|
Page 1 of 1
|
[ 8 posts ] |
|
TWGS & Norton Internet Security Problems
| Author |
Message |
|
CLStan
Sergeant
Joined: Fri Oct 04, 2002 2:00 am Posts: 7 Location: USA
|
Thank you to Rave for giving me access to this forum...I do not YET have a working TWGS server due to problems with TWGS interacting with Norton Internet Security 2003 (Firewall) and was hoping that there was a TWGS sysop out there that have ran into this problem.
Here is what I got. I'm running a Dynamic DNS Client (DNS2Go) which will point my domain (jabbs.d2g.com) to whatever IP my DSL modem happens to acquire from my ISP on bootup. When I try to telnet into TWGS Demo 1.0.55 via local loopback IP (127.0.0.1) OR directly to my LAN IP address of the machine running TWGS (in THIS case is 192.168.123.125), then there are no problems...I can see all text being sent from the TWGS system (mainly for this example...the login screen).
When I try to telnet into the TWGS system via the DynDNS (jabbs.d2g.com) OR directly to the Public IP assigned from my ISP on DSL bootup, then TWGS shows that there is an active connection...but I cannot see ANYTHING on my telnet window asking me to login. I have tried multiple Telnet clients from Microsoft Telnet to NetTerm and others...all with the same result. Seing that I can't get to it via the DynDNS address OR the Public IP, I can rule out the DynDNS being the problem.
I started some more digging through various logs and found the following entry in the Norton Internet Security 2003 logs: "A packet from jabbs1(192.268.123.125) with an invalid IP Total length of 152 was detected and blocked." I get one of these entries every time I try to open a telnet session to TWGS from outside my lan (DynDNS or Public IP). The Length it reports as too long changes...in the example above it was 152...but on this same day it also reported 151. Since the IP that it lists is 192.168.123.125, I must assume that it is being sent FROM my machine to the outside and not the other way around (else Norton would log the public IP). I can turn OFF/Disable my firewall (NIS) and I can telnet into the TWGS program with no problems. SO...I have isolated the access problems to NIS2k3.
Has anyone had this problem and what did you do to resolve it?
|
| Mon Oct 14, 2002 9:21 am |
|
 |
|
The WABBIT
Ensign
Joined: Fri Mar 02, 2001 3:00 am Posts: 227 Location: USA
|
For all firewalls you need to tell it that a certain program(s) can have access to/from the net. Some you are able to configure the firewall with the information needed. And others you are not. Personally, I don't know NIS. As Norton products are nothing more than a piece of crap. This is just my opinion. So no flames here, send them to the_wabbit1@shadowworldgame.com.
See if you can tell/setup NIS to let TWGS and maybe your telnet client to have access to and from the net. If that does not solve your problem. Then I say get red of NIS and get a real firewall program.
_________________ The WABBIT ICQ# 12988803
|
| Mon Oct 14, 2002 6:18 pm |
|
 |
|
Rave
Ambassador
Joined: Thu Feb 07, 2002 3:00 am Posts: 537 Location: USA
|
No problem. I've always been willing to do whatever it takes to see another server get started. Unfortunately, I can't really help with your problem because I don't know the first thing about Norton Internet Security. I ran a copy of NIS on a machine eight months to a year ago, and can't remember any TWGS-specific problems, but I couldn't even begin to remember how I set it up, if I had to make any specific settings changes or whatnot.
Honestly, my best advice? After using a dedicated machine as a firewall and NAT server, I simply went out and bought a 150 dollar LinkSys router for my home network. A good router is far superior to any firewall software... stopping incoming connections dead in their tracks before they even reach your machine. Many routers are as flexible if not more so than firewall packages, allowing you to block specific IP addresses, forward specific ports to specific machines, etc.
And if you really want to secure your system, there are routers available that include FLASH ROM based firewall software, extensive logging features, traffic monitoring, etc. I've never felt the need to use such a router on my home network, but if ultra security is important to you, it's something you may want to consider. BTW, most routers are preconfigured to allow you machine unlimited access to the internet, while limiting -all- inbound connections. On my router, allowing port 23 (telnet) incoming connections is as easy as pointing my web browser to the router's internal IP address, filling out a simple form and clicking on submit.
