Brand new DELL Dimension 8300 (w/ standard shipped image).
I get a DHCP address 69.81...etc. I can PING outbound fine, navigate the internet, check email, etc.
HOWEVER, I cannot PING from outside the network into my DELL computer. I first thought it was my McAfee software (antivirus, firewall, etc). I first tried to disable each program. Then I ended up uninstalling all McAfee software.
HOWEVER, I can still NOT ping my Dell. So then I tried rebooted my machine and entered SAFE MODE w/ NETWORKING. Then I CAN ping my Dell.
I have a feeling that there is some software loaded on the Dell Pre-loaded applications that is prohibiting me from PINGing the computer.
Any ideas??? I'm willing to try anything. I'm about to blow up the machine and reinstall... but would like any suggestions.
That's the expected behavior if a firewall restricting unsolicited inbound traffic were enabled. Perhaps Dell's shipping images with the XP firewall enabled. That's a good default, and will become the norm once SP2 is included. To disable XP's firewall,
see this article. But don't connect directly to the Internet without firewall protection.
Do you know if XP's firewall is turned off when you boot into SAFE MODE w/ NETWORKING? I only have access to this computer via winVNC and when I booted it into SAFE MODE I already check that option and it was unchecked (or no firewall enabled).
I didn't know that it was disabled in Safe Mode...but then, prior to SP2, the firewall has to be enabled in the distributed image, because it's not enabled in the MS distribution!
Given all the symptoms (VNC only in safe mode, ping only in safe mode), I'd say it's off - but that's based on your data.
The only time I've ever encountered a symptom like that, the culprit was a VPN client - Symantec's ("Raptor"'s successor), if I recall correctly. It was firewalling the machine regardless of the VPN client settings, and had to be uninstalled before things got sane. Is there anything like that installed?
I wish there was some program like that, then it would be obvious... but there isn't.
I even got down to the level of looking in the registry... RUN folder and looked for suspicious program loading. The only (and I checked every entry) thing that looked like it could be a culprit is DSENTRY.EXE. However, I removed that key and moved the .exe to another folder.
It actually took quite a while to find out that the VPN client was firewalling the machine at startup, without the user's knowledge and without the VPN client autostarting.
There's an enumeration of what starts in the two "safe modes" in HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal or \Network. I looked at mine, and both lists are mindbogglingly long. Since the culprit is probably a late-starting service, based on what you've eliminated so far, I wonder if it leaves any tracks in the event logs?
(edit) I wonder if comparing the output produced by
HijackThis when running in safe/network mode and normal mode might enable the process that's causing the symptom to be spotted.
jwatt
4446 Posts
112
0
Posted May 14th, 2004 04:00
Jim