SP2 Firewall: Loopback not in MySubnet

S

Stas

With XPSP2 Firewall, I have set an exception for a
program and selected "my network (subnet) only" as the
range to allow connections from. My observation is now
that I can NOT access the service from my OWN PC, but I
CAN access it from a colleague's PC (indeed on the same
subnet). When I set an explicit range as below, manually
including the loopback, then I CAN access the service
from my own PC

123.123.0.0/255.255.0.0,127.0.0.1/255.255.255.255

My conclusion is that "my network (subnet) only" allows
everybody else on the subnet, but does not include the
loopback address, and I must say that is rather strange
to me.

Stas
 
T

Torgeir Bakken \(MVP\)

Stas said:
With XPSP2 Firewall, I have set an exception for a
program and selected "my network (subnet) only" as the
range to allow connections from. My observation is now
that I can NOT access the service from my OWN PC, but I
CAN access it from a colleague's PC (indeed on the same
subnet). When I set an explicit range as below, manually
including the loopback, then I CAN access the service
from my own PC

123.123.0.0/255.255.0.0,127.0.0.1/255.255.255.255

My conclusion is that "my network (subnet) only" allows
everybody else on the subnet, but does not include the
loopback address, and I must say that is rather strange
to me.
Hi

This one might be relevant:

Programs that connect to IP addresses that are in the loopback address
range may not work as you expect in Windows XP Service Pack 2

http://support.microsoft.com/?kbid=884020
 
S

Stas

Hei Torgeir,

Thanks for your feedback. I read the same article and
concluded that it doesn't apply to what I'm observing. I
doubt that Sentinel LM connects to a loopback other than
127.0.0.1 after having done a broadcast for servers. I
decided to remove the explicit mention of the lookback IP
from the list of IP's allowed, and noticed the following
for the "exception scope" at the firewall:

"My network (subnet) only" - does NOT allow me to connect
Custom: 123.123.0.0/255.255.0.0 - DOES allow me to connect

This suggest so me that it isn't so much the calling
method that makes the difference, but the handling on the
firewall side.

---
Hi

This one might be relevant:

Programs that connect to IP addresses that are in the
loopback address range may not work as you expect in
Windows XP Service Pack 2

http://support.microsoft.com/?kbid=884020
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top