP. You must have "Internet Protocol (TCP/IP)", in the network items list in Local Area Connection - Properties.

If your computer is going to be supplying Internet service to other computers (using ICS), you'll need ICS running. Check that the service supplying ICS, under one of two possible names, is Started and Automatic.

  • For XP SP2, check the Windows Firewall / Internet Connection Sharing (ICS) service.
  • For XP pre-SP2, check the Internet Connection Firewall / Internet Connection Sharing (ICS) service.


If your computer is going to be supplying Internet service to other computers (using ICS), and ICS isn't running, rerun the Network Setup Wizard, and choose Option #1, This computer connects directly to the Internet. If there's a problem with the NSW, or if running the NSW doesn't produce acceptable results, check the Event Viewer for diagnostic messages.

>>Top

Virtual Private Networking
Internet usage, in general, involves casual connectivity. Any client, within reason, is encouraged to connect to any server. This is many to many connections.

What if you have two offices, located at distance from each other, and want to use the Internet to provide communications between the two? This would be a point to point connection, formally setup between the two offices. A Virtual Private Network is a pre-configured, secure communications tunnel, through an otherwise insecure network (aka the Internet), between two locations.

Setting up a VPN isn't done casually, or between changing locations; a VPN has to be deliberately designed and setup, from both ends.

>>Top

Asking For Help
If you're reading this article because you need help, please start by reading my Privacy Statement.

Spend a few minutes reading about How To Solve Network Problems.

Provide some background information about the problem, and about your network in general.

Ensure that each computer is Physically, and Logically, connected to your network, to your best ability.

>>Top

Diagnose the problem, on each computer involved, using my test outlined in Identifying A DNS Problem In Your Internet Service. Note, and report, the results of the tests.

Localise the problem (Where is it happening?), and identify its time scope (When is it happening?). If the problem is NOT in your LAN, and you have to go to your ISP for support, having solid time of day / day of week documentation could be very helpful.

How long has the problem been happening? Contrast that with how long have you had this computer setup as it is right now (And how was it setup previously?). And what was changed (hardware / software) just before the problem started?

I use PingPlotter (free) to document all my network issues, and have it running on at least one computer on my LAN, on a 24 x 365 basis. Set PingPlotter up regularly pinging a server outside your LAN, say your ISPs DNS server. If you see the trace stop somewhere when your problem is happening, where does it stop? Does it show loss of contact with your router, or with the ISPs DNS server? Make a file, if appropriate, and send it to the tech support at your ISP. A picture (or PingPlotter graph in this case) could be worth a thousand words.

>>Top

Finally, provide ipconfig information for each computer. You'll do this from a Command Window.

  1. Type "ipconfig /all >c:\ipconfig.txt" (less the "") into a command window (or a command window in Windows Vista). Note the spaces in the command, and note the difference between the "/" and "\" characters! Only type the command into a command window - do not type Start - Run - "ipconfig /all".
  2. Type "notepad c:\ipconfig.txt" (again, less the "") into the same command window.
  3. In Notepad, make sure that Format - Word Wrap is NOT checked!.
  4. Copy (Ctrl-A Ctrl-C) from the Notepad window, and paste (Ctrl-V) the entire contents of the ipconfig log, into your next posted message, properly formatted.
  5. Identify operating system (by name, version, and Service Pack level) with each ipconfig listing.
  6. Please don't munge or omit any detail, as there is nothing provided by ipconfig that could provide help, to any bad guy, in identifying an entry point to your LAN. The good guys, on the other hand, may need any or all of the details, to accurately diagnose your problem. Help Us To Help You.

Did you just run ipconfig, and get good output (similar to what's described in the ipconfig article?). Ok, fine, continue and examine the output as instructed below. If you ran it, and got no response, or no output, or if a window opened and closed so quickly you couldn't read anything, please read my article on Using The Command Window.

With IPConfig logs in hand, you may take a look at Reading IPConfig and Diagnosing Network Problems, if you're interested.

>>Top

Problems With The LSP / Winsock Layer In Your Network

Microsoft Windows, by default, uses Internet Protocol (IP) for all communications, whether locally (LAN) or remotely (WAN), though it will use other transports for LAN traffic, if you desire. The connection between the applications (programs that you run) on your computer, and the wires, whether physical (Ethernet) or logical (WiFi), is thru a series of programs, arranged in layers.

