Re: ZoneAlarm Pro ICS problem

From:
Date: 09/20/02


Date: Fri, 20 Sep 2002 09:27:45 +1000

On Thu, 19 Sep 2002 10:36:24 +0200, "Peter De Jager"
<peterdj@mweb.co.za> wrote:

>I'm using ZA Pro 3.1.395.0 on a W2k server with ICS enabled. My problem is
>that clients cannot see the Internet. The local network has been added as a
>trusted zone (192.168.0.*) and file/print sharing works fine. I've followed
>the instructions on the ZA site for setting up Internet Connection Sharing
>(which was working before installing ZA, as required) but still no joy. The
>way I need it set up is: ZA installed only on the ICS server, Internet zone
>set at max security. Thanks for any help.

I have ZAPro 3.0.133 running fine with ICS.

Have it on ICS gateway with Network 192.168.0.0/255.255.255.0 and IP
Address 127.0.0.1 trusted, configured as ICS/NAT Gateway with Local
Address of 192.168.0.1, Internet Zone Security is High, Trusted Zone
Security is Medium.

Have it also on client PC with Network 192.168.0.0/255.255.255.0 and IP
Address 127.0.0.1 trusted, configured as Client of ICS/NAT Gateway with
gateway address of 192.168.0.1, Zone securities set same as gateway.

Have a laptop I plug in sometimes, it runs ZA (not pro) both 2.x and 3.x
(different OS boots) and is not set as client of ICS/NAT gateway, it
also can access Internet via the gateway.

Note that you don't *need* to have ZAPro on the client PC's for it to
work - having ZAPro on the clients just helps prevent apps phoning home
(and adds the moderately functional privacy features). Perhaps you might
want to disable ZAPro on the client PC's while you debug your gateway
configuration.

>(I agree with some of the other posts that) tech support from ZoneLabs is
>virtually non-existent. Does anyone know of a dedicated ZoneLabs/ZoneAlarm
>newsgroup? I searched but didn't find. Clearly if we're going to get help it
>will be from the community, not ZoneLabs.

Other places you can try are newsgroups on Gibson Research's news
server. NB: I'm not a Steve Gibson fan, but the newsgroups on his server
have a lot of discussion about ZA/ZAPro. Checkout news.grc.com with your
news reader.

>Alternatively: Which other firewall should I try, specifically for using ICS
>as described? Thanks again.

Sounds like Kerio is a good choice (many people seem to recommend it).

--
Ross McKay, WebAware Pty Ltd
"I got to think less. I had thought that, actually."
- John Cusack, "Pushing Tin"



Relevant Pages

  • RE: ISA 2004 Firewall Client and ActiveSync 4.2
    ... at home in my WLAN all internet ... that killing my default gateway is not the way ... gateway and the appropriate DNS server entries. ... server internal IP then your client works as a secureNAT client and you're ...
    (microsoft.public.isa.clients)
  • ICS DNS suddenly stopped working.
    ... After adding a new gateway server, and reconfiguring the old gateway server ... without any intervention or other configuration, the ICS connection was ... The first adapter was connected to my cable modem ... internet connection, and configured it appropriately. ...
    (microsoft.public.windowsxp.network_web)
  • Re: ICS on small home network no longer works for http traffic
    ... 1) If you're using MS ICS or Windows ... After installed a new router or cable modem replacing dial-up to access ... the Internet, you can't access some web sites. ... The client PC can ping to a outside IP, or a name and DNS> resolves the name ok. ...
    (microsoft.public.windowsxp.network_web)
  • Re: ICS setup problem
    ... may be idiosyncratic when the ICS is being implemented rather than ... Alarm though shows nothing getting through from the Internet. ... >>that contains the name of the dial up client and path to the server! ... >>connection on the server through the dial up gateway...incoming and ...
    (microsoft.public.windowsxp.network_web)
  • RE: sbs and gateways
    ... point the default gateway to the router, the client is unable to browse the ... If the default gateway is pointing to the internal NIC of the SBS ... When an internal client attempts to access the internet, ...
    (microsoft.public.windows.server.sbs)