Showing posts with label network. Show all posts
Showing posts with label network. Show all posts

Sunday, May 12, 2013

Export and Import a readable DHCP scope

Export:
Readable:
netsh dhcp server \\SERVERNAME dump all > filename.txt
Unreadable:
netsh dhcp server \\SERVERNAME export d:\filename all

Full Export with policies (2012) using PS with Administrator Rights
Export-DhcpServer -ComputerName SERVERNAME -File "D:\filename.xml" -Force

Import:
Full Import with policies (2012) using PS with Administrator Rights
Import DhcpServer -ComputerName SERVERNAME -File "D:\filename.xml" -Force

for New 2003 server format
netsh exec filename.txt

for 2000 server format
netsh dhcp server import filename.txt all

Authorize:
1. Activate
2. Authorized from currently authorized DHCP server

Tuesday, December 20, 2011

VPN to remote network on same subnet as local network

Symptoms: 
You need to connect using VPN connection to remote client site and realize that you both using same IP subnet. You connect fine but can't access any resources on the remote subnet. Some people may suggest you to change one of the subnet, but you can't do that because both of subnet are office environment.


Cause:
It's network and route thing. Your PC think the remote IP is locally.


Solution:
You need to manually add routing for remote IP at your PC. You can do that using command ROUTE.
1. Connect to VPN site.


2. From command prompt run ROUTE PRINT to show status. In my case:

===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 11 09 26 33 75 ...... VIA Rhine II Fast Ethernet Adapter - Packet Scheduler Miniport
0x60004 ...00 53 45 00 00 00 ...... WAN (PPP/SLIP) Interface
===========================================================================
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0       10.10.10.1      10.10.10.9  21
          0.0.0.0          0.0.0.0      10.10.10.79     10.10.10.79  1
        10.10.8.0    255.255.252.0       10.10.10.9      10.10.10.9  20
       10.10.10.9  255.255.255.255        127.0.0.1       127.0.0.1  20
      10.10.10.79  255.255.255.255        127.0.0.1       127.0.0.1  50
   10.255.255.255  255.255.255.255       10.10.10.9      10.10.10.9  20
   10.255.255.255  255.255.255.255      10.10.10.79     10.10.10.79  50
        127.0.0.0        255.0.0.0        127.0.0.1       127.0.0.1  1
  2xx.2xx.2xx.2xx  255.255.255.255       10.10.10.1      10.10.10.9  20
        224.0.0.0        240.0.0.0       10.10.10.9      10.10.10.9  20
        224.0.0.0        240.0.0.0      10.10.10.79     10.10.10.79  1
  255.255.255.255  255.255.255.255       10.10.10.9      10.10.10.9  1
  255.255.255.255  255.255.255.255      10.10.10.79     10.10.10.79  1
Default Gateway:       10.10.10.79
===========================================================================
Persistent Routes:
  None

3. From here, we get information:
   - 10.10.10.9      my current IP
   - 10.10.10.79     my assigned VPN IP
   - 0x60004               my VPN interface
   - 2xx.2xx.2xx.2xx  I need to hide my client public IP

4. To manually add route run:
ROUTE ADD <TargetIP> MASK <Mask> <GatewayIP> METRIC <Metric> IF <InterfaceID>

so for my case if I want to add route to single IP 10.10.10.18 on remote site:
ROUTE ADD 10.10.10.18 MASK 255.255.255.255 10.10.10.79 METRIC 1 IF 0x6004

5. Run ROUTE PRINT again to make sure the new route listed
===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 11 09 26 33 75 ...... VIA Rhine II Fast Ethernet Adapter - Packet Scheduler Miniport
0x60004 ...00 53 45 00 00 00 ...... WAN (PPP/SLIP) Interface
===========================================================================
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0       10.10.10.1      10.10.10.9  21
          0.0.0.0          0.0.0.0      10.10.10.79     10.10.10.79  1
        10.10.8.0    255.255.252.0       10.10.10.9      10.10.10.9  20
       10.10.10.9  255.255.255.255        127.0.0.1       127.0.0.1  20
      10.10.10.18  255.255.255.255      10.10.10.79     10.10.10.79  1
      10.10.10.79  255.255.255.255        127.0.0.1       127.0.0.1  50
   10.255.255.255  255.255.255.255       10.10.10.9      10.10.10.9  20
   10.255.255.255  255.255.255.255      10.10.10.79     10.10.10.79  50
        127.0.0.0        255.0.0.0        127.0.0.1       127.0.0.1  1
  2xx.2xx.2xx.2xx  255.255.255.255       10.10.10.1      10.10.10.9  20
        224.0.0.0        240.0.0.0       10.10.10.9      10.10.10.9  20
        224.0.0.0        240.0.0.0      10.10.10.79     10.10.10.79  1
  255.255.255.255  255.255.255.255       10.10.10.9      10.10.10.9  1
  255.255.255.255  255.255.255.255      10.10.10.79     10.10.10.79  1
Default Gateway:       10.10.10.79
===========================================================================
Persistent Routes:
  None

Or You can use Portable GUI Application NetRouteView from nirsoft.net to show and manipulating your windows routing table.