The Layered Service Provider (LSP) / Windows Sockets (Winsock) portion of the network stack is a key component in all network traffic, LAN and WAN. When it stops working, we say that it's "corrupted". The symptoms of corruption can be unpredictable. By "unpredictable", I've experienced / seen:

  • Connectivity thru some services, but not all.
    • Low level services like ping may work, but email won't work.
    • Email might work, but not the browser.
    • If you have multiple browsers, maybe Firefox will work but Internet Explorer won't.
  • Connectivity to local addresses, but nothing on the Internet.
  • Connectivity to some computers on the LAN, but not others.
  • Slow connectivity all around.
  • Strange diagnoses / messages, mentioning mysterious objects like handles, semaphores, or sockets.
  • Strange name / address resolution results (garbled names).

There are multiple possible solutions to an LSP / Winsock problem, and not one of them have been found to be consistently more effective than the others. Some of them may fix some problems, but find additional problems when run a second time.

Try each solution, if applicable to your system, one after the other, until your problem is resolved. If any of these tools recommend changes, and / or make any changes for you, yet the problems are not fully resolved, continue with the other tools. Then, repeat the entire list.

Each time any changes are made, repeat the diagnosis made previously. Verify that the problem is still with you.

If you do have an LSP / Winsock problem, ignoring it and investigating something easier will not make the problem go away. Be patient, and persistent.
  1. Try the easiest solution first. Restart the computer, if you haven't yet done this.
  2. Check for a DNS or MTU problem, which can imitate, or mask, a corrupt LSP / Winsock.
  3. LSP-Fix.
  4. WinsockFix.
  5. Winsock2 Fix (Windows 98 / ME only).
  6. WinSock XP Fix (Windows XP only).
  7. For Windows Vista or XP only, use Windows native procedures. This will vary according to Service Pack level and Version.

    • To fix a corrupted LSP / Winsock in Windows XP pre-SP2:
      1. Backup and delete the following registry keys:
        [HKEY_LOCAL_MACHINE\ System\ CurrentControlSet\ Services\ Winsock]
        [HKEY_LOCAL_MACHINE\ System\ CurrentControlSet\ Services\ Winsock2]
      2. Reboot.
      3. Open the network connections folder, right click your network connection, and click Properties.
      4. Click Install | Protocol | Add.
      5. Click "Have Disk...", type "\windows\inf" in the box, and click OK.
      6. Click "Internet Protocol (TCP/IP)", then click OK.
      7. Reboot.
    • To fix a corrupted LSP / Winsock in XP SP2:
      1. Open a Command Window.
      2. Type "netsh winsock reset catalog" into the command window.
      3. Reboot.
    • To fix a corrupted LSP / Winsock in Vista:
      1. Open a Vista Command Window.
      2. Type "netsh winsock reset" into the window, and press Enter.
      3. Reboot.

  8. Try a registry based rebuild, from Bob Cerelli, One Computer Guy. First, remove the corrupted registry keys. Next, apply the correct, standard registry keys. This will vary by operating system version.
    1. Windows 98.
    2. Windows ME.
    3. Windows 2000.
    4. Windows XP.
    Note no registry based fix is available for Windows Vista, as of yet.
  9. An additional possibility is corruption in the TCP/IP components. Although LSP / Winsock provides part of the TCP/IP functionality, it is not solely a part of TCP/IP (it can include IPX/SPX and NetBEUI components). The IP stack is separate from LSP / Winsock, and sometimes you will need to (KB299357): reset TCP/IP in Windows Vista or XP, or reload TCP/IP in pre-Windows XP.
  10. Next, Re Install Your Network Hardware - first the drivers, then the physical device (if possible).
  11. Since system files may have been deleted or altered, try a repair install of Windows.


NOTE: LSPFix, and its peers, identifies and removes problems in the LSP / Winsock stack. If LSPFix, or one of its peers, identifies a stack entry as problematic, you have to trust it, and let it fix the problem. If your network is not working (which, I presume, is why you're here), give it a shot. Create a System Restore checkpoint, if you wish (and take a second checkpoint later, if the problem is fixed).

NOTE: If you're still unsure whether you can trust my advice, and put your computer at the mercy of some free software that you just downloaded, this is good. Be skeptical - that's the beneficial side of paranoia. Next, read Download Software Selectively. Finally, spend some time researching, as advised.