_________________ Lisa M. Cutler
aka Rave
|
| Mon Oct 14, 2002 7:34 pm |
|
 |
|
--drehmini--
1st Sergeant
Joined: Sun Sep 29, 2002 2:00 am Posts: 39
|
lol try doing http://www.noip.com this is the 1 i use
_________________ telnet://co.servegame.com
|
| Mon Oct 14, 2002 8:00 pm |
|
 |
|
CLStan
Sergeant
Joined: Fri Oct 04, 2002 2:00 am Posts: 7 Location: USA
|
I've looked at a lot of DNS redirectors and personally I like the Deerfield DNS2Go Client. (I can even have pages redirected to an "offline" site when I don't have the client running...but DNS redirecting isn't the issue here.)
System setup: DSL modem connected to 4 port Broadband Router (W/Nat & DHCP).
NIS settings: TWGS Full Access. Any Port, Any IP, Any machine.
Router: All ports going Outbound are open...Port 23 Inbound is open for telnet.
When NIS is Active...I can successfully access the TWGS game if I use local telnet 127.0.0.1 or the LAN IP (192.168.123.125). If I use an outside IP like the Public IP (68.17.151.229) or to the DNS2GO site (jabbs.d2g.com) then I get the following entry in my NIS log under the "firewall" section:
A packet from jabbs1(192.168.123.125) with an invalid IP Total length of 509 bytes was detected and blocked. IP Total length is greater than the packet size of 124 bytes.
Source IP address: jabbs1(192.168.123.125).
Destination IP address: jabbs.d2g.com(68.17.151.229).
Protocol: TCP.
In the example above...the IP Total length was 509 bytes...but in each log entry the number of bytes is different.
Any Ideas?
|
| Tue Oct 15, 2002 1:31 am |
|
 |
|
--drehmini--
1st Sergeant
Joined: Sun Sep 29, 2002 2:00 am Posts: 39
|
hmm try lowering ur secruity rating on ur firewall
but if this doesnt work Try mcafee i use that 1 and i don't have any probs.
_________________ telnet://co.servegame.com
|
| Tue Oct 15, 2002 3:12 pm |
|
 |
|
CLStan
Sergeant
Joined: Fri Oct 04, 2002 2:00 am Posts: 7 Location: USA
|
I deinstalled NIS and installed Zone. It seems to have fixed the problem with the empty telnet screens now.
Now to just talk my wife into letting me spend the money to register TWGS...grin.
|
| Wed Oct 16, 2002 12:22 pm |
|
 |
|
Shinare
Warrant Officer
Joined: Tue Aug 13, 2002 2:00 am Posts: 92 Location: USA
|
Well, I must agree WHOLE HEARTEDLY with Rave with her suggestion. I bought the same router she is referring to and have been VERY happy with it. It will stop cold any port requests that arent setup inside the router to be routed to a specific internal IP address. Plus it has a built in DHCP server and packet filtering, as well as many other routing options. It supports PPPoE and DHCP on the web side and works with just about any xDSL or Cable setup. All this with a very nice built in HTML server that you can connect to dirrectly to configure the router. Its a very good investment, and you can find them at Best Buy for $99. Just look for the LinkSys internet router. I'm no salesman for Linksys or have anything to do with them, but I am an accomplished Network Administrator working in the field for the past 11 years and I know a good piece of hardware when I see it.[:)]
_________________ ---telnet to telnet://bbs.angelichome.net and give my computer something to do!
[url="http://www.people.fas.harvard.edu/~pyang/base/allyourbase.swf"]ALL YOUR BASE ARE BELONG TO US![/url]
|
| Wed Oct 16, 2002 2:40 pm |
|
 |
|
|
Page 1 of 1
|
[ 8 posts ] |
|
Who is online |
Users browsing this forum: Google [Bot] and 12 guests |
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot post attachments in this forum
|
|