Leigh
Fri May 09 03:25:00 PDT 2008
Hi Bill here is another log I have just created
Does this help us
2008-05-09 11:04:21 OPEN-INBOUND TCP 81.140.65.54 192.168.16.41 27348 1723 -
- - - - - - - -
2008-05-09 11:04:21 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:22 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:23 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:24 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:24 DROP UDP 192.168.0.171 255.255.255.255 68 67 328 - - - -
- - - RECEIVE
2008-05-09 11:04:24 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:25 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:26 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:27 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:27 DROP UDP 192.168.0.171 255.255.255.255 68 67 328 - - - -
- - - RECEIVE
2008-05-09 11:04:27 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:27 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:28 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:28 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:29 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:29 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:30 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:30 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:30 DROP UDP 192.168.0.170 255.255.255.255 138 138 209 - - -
- - - - SEND
2008-05-09 11:04:30 DROP UDP 192.168.0.170 255.255.255.255 138 138 245 - - -
- - - - SEND
2008-05-09 11:04:32 DROP UDP 192.168.0.170 255.255.255.255 138 138 209 - - -
- - - - SEND
2008-05-09 11:04:33 DROP UDP 192.168.0.170 255.255.255.255 138 138 209 - - -
- - - - SEND
2008-05-09 11:04:35 DROP UDP 192.168.0.170 255.255.255.255 138 138 209 - - -
- - - - SEND
2008-05-09 11:04:36 DROP UDP 192.168.0.170 255.255.255.255 138 138 221 - - -
- - - - SEND
2008-05-09 11:04:37 DROP UDP 192.168.0.170 255.255.255.255 138 138 221 - - -
- - - - SEND
2008-05-09 11:04:38 DROP UDP 192.168.0.170 255.255.255.255 138 138 221 - - -
- - - - SEND
2008-05-09 11:04:39 DROP UDP 192.168.0.170 255.255.255.255 138 138 221 - - -
- - - - SEND
2008-05-09 11:04:40 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:41 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:42 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:43 DROP UDP 192.168.0.170 255.255.255.255 138 138 202 - - -
- - - - SEND
2008-05-09 11:04:43 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:04:43 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:43 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:04:43 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:44 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:04:44 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:45 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:46 DROP UDP 192.168.0.170 255.255.255.255 137 137 96 - - -
- - - - SEND
2008-05-09 11:04:46 DROP UDP 192.168.0.170 255.255.255.255 138 138 209 - - -
- - - - SEND
2008-05-09 11:04:46 DROP UDP 192.168.0.170 255.255.255.255 138 138 209 - - -
- - - - SEND
2008-05-09 11:04:46 DROP UDP 192.168.0.170 255.255.255.255 138 138 239 - - -
- - - - SEND
2008-05-09 11:04:47 DROP UDP 192.168.0.170 255.255.255.255 138 138 202 - - -
- - - - SEND
2008-05-09 11:04:47 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:04:48 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:04:48 DROP TCP 192.168.16.41 192.168.0.171 445 27382 48 SA
2944057071 1540601253 9520 - - - SEND
2008-05-09 11:04:48 OPEN-INBOUND TCP 192.168.0.1 192.168.16.41 27383 139 - -