As a last resort, try and diagnose the problem, by enumerating the contents of the LSP. You might identify an unknown problem, and more than you might benefit from your efforts. LSP enumeration will vary, according to what operating system is running on your computer.

For more information about LSP / Winsock problems, see the Microsoft articles


>> Top

Windows 9x (95/98/ME) and the Browser

When you have computers running Windows 9x (95, 98, or ME) on the same network with computers running Windows NT (NT, 2000, XP, Server 2003), you should expect browser problems (such as computers not visible, or "access denied", when trying to use Network Neighborhood). The rules for detecting the absence of the master browser ("Browse Master" in Windows 9x) vary between the 2 platforms. This leads to the problems when a working LAN of Windows 9x computers has a Windows XP computer added.

If you don't want to have browser conflicts, you'll need to disable the browser on each of either the Windows 9x, or the Windows NT, computers. Choose intelligently in which group you wish to disable the browser. If you have just 1 or 2 Windows NT computers, and a larger number of Windows 9x computers, you might elect to disable the browser on the Windows NT computers. Conversely, if you have a lot of Windows NT computers, and a couple Windows 9x computers, disabling the Browse Master on the Windows 9x computers would make more sense.

To stop the Windows 9x Browse Master:


  • From Control Panel - Network, double click on "File and printer sharing for Microsoft Networks".
  • In "File and printer sharing for Microsoft Networks Properties", change the Value for Browse Master to Disabled.
  • Hit OK, and restart the system.

Alternatively, you can edit the Windows Registry. Change value [HKLM\ System\ CurrentControlSet\ Services\ Browser\ Parameters\ IsDomainMaster] to False. Then restart the system.

To stop the Browser on a Windows NT/2000/XP system, simply set the Computer Browser service to Stopped and Disabled.

Any time you change the browser setup on your LAN, you may have to wait for up 51 minutes, before all computers are synchronised. If this latency period is unacceptable, you may restart each computer. For maximum reliability, power all computers off; when all computers are off, power each one back on again, starting with the one which you want to serve as the master browser.

Having done this, you may need to deal with Network Neighborhood problems in general, so continue by reading Irregularities In Workgroup Visibility.

If you wish to diagnose this issue, and confirm that it's a problem first, you can run Browstat from any of the Windows NT (NT, 2000, XP, 2003) computers. Browstat won't run on Windows 9x (95, 98, ME) computers, but if you run browstat twice on each computer running NT, you can compensate for that. Run:

browstat status
browstat listwfw workgroup
where workgroup is the name of the workgroup of which this computer is a member, taken from the "browstat status" log.

For more information about Windows 9x browser issues, read the Microsoft white paper Browsing and Windows 95 Networking, or this Microsoft article (KB246489): Frequent Browser Elections When Windows 95 and Windows NT 4.0 Configured in Workgroup.

For more information about the browser in general, read The NT Browser (or Why can't I always see all of the computers on the LAN?).

And for more issues relevant to the various operating systems, see Older Operating Systems - Windows 98, Windows ME, Windows NT

>> Top

Using CDiag Without Assistance


  1. Visually identify the CDiag Base Code (everything INSIDE the "#####" lines). Please DO NOT include ANY portion of the "#####" lines.

  2. Open Notepad.

  3. Highlight then Copy the code (Ctrl-C), precisely as it is presented, and Paste (Ctrl-V) into Notepad.

  4. Examine the contents of Notepad. Is the text, as copied, readable (similar in format to the Base Code)? It won't run well, if it's not easily readable.

  5. If the text is not easily read, then:
    • Stretch the sides of the Notepad window, so it becomes wider. If this improves readability, then continue with Step 6.
    • Close Notepad, as is (do not bother to save anything).
    • Open Notepad, again.
    • Under Format, change the setting for Word Wrap. If it is unchecked, check it. If checked, uncheck it.
    • Return to Step 3.

