testing vpn, now i'm hosed!

O

OOL

Well, it seems I really did it this time.

I'm taking 70-216.

all home PC's win2k pro , SP4 and all current patches.

I have a win2k server in my house with 3 additional pc's (win2k pro)
connected using AD/roaming profiles. Since I'm working towards
mcsa/mcse, I use one PC to test different configurations. I did the
following....

Have cable modem with switch/router. All PC's have static IP
with DNS set to Win2k server. Server has forwarders to resolve
Internet IP addr. Default gateway is set to router.

Added second nic to server and a second to one pc. All is well.
Set up RRAS on server.
DNS states listeneing on both IP's.
Second nic on both boxes connected to seperate hub.

Logged on locally to win2k pro to test setting up a vpn connection
Used new connection wizard to set up vpn connect.through the second
nic to server. This worked.

Now the trouble on win2k test pc.......

Note: Only the win2k pro pc I was testing with is now acting funky. All
other pc's are working normally.

Can still do domain logon and all shares are ok.

On win2k box, nslookup returns error no response from server
DNS is working fine when tested from other pc's).
IE will not go anywhere internally or externally even if I use IP address.
Bottom line, all software attempting internet connection fail DNS lookup.

Can ping all internal PC's, and gateway.

Removed VPN connection. No change
Turned off/removed RRAS on server. No change
Removed/re-installed TCP/IP on PC. No change.
Removed second NIC on PC. Re-installed original. No change.

Event viewer (system) shows (after VPN test and reboot)....

Service control manager: Net logon teminates with 5737

NetLogon: The system returned the following unexpected error
code: The requested service provider could not be loaded or
initialized.

Looked up 5737, found only about issue with SP2, but replaced
rsaenh.dll anyway.

Any suggestions on additional diagnostics or just any suggestions
would be welcome. I'm a little wordy, but wanted to include all the
facts I could since I'm currently clueless.

The next step is going to be to reload the box if I can't come up
with anything else.

Thanks,

Tom
 
M

Marina Roos

If you have 2 nics in the server and are using RRAS, make sure you do the
regedits in 292822.
Furthermore: the internal should have a blank gateway. DNS on both internal
and external nic should only point to your server-IP.
Only TCP/IP should be bound to your external nic.
Check the bindingorder and make sure the internal nic in on top.
DNS-server should only be listening to the server-IP.
I assume you use the second nic for connecting to the internet.

Marina
 
A

anthony wooldridge

Marina Roos said:
If you have 2 nics in the server and are using RRAS, make sure you do the
regedits in 292822.

can you please explain "do the regedits in 292822"
does it refer to a previous news posting if so how can I access it?
Furthermore: the internal should have a blank gateway. DNS on both internal
and external nic should only point to your server-IP.
Only TCP/IP should be bound to your external nic.

Check the bindingorder and make sure the internal nic in on top.
DNS-server should only be listening to the server-IP.

can you explain? do you mean use loopback 127.0.0.1 or what?
 
M

Marina Roos

If your server has 2 nics and if you're using RRAS, your might have the
symptoms of the multihomed servers as explained in 292822 (Name resolution)
on the MS-site, knowledgebase. If your server is on SP3, or rather SP4, you
already have the hotfix mentioned in that article, but you still need to
apply those regedits.
Make sure DNS-server is loaded on your server and point it to your
server-IP. On the servernic(s) DNS should *only* point to your server-IP.

Marina
 
R

Roland Hall

Marina may be referring to a Technet article...

http://support.microsoft.com/default.aspx?scid=kb;en-us;292822&Product=win2000


Marina Roos said:
If you have 2 nics in the server and are using RRAS, make sure you do the
regedits in 292822.

can you please explain "do the regedits in 292822"
does it refer to a previous news posting if so how can I access it?
Furthermore: the internal should have a blank gateway. DNS on both internal
and external nic should only point to your server-IP.
Only TCP/IP should be bound to your external nic.

Check the bindingorder and make sure the internal nic in on top.
DNS-server should only be listening to the server-IP.

can you explain? do you mean use loopback 127.0.0.1 or what?
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top