Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

DHCP Question with SP1

1 view
Skip to first unread message

Daniel Woodhouse

unread,
Jul 1, 2005, 7:34:25 PM7/1/05
to
Hi there

I installed SP1 for SBS2003 premium on both my main server and my test
server (Brand new install) and the install went fine but DHCP stopped
working on both servers. On investigation I found out that ISA2004's
internal firewall is blocking the requests and needs to be configured. I
configured it as per instructions from Tom Shinders ISA2004 book and also
some articles off the internet but it still would not work.

Basically the instructions say to allow the DHCP Request and send using the
group called "Internal". I noticed that the ISA firewall was still blocking
the requests and as soon as I removed the internal group from the DHCP
packet filters and added External instead it works fine.

This to me would make sense as the internal group is defined by the internet
IP range of your network for example 192.168.1.1-192.168.1.254. When a
computer is plugged into the network and it tries to get an ip address at
that point the address of the PC is either 0.0.0.0 or 169.x.x.x and there
fore it is never a part of the internal group so it can never get and IP
address as the firewall is blocking the request. ISA 2004 was even telling
me that an external address is attemping to access DCHP and that it denied
the request. That is why when I added the external group it works.

My question is this... Am I missing something here? Can all the instructions
on the internet be wrong? If I am wrong what do I need to do to configure it
without using the external group.

My concern is.... Allowing the external group to access DHCP does this open
up the potential of any computer on the internet to access DHCP?

It seems a bit of a mistake on Microsofts behalf to supply a patch that
basically kills DHCP out of the box. There must be thousands of networks
breaking down because you dont usually find this problem until the PC's DHCP
leases start to expire. I can't help thinking I missed a step in the SP1
install.

Thanks in advance for your time.

Cheers

Daniel.


Les Connor [SBS Community Member - SBS MVP]

unread,
Jul 2, 2005, 1:20:07 AM7/2/05
to
Something is odd to your configuration, I think.

Can you post an ipconfig /all from the server, and one from a client?


--
Les Connor [SBS Community Member - SBS MVP]
-----------------------------------------------------------
SBS Rocks !


"Daniel Woodhouse" <dan...@woodhouse.net.nznospam> wrote in message
news:%23X%23xyVpf...@tk2msftngp13.phx.gbl...

Daniel Woodhouse

unread,
Jul 3, 2005, 4:16:35 PM7/3/05
to
This is the server....Brand new install

Ethernet adapter Local network:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network
Connection
Physical Address. . . . . . . . . : 00-0E-0C-4A-94-8E
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.20.1
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . : 192.168.20.1
Primary WINS Server . . . . . . . : 192.168.20.1

Ethernet adapter Internet:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network
Connection #
2
Physical Address. . . . . . . . . : 00-0E-0C-4A-94-8F
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.1.2
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 192.168.20.1
Primary WINS Server . . . . . . . : 192.168.20.1
NetBIOS over Tcpip. . . . . . . . : Disabled

Client setup...

IP Address. . . . . . . . . . . . : 192.168.20.33
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.20.1

Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No


Ethernet adapter Local Area Connection:

Description . . . . . . . . . . . : Intel(R) PRO/100 VE Network
Connecti
on
Physical Address. . . . . . . . . : 00-11-11-5D-71-08
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.20.33
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.20.1
DHCP Server . . . . . . . . . . . : 192.168.20.1
DNS Servers . . . . . . . . . . . : 192.168.20.1
Primary WINS Server . . . . . . . : 192.168.20.1
Lease Obtained. . . . . . . . . . : Monday, 4 July 2005 8:05:24 a.m.
Lease Expires . . . . . . . . . . : Tuesday, 12 July 2005 8:05:24
a.m.

Cheers

Daniel.

"Les Connor [SBS Community Member - SBS MVP]" <les.c...@DEL.cfive.ca>
wrote in message news:uWzJ2Wsf...@TK2MSFTNGP10.phx.gbl...

Marina Roos [SBS-MVP]

unread,
Jul 3, 2005, 5:04:24 PM7/3/05
to
Hi Daniel,

We are missing some vital information here. Please put the complete output
of ipconfig/all in here.

--
Regards,

Marina Roos
Microsoft SBS-MVP
One of the Magical M&M's
www.smallbizserver.net
Take part in SBS forum:
http://www.smallbizserver.net/Default.aspx?tabid=53

"Daniel Woodhouse" <dan...@woodhouse.net.nznospam> schreef in bericht
news:%23XzsWyA...@TK2MSFTNGP09.phx.gbl...

Daniel Woodhouse

unread,
Jul 3, 2005, 7:14:47 PM7/3/05
to
...sorry..here we go...

****Server...

Microsoft Windows [Version 5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.

C:\Documents and Settings\Administrator>ipconfig /all

Windows IP Configuration

Host Name . . . . . . . . . . . . : buzzlightyear
Primary Dns Suffix . . . . . . . : Woodhouse.local


Node Type . . . . . . . . . . . . : Hybrid

IP Routing Enabled. . . . . . . . : Yes


WINS Proxy Enabled. . . . . . . . : No

DNS Suffix Search List. . . . . . : Woodhouse.local

Ethernet adapter Local network:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network
Connection
Physical Address. . . . . . . . . : 00-0E-0C-4A-94-8E
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.20.1
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . : 192.168.20.1
Primary WINS Server . . . . . . . : 192.168.20.1

Ethernet adapter Internet:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network
Connection #
2
Physical Address. . . . . . . . . : 00-0E-0C-4A-94-8F
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.1.2
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 192.168.20.1
Primary WINS Server . . . . . . . : 192.168.20.1
NetBIOS over Tcpip. . . . . . . . : Disabled

