Can Ping Server But Server Can't Ping Client

Discussion in 'Networks' started by PompeyFC, Jul 30, 2007.

  1. PompeyFC

    PompeyFC Nibble Poster

    66
    1
    17
    Anyone know why this is ?

    DHCP is allocating ip addresses fine and my 2 xp pro PC's are receiving their info fine

    I can ping the server by name but the server cannot ping any of the clients

    I cannot join a domain because I get network not found

    dcdiag, netdiag, nslookup etc all report they are fine
     
    Certifications: MCP, MCDST, A+, 70-270, 70-290, Network+
    WIP: Windows 7
  2. BosonMichael
    Honorary Member Highly Decorated Member Award 500 Likes Award

    BosonMichael Yottabyte Poster

    19,183
    500
    414
    Client sofware-based firewall?
     
    Certifications: CISSP, MCSE+I, MCSE: Security, MCSE: Messaging, MCDST, MCDBA, MCTS, OCP, CCNP, CCDP, CCNA Security, CCNA Voice, CNE, SCSA, Security+, Linux+, Server+, Network+, A+
    WIP: Just about everything!
  3. Sparky
    Highly Decorated Member Award 500 Likes Award

    Sparky Zettabyte Poster Moderator

    10,718
    543
    364
    Certifications: MSc MCSE MCSA:M MCSA:S MCITP:EA MCTS(x5) MS-900 AZ-900 Security+ Network+ A+
    WIP: Microsoft Certs
  4. PompeyFC

    PompeyFC Nibble Poster

    66
    1
    17
    tried stopping windows firewall and pinging but same thing, I did not stop it in services though just through the applet.

    surely you should not have to run a client server network with no firewall??!?!? at least the DNS/Domain guy at work says that XP and Server 2003 should be able to communicate with windows firewall on
     
    Certifications: MCP, MCDST, A+, 70-270, 70-290, Network+
    WIP: Windows 7
  5. Sparky
    Highly Decorated Member Award 500 Likes Award

    Sparky Zettabyte Poster Moderator

    10,718
    543
    364
    What error message do you get when you try to ping a PC?
     
    Certifications: MSc MCSE MCSA:M MCSA:S MCITP:EA MCTS(x5) MS-900 AZ-900 Security+ Network+ A+
    WIP: Microsoft Certs
  6. PompeyFC

    PompeyFC Nibble Poster

    66
    1
    17
    sorry sparky sort of is related to the previous thread but I have moved on from there a fair bit

    I just get request timed out when pinging from server to client

    yet DHCP allocates fine and I can ping server by name and IP from client. most odd.

    is the router stopping something ?
     
    Certifications: MCP, MCDST, A+, 70-270, 70-290, Network+
    WIP: Windows 7
  7. Sparky
    Highly Decorated Member Award 500 Likes Award

    Sparky Zettabyte Poster Moderator

    10,718
    543
    364
    How is everything setup now? Is the Server and two PCs patched into the router?

    Does the router have a static IP (it should do)? If so can the server ping that? :blink
     
    Certifications: MSc MCSE MCSA:M MCSA:S MCITP:EA MCTS(x5) MS-900 AZ-900 Security+ Network+ A+
    WIP: Microsoft Certs
  8. PompeyFC

    PompeyFC Nibble Poster

    66
    1
    17
    checklist

    yes, 2 clients plus server patched into the router - 1 network card on server

    1) does DHCP allocate addresses in scope - yes
    2) does dcdiag report everything ok - yes
    3) does netdiag pass everything - yes
    4) can the server ping the gateway - ie the router - yes
    5) can the server ping outside of the gateway ie internet - yes
    6) can the client ping the server by IP and name - yes
    7) can the client access the net - yes
    8) can the 2 clients ping each other - NO
    9) does NSLOOKUP report correct server - yes

    it must be firewall related ? but how are you supposed to have any sort of security if you run xp clients and server2003 without firewall on. Microsoft have surely not allowed this - it would be a major flaw in the design as xp clients are meant to be able to communicate with server 2003 with windows firewall enabled.

    is there a port I can open ?
     
    Certifications: MCP, MCDST, A+, 70-270, 70-290, Network+
    WIP: Windows 7
  9. Sparky
    Highly Decorated Member Award 500 Likes Award

    Sparky Zettabyte Poster Moderator

    10,718
    543
    364
    Stop the Windows firewall service and then disable it. If you can ping the client PCs and you still want the added security of the Windows firewall you need to add an exception for ICMP traffic.

    You can do this within Windows firewall or through Group Policy.
     
    Certifications: MSc MCSE MCSA:M MCSA:S MCITP:EA MCTS(x5) MS-900 AZ-900 Security+ Network+ A+
    WIP: Microsoft Certs
  10. PompeyFC

    PompeyFC Nibble Poster

    66
    1
    17
    yep everything now disabled. still cannot ping server to client
     
    Certifications: MCP, MCDST, A+, 70-270, 70-290, Network+
    WIP: Windows 7
  11. Sparky
    Highly Decorated Member Award 500 Likes Award

    Sparky Zettabyte Poster Moderator

    10,718
    543
    364
    Strange problem, can you switch the ports (for the PCs) on the router and then reboot it? :blink

    Edit: can you create a share on a PC and try and access it from the server? Type \\<ip address of PC> at the run line of the server. If you get a prompt for authentication then it looks like ICMP traffic is getting blocked.

    Also in 'My Network Places' are the PCs listed in a workgroup?
     
    Certifications: MSc MCSE MCSA:M MCSA:S MCITP:EA MCTS(x5) MS-900 AZ-900 Security+ Network+ A+
    WIP: Microsoft Certs
  12. PompeyFC

    PompeyFC Nibble Poster

    66
    1
    17
    sorry dude I have been a dick.

    Whilst I had disabled ZoneAlarm I had not un-installed it. Therefore some services which I did not recognise but belonged to zonealrm were still running. I un-installed it and hey presto i can ping from server to client

    MORE importantly I have joined the domain and I have windows Firewall enabled on both Server and XP Client, and I have not created any additional exceptions to be able to do this.

    It would seem very strange if Microsoft had designed it in such a way you could not use windows firewall and therefore be open to attack.

    THANK YOU very much for all your help, especiallly Moley and Sparky.

    We all learn by stupid mistakes I guess. !!!!
     
    Certifications: MCP, MCDST, A+, 70-270, 70-290, Network+
    WIP: Windows 7
  13. Sparky
    Highly Decorated Member Award 500 Likes Award

    Sparky Zettabyte Poster Moderator

    10,718
    543
    364
    Glad its sorted now mate :thumbleft
     
    Certifications: MSc MCSE MCSA:M MCSA:S MCITP:EA MCTS(x5) MS-900 AZ-900 Security+ Network+ A+
    WIP: Microsoft Certs
  14. dales

    dales Terabyte Poster

    2,005
    51
    142
    Just seen this thread, I've seen that sort of issue before, you would have thought that by clicking disable zonealarm that actually means stop firewalling my box, aparently zonelabs dont see it that way. Good product for a home user but it does appear to carry on working even when you dont want it to.


    "Sparkey has just inspired me to go and dig out my prong album, I have not listened to that for ages." :twisted: 8)
     
    Certifications: vExpert 2014+2015+2016,VCP-DT,CCE-V, CCE-AD, CCP-AD, CCEE, CCAA XenApp, CCA Netscaler, XenApp 6.5, XenDesktop 5 & Xenserver 6,VCP3+5,VTSP,MCSA MCDST MCP A+ ITIL F
    WIP: Nothing

Share This Page

Loading...
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.