- - - - - - -
2008-05-09 11:04:48 DROP TCP 192.168.16.41 192.168.0.171 139 27384 48 SA
293628911 1492339613 9520 - - - SEND
2008-05-09 11:04:48 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:04:51 DROP UDP 192.168.0.170 255.255.255.255 138 138 202 - - -
- - - - SEND
2008-05-09 11:04:51 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:04:51 DROP TCP 192.168.16.41 192.168.0.171 445 27382 48 SA
2944057071 1540601253 9520 - - - SEND
2008-05-09 11:04:51 DROP TCP 192.168.16.41 192.168.0.171 139 27384 48 SA
293628911 1492339613 9520 - - - SEND
2008-05-09 11:04:51 DROP TCP 192.168.16.41 192.168.0.171 445 27382 40 A
2944057072 1540601253 9520 - - - SEND
2008-05-09 11:04:51 DROP TCP 192.168.16.41 192.168.0.171 139 27384 40 A
293628912 1492339613 9520 - - - SEND
2008-05-09 11:04:52 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:04:53 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:04:55 DROP UDP 192.168.0.170 255.255.255.255 138 138 211 - - -
- - - - SEND
2008-05-09 11:04:55 DROP UDP 192.168.0.170 255.255.255.255 138 138 202 - - -
- - - - SEND
2008-05-09 11:04:55 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:04:56 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:04:57 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:04:57 DROP TCP 192.168.16.41 192.168.0.171 139 27384 48 SA
293628911 1492339613 9520 - - - SEND
2008-05-09 11:04:57 DROP TCP 192.168.16.41 192.168.0.171 445 27382 48 SA
2944057071 1540601253 9520 - - - SEND
2008-05-09 11:04:57 DROP TCP 192.168.16.41 192.168.0.171 445 27382 40 A
2944057072 1540601253 9520 - - - SEND
2008-05-09 11:04:57 DROP TCP 192.168.16.41 192.168.0.171 139 27384 40 A
293628912 1492339613 9520 - - - SEND
2008-05-09 11:05:00 DROP UDP 192.168.0.170 255.255.255.255 138 138 202 - - -
- - - - SEND
2008-05-09 11:05:00 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:05:00 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:05:01 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:05:04 DROP UDP 192.168.0.170 255.255.255.255 138 138 202 - - -
- - - - SEND
2008-05-09 11:05:04 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:05:05 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:05:05 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:05:08 DROP UDP 192.168.0.170 255.255.255.255 138 138 211 - - -
- - - - SEND
2008-05-09 11:05:08 DROP UDP 192.168.0.170 255.255.255.255 138 138 202 - - -
- - - - SEND
2008-05-09 11:05:08 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:05:09 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:05:09 CLOSE TCP 192.168.16.41 192.168.0.1 139 27383 - - - - -
- - - -
2008-05-09 11:05:09 DROP TCP 192.168.0.171 192.168.16.41 27389 80 48 S
2642745237 0 65535 - - - RECEIVE
2008-05-09 11:05:10 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:05:11 DROP UDP 192.168.16.41 239.255.255.250 1088 1900 161 - -
- - - - - RECEIVE
2008-05-09 11:05:12 OPEN TCP 192.168.16.41 192.168.16.254 1091 49153 - - - -
- - - - -
2008-05-09 11:05:12 CLOSE TCP 192.168.16.41 192.168.16.254 1091 49153 - - -
- - - - - -
2008-05-09 11:05:12 OPEN TCP 192.168.16.41 192.168.16.254 1092 49152 - - - -
- - - - -
2008-05-09 11:05:12 DROP UDP 192.168.0.170 255.255.255.255 138 138 202 - - -
- - - - SEND
2008-05-09 11:05:12 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:05:12 DROP TCP 192.168.0.171 192.168.16.41 27389 80 48 S
2642745237 0 65535 - - - RECEIVE
2008-05-09 11:05:13 CLOSE TCP 192.168.16.41 192.168.16.254 1092 49152 - - -