Thursday, December 15, 2011

Find Old Network Card not show under Device Manager

Symptoms: 
Popup error while setting IP
The IP address XXX.XXX.XXX.XXX you have entered for this network adapter is already assigned to another adapter Name of adapter. Name of adapter is hidden from the network and Dial-up Connections folder because it is not physically in the computer or is a legacy adapter that is not working. If the same address is assigned to both adapters and they become active, only one of them will use this address. This may result in incorrect system configuration. Do you want to enter a different IP address for this adapter in the list of IP addresses in the advanced dialog box?

But cannot find this old hidden device to remove even you already enabled show hidden device in Device Manager

Cause:
Show hidden devices option in the Device Manager (View > Show hidden devices) does not always show the old NIC (ghosted adapter) to which that IP Address is assigned.

Solution:
From cmd prompt:
    set devmgr_show_nonpresent_devices=1

After that make sure in Device Manager:
    View > Show Hidden Device        Checked

Should show dimmed network adapter under network manager group.

Note:
For Some old OS, you may doing by add System Variable:
- In the System variables section, click New.
- Set the Variable name to devmgr_show_nonpresent_devices and set the Variable value to 1 to enable the parameter

Thursday, September 15, 2011

Excel 2003 opens slower across the network

Symptoms:
After you install MS11-021 and the Office File Validation (OFV) Add-in for Office 2003 (KB 2501584), workbooks stored in a network location open slower over the network in Excel 2003 than they did without the OFV installedcompare to open from local drive.

Cause:
The OFV reads the file to determine whether the file is trustworthy before it opens the file. When this is done over the network it reduces performance because of the network traffic when reading in the parts of the workbook.

Solution:
You can use the EnableOnLoad registry entry to configure how you want Excel to handle opening workbooks for the OFV. By default, the EnableOnLoad entry is not present in the Windows registry.


  1. Start regedit

  2. Locate HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\

  3. Add New Key: Excel

  4. Under Excel, add New Key: Security

  5. Under Security, add New Key: FileValidation

  6. Under FileValidation, add DWORD Value: EnableOnLoad with default value is 0 which disables the validation.

Or you can create a reg files contain below text and execute them

Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Excel\Security\FileValidation]"EnableOnLoad"=dword:00000000


More Info: http://support.microsoft.com/kb/2570623

Wednesday, May 18, 2011

Old DHCP Servers appear in the list of Authorized servers

Symptoms:
1. You may see the old server’s name still listed when you view DHCP Authorized servers
2. You may get the following error: "There is no such object on the server” when tried to unauthorized

Solution:
Remove the objects from Active Directory using ADSIEDIT:
1. Start Adsiedit.msc.
2. Open the configuration Container.
3. Expand Services.
4. Expand Net Services.
5. On the right hand side, find a record named CN=DHCPRoot
6. Right Click the CN=DhcpRoot entry and then click Properties
7. Highlight DhcpServers Attribute and click Edit
8. Highlight the entry with the old Domain name and click Remove from DHCPServers Attribute. Click OK to close DHCPServers editor’s screen
9. Once deleted the DHCPServers value will be “not set"
10. Save the change by clicking OK and close Adsiedit.
11. Restart the DHCP server service
12. run the following command: “Netsh DHCP show server” to check
13. If the servers are still listed, run the command “netsh DHCP delete server ServerFQDN ServerIPAddress”

Monday, June 21, 2010

Command to Reset Winsock and/or TCP/IP

Symptoms:
After install/uninstall some program or affected by trojan, we cannot access network/internet while in the good network link status

Cause:
Some Winsock catalog missing/error

Solution:
To reset winsock:
netsh winsock reset

To reset TCP/IP:
netsh int ip reset

Both will rewrites the registry back to default state, then restart to apply

This command avaliable since windows 2000

Tuesday, June 8, 2010

Reset / reloaded DNS cache table

Symptoms:
If your a mobile user and commonly switch profile between many places, you could find problem while accessing some sites using URL name address but directly their IP address

Cause:
The DNS cache table still attached to old gateway network profile

Solution:
if manualy Repair Network Option doesn't work

To unload all cache:
ipconfig /flushdns

to reload new:
ipconfig /registerdns

Thursday, March 12, 2009

Prevent the network adapter from detecting a link state

To prevent the network adapter from detecting a link state, follow these steps.