C:\Documents and Settings\Administrator>

****Client... please note that DHCP is working because I have left the
external group in the packet filter.

Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\daniel.WOODHOUSE>ipconfig /all

Windows IP Configuration

Host Name . . . . . . . . . . . . : PERCYTHEPC
Primary Dns Suffix . . . . . . . : Woodhouse.local


Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No

DNS Suffix Search List. . . . . . : Woodhouse.local
woodhouse.local

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . : woodhouse.local


Description . . . . . . . . . . . : Intel(R) PRO/100 VE Network
Connecti
on
Physical Address. . . . . . . . . : 00-11-11-5D-71-08
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.20.33
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.20.1
DHCP Server . . . . . . . . . . . : 192.168.20.1
DNS Servers . . . . . . . . . . . : 192.168.20.1
Primary WINS Server . . . . . . . : 192.168.20.1
Lease Obtained. . . . . . . . . . : Monday, 4 July 2005 8:05:24 a.m.
Lease Expires . . . . . . . . . . : Tuesday, 12 July 2005 8:05:24
a.m.

C:\Documents and Settings\daniel.WOODHOUSE>

Thanks so much

Daniel.

"Marina Roos [SBS-MVP]" <mar...@roos.nodontwantspam.nl.com> wrote in message
news:OKzwQLB...@TK2MSFTNGP09.phx.gbl...

Marina Roos [SBS-MVP]

unread,
Jul 3, 2005, 9:46:50 PM7/3/05
to
Hi Daniel,

Ipconfigs look good, although you can delete the WINS on the external nic.

Now the 'I have left the external group in the packet filter' is not making
much sense to me. Please elaborate. Undo whatever you did, and simply rerun
CEICW and enable the firewall. This will put back ISA to its defaults.

--
Regards,

Marina Roos
Microsoft SBS-MVP
One of the Magical M&M's
www.smallbizserver.net
Take part in SBS forum:
http://www.smallbizserver.net/Default.aspx?tabid=53

"Daniel Woodhouse" <dan...@woodhouse.net.nznospam> schreef in bericht

news:%23dNTEUC...@TK2MSFTNGP10.phx.gbl...

Daniel Woodhouse

unread,
Jul 3, 2005, 11:01:40 PM7/3/05
to
Hi Marina

That is the problem I am having. I put the ISA2004 back to the defaults
using the CEICW and DHCP stops working again. I fix the problem using the
following instructions...


Allowing the DHCP (Request) Protocol
In this procedure, the DHCP clients are located in the Internal network. To
allow the DHCP (request) protocol, use the following steps.

1.
In the Firewall Policy node of ISA Server Management, right-click
Firewall Policy, point to New, and then click Access Rule.

2.
In the New Access Rule Wizard, type a name for the rule. For example:
Allow DHCP Requests. Then click Next.

3.
In the Rule Action page, click Allow. Then click Next.

4.
In the Protocols page, in This rule applies to, click Selected
protocols. Then click Add.

5.
In Add Protocols, in the All Protocols section, click DHCP (request).
Click Add, click Close, and then click Next.

6.
In the Access Rule Sources page, click Add.

7.
In Add Network Entities, in the Networks section, click Internal. Click
Add, click Close, and then click Next.

8.
In the Access Rule Destinations page, click Add.

9.
In Add Network Entities, in the Networks section, click Local Host.
Click Add, click Close, and then click Next.

10.
In the User Sets page, All Users is selected by default. Click Next,
and then click Finish.


Allowing the DHCP (Reply) Protocol
In this procedure, the DHCP clients are located in the Internal network. To
allow the DHCP (reply) protocol, use the following steps.

1.
In the Firewall Policy node of ISA Server Management, right-click
Firewall Policy, point to New, and then click Access Rule.

2.
In the New Access Rule Wizard, type a name for the rule. For example:
Allow DHCP Replies. Then click Next.

3.
In the Rule Action page, click Allow. Then click Next.

4.
In the Protocols page, in This rule applies to, click Selected
protocols. Then click Add.

5.
In Add Protocols, in the All Protocols section, click DHCP (reply).
Click Add, click Close, and then click Next.

6.
In the Access Rule Sources page, click Add.

7.
In Add Network Entities, in the Networks section, click Local Host.
Click Add, click Close, and then click Next.

8.
In the Access Rule Destinations page, click Add.

9.
In Add Network Entities, in the Networks section, click Internal. Click
Add, click Close, and then click Next.

10.
In the User Sets page, All Users is selected by default. Click Next,
and then click Finish.

By adding the the internal network entity the internal firewall blocks the
DHCP request because a PC that has no IP address (needs to renew one) is not
a member of the Internal network entity group. I add the external network
entity to the access rule and it works fine...

Thanks again.

Daniel.


"Marina Roos [SBS-MVP]" <mar...@roos.nodontwantspam.nl.com> wrote in message

news:ugL7FpDg...@TK2MSFTNGP14.phx.gbl...

Daniel Woodhouse

unread,
Jul 7, 2005, 9:40:04 PM7/7/05
to
Hi Group

Just thought I would let you know I figured out what the problem was in case
you wanted to know. The LAT was set for 192.168.20.1-192.168.20.254 instead
192.168.20.1-192.168.20.255. Since the workstations use a broadcast address
of .255 the server thought they were external requests.

All working perfectly now.

Daniel.


"Daniel Woodhouse" <dan...@woodhouse.net.nznospam> wrote in message

news:uk2U6SEg...@TK2MSFTNGP10.phx.gbl...

0 new messages