- - - - - -
2008-05-09 11:05:13 OPEN TCP 192.168.16.41 192.168.16.254 1094 49152 - - - -
- - - - -
2008-05-09 11:05:13 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:05:13 CLOSE TCP 192.168.16.41 213.171.216.66 1080 110 - - - -
- - - - -
2008-05-09 11:05:14 CLOSE TCP 192.168.16.41 192.168.16.254 1094 49152 - - -
- - - - - -
2008-05-09 11:05:14 DROP UDP 192.168.16.41 239.255.255.250 1088 1900 161 - -
- - - - - RECEIVE
2008-05-09 11:05:14 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:05:17 DROP UDP 192.168.0.170 255.255.255.255 138 138 202 - - -
- - - - SEND
2008-05-09 11:05:17 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:05:17 DROP UDP 192.168.16.41 239.255.255.250 1088 1900 161 - -
- - - - - RECEIVE
2008-05-09 11:05:17 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:05:18 DROP UDP 192.168.0.170 255.255.255.255 137 137 78 - - -
- - - - SEND
2008-05-09 11:05:19 DROP TCP 192.168.0.171 192.168.16.41 27389 80 48 S
2642745237 0 65535 - - - RECEIVE
2008-05-09 11:05:21 DROP UDP 192.168.0.170 255.255.255.255 138 138 211 - - -
- - - - SEND
2008-05-09 11:05:46 DROP UDP 192.168.0.170 255.255.255.255 138 138 239 - - -
- - - - SEND
2008-05-09 11:05:49 OPEN UDP 192.168.16.41 195.26.36.3 1095 53 - - - - - - -
- -
2008-05-09 11:05:49 CLOSE TCP 192.168.16.41 81.140.65.54 1723 27348 - - - -
- - - - -
"Leigh" wrote:
> Hello Bill
>
> I have allowed the print and file sharing to be accessed by any computer
> (including those on the internet) previously and still no luck.!!
> I also created a log file "pfirewall" previously which I have copied into
> here. Unfortunately it doesnt fit very well and looks a mess in this post.
> Perhaps you can cast your eye over it and make some observations that may
> help as I do not really understand all the information contained.
>
> 81.140.65.54 is the SBS external static .192.168.16.41 is the XP internal
> fixed IP 192.168.0.1 is the internal SBS ip
> I can see a lot of DROPS in the log which seem to involve TCP and UDP ports
>
> In all the research I have done I understood I only need to make sure to
> open port 1723 so what are all the others, are they to do with the VPN
> connection I am trying to make and do I need to open them.
> I dont want to open them if that will cause me other problems. Can you advise
>
> Thanks for your help
>
> 2008-04-25 14:15:42 OPEN-INBOUND TCP 81.140.65.54 192.168.16.41 13477 1723 -
> - - - - - - - -
> 2008-04-25 14:15:46 DROP UDP 192.168.0.174 255.255.255.255 68 67 328 - - - -
> - - - RECEIVE
> 2008-04-25 14:15:50 DROP UDP 192.168.0.174 255.255.255.255 68 67 328 - - - -
> - - - RECEIVE
> 2008-04-25 14:16:03 DROP TCP 192.168.16.41 192.168.0.174 445 13502 48 SA
> 3084194260 1133350834 9520 - - - SEND
> 2008-04-25 14:16:03 DROP TCP 192.168.0.1 192.168.16.41 13503 139 48 S
> 804954720 0 65535 - - - RECEIVE
> 2008-04-25 14:16:03 DROP TCP 192.168.16.41 192.168.0.174 139 13504 48 SA
> 369768440 2327057425 9520 - - - SEND
> 2008-04-25 14:16:06 DROP TCP 192.168.16.41 192.168.0.174 445 13502 48 SA
> 3084194260 1133350834 9520 - - - SEND
> 2008-04-25 14:16:06 DROP TCP 192.168.16.41 192.168.0.174 139 13504 48 SA
> 369768440 2327057425 9520 - - - SEND
> 2008-04-25 14:16:06 DROP TCP 192.168.0.1 192.168.16.41 13503 139 48 S
> 804954720 0 65535 - - - RECEIVE
> 2008-04-25 14:16:06 DROP TCP 192.168.16.41 192.168.0.174 445 1350240 A
> 3084194261 1133350834 9520 - - - SEND
> 2008-04-25 14:16:06 DROP TCP 192.168.16.41 192.168.0.174 139 13504 40 A