Note The NetBEUI protocol and the IPX protocol do not support Media Sensing.

1. Start Registry Editor.
2. Locate the following registry subkey:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters

3. Add the following registry entry to the Parameters subkey:

Name: DisableDHCPMediaSense
Data type: REG_DWORD (Boolean)
Value: 1

Note This entry controls the behavior of Media Sensing. By default, Media Sensing events trigger a DHCP client to take an action. For example, when a connect event occurs, the client tries to obtain a lease. When a disconnect event occurs, the client may invalidate the interface and routes. If you set this value data to 1, DHCP clients and non-DHCP clients ignore Media Sensing events.

4. Restart the computer.

Note Microsoft Windows Server 2003 supports Media Sensing when it is used in a server cluster environment. By default, however, Media Sensing is disabled in a Windows Server 2003-based server cluster, and the DisableDHCPMediaSense registry entry has no effect. In Windows Server 2003 Service Pack 1 (SP1), the DisableClusSvcMediaSense registry entry was introduced. You can use this registry entry to enable Media Sensing on the Windows Server 2003-based nodes of a server cluster. The details of the DisableClusSvcMediaSense registry entry are as follows:

Key: HKEY_LOCAL_MACHINE\Cluster\Parameters
Name: DisableClusSvcMediaSense
Data type: REG_DWORD (Boolean)
Default value: 0

By default, the DisableClusSvcMediaSense entry is set to 0. When this entry is set to 0, Media Sensing is disabled. If you set the DisableClusSvcMediaSense entry to 1, you can use the DisableDHCPMediaSense entry to enable Media Sensing. This behavior matches the behavior of a Microsoft Windows 2000 Server cluster environment.

More info: http://support.microsoft.com/kb/239924/

Wednesday, January 28, 2009

The registry key for a TCP IP printer port

The registry key for a TCP IP printer port looks like this :

Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Monitors\Standard TCP/IP Port\Ports]
"StatusUpdateInterval"=dword:0000000a
"StatusUpdateEnabled"=dword:00000001

;all defaults : RAW, port 9100

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Monitors\Standard TCP/IP Port\Ports\IP_1.92.1.2]
"Protocol"=dword:00000001
"Version"=dword:00000001
"HostName"=""
"IPAddress"="1.92.1.2"
"HWAddress"=""
"PortNumber"=dword:0000238c
"SNMP Community"="public"
"SNMP Enabled"=dword:00000000
"SNMP Index"=dword:00000001

;customized: LPR, LPR Queue Name, port 515

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Monitors\Standard TCP/IP Port\Ports\IP_192.168.1.123]
"Protocol"=dword:00000002
"Version"=dword:00000001
"HostName"=""
"IPAddress"="192.168.1.123"
"HWAddress"=""
"PortNumber"=dword:00000203
"SNMP Community"="public"
"SNMP Enabled"=dword:00000000
"SNMP Index"=dword:00000001
"Queue"="this_is_a_user_defined_lpr_ue"
"Double Spool"=dword:00000000

Tuesday, January 27, 2009

Symptoms:
Users who would like to prevent worms which execute without any user interaction using an “AutoRun.inf” file, can disable the Windows AutoRun feature completely with the help of the Windows group policy editor (Gpedit.msc). This would be helpful to stop USB virus spreading.

If you want to disable using GPO for all clients under Active Directory, follow instruction to access that http://iwan-it-admin-tips.blogspot.com/2009/01/domain-group-policies-edit.html

Solution:
Group Policy
>Local Computer Policy
>>Computer Configuration
>>>Administrative Templates
>>>>System
>>>>>Turn off Autoplay - Enabled

Do the same for User Configuration

For AD:
Group Policy Object Editor
>Default Domain Controllers Policy [sever name] Policy

>>Computer Configuration
>>>Administrative Templates
>>>>System
>>>>>Turn off Autoplay - Enabled

Do the same for User Configuration

Friday, January 23, 2009

Remotely Adding Firewall Exception List

Purposes:
You want to add Firewall Exception List under Client PC remotely

Solution:
1. Make sure you can remote registry Client PC
2. Open regedit.exe
3. File > Connect Remote Registry...
4. Browse your Client PC Name
5. Add this entry: (in this sample I add Radmin access)
[HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"4899:TCP"="4899:TCP:LocalSubNet:Enabled:Radmin"

6. To Enable Open File and Sharing Access
[HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP"="139:TCP:*:Enabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:*:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:*:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:*:Enabled:@xpsp2res.dll,-22002"


7. To Enable Disable Firewall, using this Key
[HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall"=dword:00000001
"DisableNotifications"=dword:00000000
"DoNotAllowExceptions"=dword:00000000