Jump to content

local network names resolution differences between windows 7 sessions...


Recommended Posts

hello,

I have a local network with 21 windows 7 stations and Eset smart security 7, I have a shared printer on a computer with a software : Remote Queue Manager Personal.

When I print from a station, I don't always see in this software the name of the station, but its Ipv6 adress...

I have tried to put him in apprentissage mode or interactive mode (hips and firewall), I have look at the logs for the connexions and what the firewall did block... I have did a right click on some lines in the log and tell him  not to block it for all similar stuff but :

 - for some lines in the log I can't unblocked and autorise, why?

 - when, on a station,  I'm connected in an administrator session of windows 7 I see the name of this station in the sofware on the computer who control the prints, the names resolution works, but when I print a document from a session with limited rights on windows 7 I see the IPV6 adress in the software, the names resolution do not works, why?

 

Sorry for my english, I'm french.

Thank you

 

Link to comment
Share on other sites

Hello cedlere, since this is a local network, have you disabled ipv6 in the network adapters of the machines ?

Windows doesn't save wired network profiles. Therefore i assume if you make the change in the adapter under the admin account, user should use same.

 

In regards to your firewall settings in ESS, is the client able to print if you switch the firewall mode to learning or automatic ?

Link to comment
Share on other sites

  • Administrators

Why do you believe the isssue is related to ESET Smart Security? Does the problem go away after temporarily disabling the firewall?

Link to comment
Share on other sites

Hello cedlere, since this is a local network, have you disabled ipv6 in the network adapters of the machines ?

Windows doesn't save wired network profiles. Therefore i assume if you make the change in the adapter under the admin account, user should use same.

 

In regards to your firewall settings in ESS, is the client able to print if you switch the firewall mode to learning or automatic ?

- the stations use internet a lot, I prefer to keep Ipv6 , some websites could not work then?

- Perhaps the problem is not in the adaptater configuration... the prints works, in all the cases, it's in the name resolution, the control print software display the name of the station when the print comes from an admin session but when the print comes from a limited windows session, the software displays the ipv6 adress...

 

 

Why do you believe the isssue is related to ESET Smart Security? Does the problem go away after temporarily disabling the firewall?

It's not possible to all disabling in eset smart secutity, he continue to block some things... for sample I couldn't browse my network well and see all the stations but in the logs of eset I have unblocked some protocoles and ports for the name resolution and after I could see all my network.

I have all tried : learning mode, interactive mode, in HIPS, in the firewall, I have tried to disable HIPS and all, restart the machine, disabling the protection, disabling the firewall, etc... he continue to block some things... the last thing  that I see is to uninstall the sofware to test...

I have tried to repair Ipv6 but the problem is always here, so I think it comes from eset :

hxxp://technet.microsoft.com/fr-fr/library/bb727023.aspx

But why the difference between the windows sessions? the admin session and the session with restricted rights.

Link to comment
Share on other sites

  • Administrators

If you suspect the firewall to block certain communication, try changing the integration type to "Personal firewall is completely" disabled and restart the system. If that doesn't make any difference, what about renaming C:\Windows\System32\drivers\eamonm.sys and ehdrv.sys in safe mode, one at a time?

Link to comment
Share on other sites

cedlere, your local ip is not the same ip that broadcasts over the web, its your internal networks ip. :)

 

If you suspect its in the name resolution, then check your dns settings in the adapter, obtain automatic dns ? or possibly on your server if using a domain, the dns server role may need to be looked at, or on your router if no server. :)  In your local network, which node receives dns requests ?

 

If you uninstall ESET completely , the issue persists ?

Link to comment
Share on other sites

If you suspect the firewall to block certain communication, try changing the integration type to "Personal firewall is completely" disabled and restart the system.

Effectively, I did not know this option, so I can test without uninstall the sofware, and the problem seems not always comes from Eset, sorry...

 

 

 

If you suspect its in the name resolution, then check your dns settings in the adapter, obtain automatic dns ? or possibly on your server if using a domain, the dns server role may need to be looked at, or on your router if no server. :)  In your local network, which node receives dns requests ?

 

 

Here is what I have do :

- changing the integration type to "Personal firewall is completely disabled", disabling HIPS, restart, disabling protection => so no firewall nether protection (on the 2 pc : client and server)

- no ipv6 on the pc server

- cmd on the pc server : ipconfig /release, ipconfig /renew, arp -d *, ipconfig /registerdns, nbtstat -RR

- cmd on the pc client : ipconfig /release, ipconfig /renew, arp -d *, ipconfig /registerdns, nbtstat -RR

- I have verify the resolution with nbtstat -a : ok

but I did always have the same problem... must we wait 15 min or more?

I have on my freebox disable opendns (208.67.222.222, 208.67.220.220)

My problem was solved ! so I thought it was opendns the problem, but I did put again the opendns adress on my box, but it always works !

So I have succeed but I did not know  where the problem comes from? :

- I should wait more than 15 min?

- it did not try netbios/ wins after opendns? (my node is hybrid)

- since the name is the cache I can use opendns instead?

 

Someone have an idea?

thanks you

Link to comment
Share on other sites

I have twenty stations... I have tried on a other station what I have explained above on an other station, but this time when I restablished the firewall and eset protection my name was not resolved anymore... so sometimes it's the fault to Eset...

I have tried on some stations to parameter in "internet and mail" , in "protocol filter", in " IP adresses exclued" to not filter the adress of the station where my server is, it did seem to work for some stations but not for all... some other ideas?

An answer for what I have I tried above?

For me, my problem is not totally resolved again...

Thanks you

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...