| Author |
Message |
Richard Fagen
Guest
|
Posted:
Thu Jan 20, 2005 11:07 pm Post subject:
dyndns.org question |
|
|
Hi Everyone,
I've been using DNS2GO.COM for a few clients but lately, I started
having VPN/RDP problems. People here suggested DynDNS.org instead.
I registered and downloaded a client (Direct Update 3.6.3) that works
perfectly with my home/office PC but doesn't work with SBS 2000. I
think it is an ISA or router issue.
The server has two NICs (internal 192.168.16.2, external 192.168.123.2).
I have a router (192.168.123.254) between the ext. NIC and the DSL modem.
Is there something I have to do to the Direct Update client or ISA
server to get the current dynamic address in the client software? Is
there a proxy setting or port I must open?
Thanks.
Richard Fagen |
|
| Back to top |
|
 |
Javier Gomez [SBS MVP]
Guest
|
Posted:
Fri Jan 21, 2005 12:01 am Post subject:
Re: dyndns.org question |
|
|
I'm not sure how changing Dynamic DNS provider is going to help you (unless
DNS2GO is not updating)... but the problem with DirectUpdate is most likely
a firewall thingy. Are you using ISA? Check the logs... I believe you need
to open a packet filter to port 80 (outbound), but I frankly don't remember.
Cheers,
--
Javier [SBS MVP]
www.msmvps.com/javier
<< SBS ROCKS!!! >>
"Richard Fagen" <no_spam@my_isp.com> wrote in message
news:O6YKLKx$EHA.2016@TK2MSFTNGP15.phx.gbl...
| Quote: | Hi Everyone,
I've been using DNS2GO.COM for a few clients but lately, I started having
VPN/RDP problems. People here suggested DynDNS.org instead.
I registered and downloaded a client (Direct Update 3.6.3) that works
perfectly with my home/office PC but doesn't work with SBS 2000. I think
it is an ISA or router issue.
The server has two NICs (internal 192.168.16.2, external 192.168.123.2). I
have a router (192.168.123.254) between the ext. NIC and the DSL modem.
Is there something I have to do to the Direct Update client or ISA server
to get the current dynamic address in the client software? Is there a
proxy setting or port I must open?
Thanks.
Richard Fagen |
|
|
| Back to top |
|
 |
Richard Fagen
Guest
|
Posted:
Fri Jan 21, 2005 12:53 am Post subject:
Re: dyndns.org question |
|
|
Hi Javier,
DNS2GO does work, but lately (sometimes after installing XP SP2), while
I can make the VPN, WINS doesn't work unless I disable the client's
Windows XP Firewall. This means RDP users must reference their PCs via
IP number (that changes) instead of the usually station's name.
For clients without DNS2GO, WINS works and I don't have to disable
anything. I suspect something changed with XP and/or DNS2GO. In any
case, I'd like to try DYNDNS.ORG instead to see it is makes a difference.
I agree with the 'firewall thingy' idea. Yes, I am using ISA. The
help says...
"Then, make sure that no firewall application (like ZoneAlarm) is
blocking TCP connection on port 40019 (default port)."
I opened this port in the router's setup. (strange, I forgot to open
the port in my home router, but it still worked) I'm not sure if I have
to do anything in ISA.
For other program (Mozilla), I already created entries to allow IP
traffic. I don't fully understand ISA and get confused between "Access
Policy" entries for "IP Packet Fileters" and "Protocol Rules". Do I
need to do anything for
Thanks
Richard
Javier Gomez [SBS MVP] wrote:
| Quote: | I'm not sure how changing Dynamic DNS provider is going to help you (unless
DNS2GO is not updating)... but the problem with DirectUpdate is most likely
a firewall thingy. Are you using ISA? Check the logs... I believe you need
to open a packet filter to port 80 (outbound), but I frankly don't remember.
Cheers,
|
|
|
| Back to top |
|
 |
Javier Gomez [SBS MVP]
Guest
|
Posted:
Fri Jan 21, 2005 1:17 am Post subject:
Re: dyndns.org question |
|
|
| Quote: | "Then, make sure that no firewall application (like ZoneAlarm) is blocking
TCP connection on port 40019 (default port)."