  6. Add the details for your LAN, giving the CDiag Assembled Code. Here's an example of what you might have, for a 2 computer LAN, with a NAT router. Details added are in bold type.

    set FullTarget1=PChuck1 192.168.1.50
    set FullTarget2=PChuck2 192.168.1.51
    set FullTarget3=
    set FullTarget4=
    set FullTargets=%FullTarget1% %FullTarget2% %FullTarget3% %FullTarget4%
    set FullTargets=%FullTargets% 127.0.0.1
    set PingTargets=www.yahoo.com 66.94.230.32 192.168.1.1
    Set Version=V1.34

    Note that each target is specified on a separate line (FullTarget1, FullTarget2, ...), and each is specified by Name, followed by IP address. Each target test includes 4 steps:
    1. Ping target by name.
    2. Net View target by name.
    3. Ping target by IP address.
    4. Net View target by IP address.
    Note, too, that each computer targets itself with each set of tests. This is intentional. Knowing, as a baseline, that each computer is accessible to itself, is essential.

  7. Save the CDiag Assembled Code as "cdiag.cmd", as type "All Files", into the root folder "C:\", onto each computer with an NT based OS (NT / 2000 / 2003 / XP) in your LAN. This is the part where I can't help - you have to get the Assembled Code to each computer somehow. If file sharing worked, you could copy it across the LAN, but of course, you probably wouldn't need CDiag then.

  8. Run the Assembled Code on each computer with an NT based OS (NT / 2000 / 2003 / XP / Vista). Don't waste yours or my time, running it under Windows 9x (95, 98, ME).

    • Start - Run - "c:\cdiag".
    • Wait patiently.
    • When Notepad opens up displaying the CDiag Log (c:\cdiag.txt), first check Format and ensure that Word Wrap is NOT checked! Then, print it, or set it aside, for interpretation.

  9. Aggregate all CDiag logs, then interpret the complete result.

Dealing With Pop-Ups

There are at least three varieties of pop-ups, and the solutions vary accordingly.



After you finish with this episode of malware / unwanted network traffic, improve your chances for the future.

Messenger Service Pop-Ups

This will be a text only message, and will only hit you when you're online. A Messenger Service pop-up can't contain a clickable link. The window will be titled "Messenger Service".

This type of spam has become quite common over the past year or so, and unintentionally serves as a valid security alert. It demonstrates that you haven't been taking sufficient precautions while connected to the Internet. Your data probably hasn't been compromised by these specific advertisements, but if you're open to this exploit, you most definitely open to other threats, such as the Blaster Worm that still haunts the Internet. Install and use a decent, properly configured firewall.

Messenger Service of Windows
Messenger Service Window That Contains an Internet Advertisement Appears
Stopping Advertisements with Messenger Service Titles

If you're using AOL, you'll either need to find a 3rd party firewall that is compatible with AOL, or switch to a real ISP that is compatible with the real Internet. This is because AOL is an on-line content provider that ignores international networking standards in favor of its own proprietary products, and has deliberately made its connection software incompatible with both WinXP's built-in firewall and WinXP's Internet Connection Sharing feature. AOL's proprietary connection applet is deliberately designed to preclude your setting/adjusting any of its properties, to include enabling/disabling WinXP's ICF and ICS.

Whichever firewall you decide upon, be sure to ensure UDP ports 135, 137, and 138 and TCP ports 135, 139, and 445 are all blocked from Internet access. You may also disable Inbound NetBIOS (NetBIOS over TCP/IP). You'll have to follow the instructions from firewall's manufacturer for the specific steps.

Please make sure that you only block the above ports from Internet traffic. If you have a LAN, and are using Windows Networking, you do not want to block those ports between your computers. Only block those ports between your computers and the Internet. Read the firewall / router manual.

You can test your firewall at:

Gibson Research (ShieldsUp!)
SecurityMetrics
Sygate Security Scan
Symantec Security Check

Be especially wary of people who advise you to do nothing more than disable the messenger service. Disabling the messenger service, by itself, is a "head in the sand" approach to computer security, similar to Security by Obscurity. The real problem is not the messenger service pop-ups; they're actually providing a useful, if annoying, service by acting as a security alert.


Regular Browser Based Pop-Ups

This will be an HTML message, and will only hit you when you're online. A browser based popup will probably contain clickable links. The window title will vary.

There are many ways of dealing with annoying, but not illegal, advertising pop-ups. Here are two.
Get the free Google Toolbar. Hosts file blocking works on this problem also.
Blocking Ads, Parasites, and Hijackers with a Hosts File.


Adware / Spyware Pop-Ups

This will be an HTML message, and can hit you when you're online, or offline. An adware based popup will probably contain clickable links. The window title will vary.

Please see Dealing With Malware (Adware / Spyware) to continue.