Quantcast
Channel: Forefront Edge Security – DirectAccess, UAG and IAG フォーラム
Viewing all 1485 articles
Browse latest View live

DirectAccess client - problem re-connecting clients

$
0
0

Hello experts,

I have a fully patched surface pro3 running Windows Enterprise 8.1.  It is connecting to DirectAccess 2012 R2 fully patched, including limited release patches for DirectAccess.

Every time I leave the surface pro for 10 minutes, its screen goes black (possibly default power saving scheme).  When I bring it back online, it tries to re-connect to DirectAccess workplace connection but stays connecting.  To recover, I have to disconnect the wi-fi and re-connect before it will re-establish a connection.

Is there any solution to this, as it will annoy our Surface users if they have to do this each time.  I appreciate a connection needs to be re-established, but having to tweak the wi-fi each time is a bit of additional labor which we have to communicate out and I don't think this exactly an enterprise solution.

Any advice would be appreciated, I don't really want to roll out non-power saving policies for this.

Thanks, Matt.


DirectAccess not connecting on Windows 10 Enterprise

$
0
0

Hi,

Ive got a Windows 10 Enterprise machine setup in my domain. The domain controller has DirectAccess enabled configured and installed however i have an issue.

When connecting to the server from another location using DirectAccess the computer will connect to the wireless network and then attempt to connect to the server. However when connecting to the server it stops after 5 secs and just stays with no network connection available however other computers (that are not on the domain) stay connected to the internet

How do i resolve this issue? 


Jordan Harvey


Configuring Load balancing of DA Servers with NLB and a hardware load balancer

$
0
0
Hi,

 I have 2 DA servers, both with 2 NICs (1 in DMZ and 1 on the internal network). The second server has had the DA role installed, but not configured. I want to configure load balancing in the following manner:
- External\DMZ NIC using NLB
- Interbal NIC using a hardware load balancer

All of the GUI and PowerShell options I've seen want to use the same load balancing method for both the internal and external interface, what I don't know is how to configure load balancing to accomodate a mixed load balancing setup?

In addition, I'm looking at using manage out with limited isatap applying to a single server, this server will then be used to RDP, remote assist, etc clients. I'm planning on following the process listed here: https://www.packtpub.com/books/content/configuring-manage-out-directaccess-clients. The manage out server will be on the same VLAN as my DA servers and clients connect to the DA servers via ip-https. What I would like to know is if I need to open any additional ports between my manage out server to the DA clients? My understanding is that using limited isatap, the manage out server's ipv6 traffic is routed via the DA servers and encapsulated in ipv4 over the internet, so therefore no additional ports need to be open, other than say 3389 on the DA client?

 Thanks

IT Support/Everything

Server 2012 DirectAccess - Both NIC's show as Domain Network

$
0
0
I never found an official answer to this issue we had and was wondering if anyone here knows the best way to make the external NIC public.

During setup of DirectAccess 2012 we had to create a firewall rule to force the External NIC to be Public.  I saw many people commenting on ways to force it to Public but none seemed to work except for the firewall rule.

So my question.  What is the proper way to make my External NIC Public.  If it is the firewall rule how did you setup the rule?  We blocked outgoing TCP to our two consecutive external IP's.



I personally believe the firewall rule we created is causing Teredo to not work correctly.  See my previous post.



Thank you in advance


UAG Cookie dependency

$
0
0

Hi,

I have a web API service accessed through the UAG endpoint.

Would like to make the service available to different client application. But the service accessible only from the Browser.

The reason being UAG expect the cookie sent from the client to process the request. Is their a way in UAG setup to overcome this problem

Thanks in advance

Selva 

Manage Out DirectAccess (Server 2012) using native IPv6

$
0
0

I have 2 Windows 2012 DirectAccess servers: 1 at a primary site and 1 at a secondary site. I want to be able to setup a "manage out" scenario for a few DirectAccess clients. How would I do this in a multisite environment if Microsoft recommends native IPv6 instead of ISATAP? I haven't been able to find any documentation on how to do this when two sites are involved. Any help is appreciated. 

Thanks,

Chris

Not able to install Forefront UAG client components with IE11 on Windows 10

$
0
0

Hi there,

Does anyone have a clue why I am not able to install the Forefront UAG client components while using Internet Explorer 11 and Windows 10? It looks like there are additional security settings that have been changed on the os level. In Windows 8.1 everything works fine!

The bar that should have popped up requesting the installation of the activex component just does not show up. In the JavaScript console I see quite a few access denied messages. Also, inspecting one of the exceptions, it mentions something like "component cannot be created by automation layer".

Being able to use the Forefront UAG application portal is extremely critical to my daily workflow. I hope there is a simple remedy available. In the meanwhile I will need to keep Windows 8.1 around.

DirectAccess connection issue after sleep

$
0
0

I've recently setup DirectAccess for a primary school for students that take their netbooks home. At this stage, they are on a force tunnel setup and we are using it to push students through the schools filtered ISP connection. We have the SMB port blocked at the DA server so that students can't browse the network from home.