I opened this port in the router's setup. (strange, I forgot to open the
port in my home router, but it still worked).
|
You probably didn't have to do that... most likely 40019 needs to be open in
the outbound. Most routers don't control outbound traffic.
| Quote: | I'm not sure if I have to do anything in ISA.
|
Yes, you most likely need to create that packet filter (and if you are using
web based IP detection, which is a must behind a NAT router, then you need
port 80 outbound as well).
| Quote: | For other program (Mozilla), I already created entries to allow IP
traffic. I don't fully understand ISA and get confused between "Access
Policy" entries for "IP Packet Fileters" and "Protocol Rules". Do I need
to do anything for
|
I assume you are installing DU on the server... so a Packet Filter is what
you need (Protocol Rules affect the clients, not the server). Follow the
directions in this site (under "Packet Filtering for Services and App's on
the ISA Server"):
http://www.isaserver.org/tutorials/How_to_use_ISA_Server_Packet_Filters.html
Call it DirectUpdate, select TCP as protocol, direction = outbound, local
port = dynamic, remote port = fixed : 40019.
If you still have trouble. Just post back.
Cheers,
--
Javier [SBS MVP]
www.msmvps.com/javier
<< SBS ROCKS!!! >> |
|
| Back to top |
|
 |
SuperGumby [SBS MVP]
Guest
|
Posted:
Fri Jan 21, 2005 3:53 am Post subject:
Re: dyndns.org question |
|
|
you can also change ISA to accept 'basic authentication' and set DU to use
proxy settings.
"Javier Gomez [SBS MVP]" <javier_gomez@REMOVE.THIS.engineer.com> wrote in
message news:%23cQNCTy$EHA.3368@TK2MSFTNGP15.phx.gbl...
| Quote: | "Then, make sure that no firewall application (like ZoneAlarm) is
blocking TCP connection on port 40019 (default port)."
I opened this port in the router's setup. (strange, I forgot to open the
port in my home router, but it still worked).
You probably didn't have to do that... most likely 40019 needs to be open
in the outbound. Most routers don't control outbound traffic.
I'm not sure if I have to do anything in ISA.
Yes, you most likely need to create that packet filter (and if you are
using web based IP detection, which is a must behind a NAT router, then
you need port 80 outbound as well).
For other program (Mozilla), I already created entries to allow IP
traffic. I don't fully understand ISA and get confused between "Access
Policy" entries for "IP Packet Fileters" and "Protocol Rules". Do I need
to do anything for
I assume you are installing DU on the server... so a Packet Filter is what
you need (Protocol Rules affect the clients, not the server). Follow the
directions in this site (under "Packet Filtering for Services and App's on
the ISA Server"):
http://www.isaserver.org/tutorials/How_to_use_ISA_Server_Packet_Filters.html
Call it DirectUpdate, select TCP as protocol, direction = outbound, local
port = dynamic, remote port = fixed : 40019.
If you still have trouble. Just post back.
Cheers,
--
Javier [SBS MVP]
www.msmvps.com/javier
SBS ROCKS!!!
|
|
|
| Back to top |
|
 |
Richard Fagen
Guest
|
Posted:
Fri Jan 21, 2005 6:48 am Post subject:
Re: dyndns.org question |
|
|
Hi Javier,
Thanks for the GREAT link. Now ISA is starting to make much more sense.
I see Protocol Rules are for the workstations/PC and Packet Filters are
for applications and services on the server. Finally, an explanation
in simple terms :)
As per your message, I created a new Packet Filter but it still doesn't
work. I'm sure I needed to do this too, so I suspect there is another
setting somewhere in DirectUpdate that I need to configure.
| Quote: | Call it DirectUpdate, select TCP as protocol, direction = outbound,
local port = dynamic, remote port = fixed : 40019.
|
Wouldn't port 80 be opened as part of the SBS install? I checked and
there are default rules for ports 80 and 443 already.
| Quote: | Yes, you most likely need to create that packet filter (and if you are using
web based IP detection, which is a must behind a NAT router, then you need
port 80 outbound as well).
|
Richard |
|
| Back to top |
|
 |
Richard Fagen
Guest
|
Posted:
Fri Jan 21, 2005 6:48 am Post subject:
Re: dyndns.org question |
|
|
Hi,
This sounds like a great idea. I previously tried some setting in the
proxy area but I wasn't sure what the settings should be.
If the server's internal nic is the default 192.168.16.2 and the ext nic
is 192.168.123.2 and the router is 192.168.123.254, what should I enter
in DU's proxy text field? There is another checkbox that asks, "server
requires authentication?", then it displays textboxes for port (default
8080) and usernamne/password.
I tried many combinations but I think I'd better ask the ISA experts here.
How does one change ISA to accept basic authenication?
| Quote: | you can also change ISA to accept 'basic authentication' and set DU to use
proxy settings.
|
Thanks for the ideas.
Richard |
|
| Back to top |
|
 |
|
|
|
|