> 369768441 2327057425 9520 - - - SEND
> 2008-04-25 14:16:12 DROP TCP 192.168.16.41 192.168.0.174 139 13504 48 SA
> 369768440 2327057425 9520 - - - SEND
> 2008-04-25 14:16:12 DROP TCP 192.168.16.41 192.168.0.174 445 13502 48 SA
> 3084194260 1133350834 9520 - - - SEND
> 2008-04-25 14:16:12 DROP TCP 192.168.0.1 192.168.16.41 13503 139 48 S
> 804954720 0 65535 - - - RECEIVE
> 2008-04-25 14:16:12 DROP TCP 192.168.16.41 192.168.0.174 445 13502 40 A
> 3084194261 1133350834 9520 - - - SEND
> 2008-04-25 14:16:12 DROP TCP 192.168.16.41 192.168.0.174 139 13504 40 A
> 369768441 2327057425 9520 - - - SEND
> 2008-04-25 14:16:22 DROP UDP 192.168.0.170 255.255.255.255 138 138 239 - - -
> - - - - SEND
> 2008-04-25 14:16:24 DROP TCP 192.168.0.174 192.168.16.41 13518 80 48 S
> 1701259848 0 65535 - - - RECEIVE
> 2008-04-25 14:16:27 DROP TCP 192.168.0.174 192.168.16.41 13518 80 48 S
> 1701259848 0 65535 - - - RECEIVE
> 2008-04-25 14:16:33 DROP TCP 192.168.0.174 192.168.16.41 13518 80 48 S
> 1701259848 0 65535 - - - RECEIVE
>
>
> "Bill Sanderson" wrote:
>
> > I'm surprised at this result. I'd have thought that the VPN tunnel between
> > the SBS server and the XP workstation would have bypassed the firewall.
> >
> > Here's what I think I would do to try to troubleshoot this:
> >
> > Arrange to be able to connect to one of the XP workstations via Remote
> > Desktop. Open Remote Desktop through the Windows firewall on that XP
> > machine.
> >
> > You may find that when the VPN tunnel connects, you lose the RDP connection,
> > unfortunately--if that's the case, I'm not sure how to work around it.
> >
> >
http://support.microsoft.com/kb/875357
> >
> > is the article I would use to guide your troubleshooting. However, I think
> > you
> > could save some time if you can find as much information about this
> > "inherited software" as possible--particularly--what executables, if any,
> > are involved on the XP end, and what ports and protocols.
> >
> > One thought is to open file and printer sharing through the firewall, which
> > is a simple checkbox--if that is not already enabled. Another would be to
> > modify the scope of that sharing to include not just the local (in-store)
> > network, but also the IP address of the SBS 2003 server end of the VPN
> > tunnel.
> >
> > The firewall on the XP end can be configured to log dropped packets. I'd
> > suggest enabling this logging, and attempting a connection, and then
> > inspecting the log to see what's happening. That should give you clues
> > about what needs to be allowed through.
> >
> >
> >
> > "Leigh" <Leigh@discussions.microsoft.com> wrote in message
> > news:B3009467-6D21-4EC4-99C8-BAC6AD48A285@microsoft.com...
> > >I have Win 2003SBS and several Win XP sp2 standalone remote machines.
> > > I need to collect simple files from the XP machines using the 2003SBS and
> > > the internet on a daily basis.
> > > I have set XP machines as VPN servers
> > > I can connect to these machines from the 2003SBS by VPN no problem
> > >
> > > My problem is this.
> > >
> > > When I try to map a drive in 2003SBS to the shared folder on the XP
> > > machine
> > > I am unable to do so except when the Windows firewall is switched off on
> > > the
> > > XP machine.
> > > When the XP firewall is off every thing works fine.
> > > What do I have to do to the firewall to allow access to the shared folder,
> > > because I would rather not leave the firewall turned off permanently.
> > >
> > > Thanks for any help
> > >
> >