At the moment, our test group of users (approx. 5) is working well, with 1 exception.  The students are used to putting their netbooks to sleep when they leave school, and turning them back on when they get home.  Sometimes the connection doesn't get established and they are left with a 'Proxy not responding' error when trying to browse.  The connection status shows they are connected, and on the DA server it all looks o.k.  I've also noticed that it could take around 30 seconds to a minute to make the connection.

At this stage, students are being advised to restart their machine if they have connection issues, but it seems ridiculous to have to do this all the time.  We are projecting in the coming weeks that we will have around 400 netbooks using this method when it becomes adoptive.

Our current setup is through a DMZ (TMG 2010) that pushes traffic to the DA server (NLS and DA on the same virtual machine) within our network.  We are running DA on a 2012R2 server.  The virtual machine has 2 CPU's assigned and approx. 6GB if RAM, but it doesn't look to be under any load.  Our same TMG DMZ server also pushes a VPN to staff through to a NPS server internally.  Their connection takes around 3-5 seconds to be established, although they have to manually double click an icon that points to their rasphone.pbk file.

Can anyone suggest anything to improve the connection speed and reliability of the DA service?


DirectAccess - Not Configured

$
0
0

Hi Everyone,

Brief description. I am attempting to implement DirectAccess in a small business and am currently getting a "Direct Access - Not configured" status when running the commandnetsh dns show state. I have all green check marks on DA server and have even checked the Name Resolution Policy in the GPO that was created to confirm that they were there. Any ideas on why I may be having this issue? Client is running Windows 10, firewall enabled, domain controller is 2008 R2 and all other servers are 2012 R2. Thanks ahead of time for any responses!

JBTechnet

Directaccess - Inside Corporate Network

$
0
0
Currently testing out deployment of DirectAccess and have my one client computer saying itsInside of the Coporate Network (when its not) after a show netsh dns show state. Obviously this is a NLS error, but striking out on what the possible causes could be. The NLS is currently on the DirectAccess server. Any ideas/assistance would be appreciated!

DirectAccess on Server 2012 R2 with Single NIC behind NAT on IPv4 only Corporate Network Results in "DNS Not Working Properly"

$
0
0

I hit this problem at a customer site and can re-produce it in a simple lab.  Lab environment: servers:

  • 1x Server 2012 R2 DC and DNS server - DC1 - 10.0.0.1
  • 1x Server 2012 R2 DirectAccess (DA) server - DA1 - 10.0.0.100

Servers are running "Update" (KB2919355) and following DA hotfixes:

  • KB2929930
  • KB2966087

I configured DA (via advanced wizard) as follows:

  • DA and remote access
  • AD group
  • directaccess-webprobehost DNA (A) record pointing to 10.0.0.100
  • behind an edge device (with a single network adapter)
  • SSL certificate from enterprise root CA issued to directaccess.contoso.com
  • NLS on remote server using https://nls.corp.contoso.com
  • DNS: corp.contoso.com = 10.0.0.1; nls.corp.contoso.com = ""
  • DNS suffix search list = corp.contoso.com

The DNS server validates successfully in the configuration UI.

With this configuration, I get a static IPv6 address of fd79:7a37:cbd9:3333::1/128 assigned to the NIC

The operations status is all green apart from DNS which displays the following error:

"DNS: Not Working Properly"

Error:

None of the enterprise DNS servers fd79:7a37:cbd9:7777::a00:1 used by DirectAccess clients for name resolution are responding. This might affect DirectAccess client connectivity to corporate resources.

Causes:

Enterprise DNS servers fd79:7a37:cbd9:7777::a00:1 are not responding.

I can, however ping fd79:7a37:cbd9:7777::a00:1 (which is the DNS64 translation of 10.0.0.1)

I would like to know what checks are failing as there are no failures in Event Viewer.

I have come across forums where people have the same issue and fix it by specifying the local IP (in this case 10.0.0.100) as the DNS server, however Richard Hicks has confirmed with me that the DNS server should be set to the DNS server, not the DA server's IP.

Problem On DA Dashboard

$
0
0

hello

I have installed and configured Remote Access management. My Direct access is working fine on Client machine also i have run the DA troubleshooting tool all the test got executed successfully. But the thing is that I am getting error on my DA server. When i am opening Remote Access Management Console and going on Dashboard one of the error is on Configuration status "configuration cannot be retrieved from the  domain Controller". I thought of it would be resolve after some time or i have an logon problem. But this wasn't  an issue. the issue is something else. Can anyone help me out. the answer will be appreciable if it will help me out.

thanks.

UAG 2010/Exchange 2013 Publish Apps

$
0
0

Hi all,

I've been looking for quite sometime at how to publish apps via UAG for Exchange 2013. Does anyone have any documentation on this at all?

Or if anyone is aware of how to do it, that would be good! :)

Thanks

Craig

Direct Access and 2FA

$
0
0

----=====REPOST FROM SECURITY BOARD=====----

Greetings,

I have a quick question.  When using DA with 2FA, if I cancel the connection attempt when I first login, I have to lock / unlock my PC to get the authentication pop up again. This is not always successful.

Is there any other way of achieving this?  I am happy enough to lock / unlock the PC (or reboot), I got to thinking if there is a more elegant way of doing this. Does anyone know if you can create a shortcut to the application (I haven't been able to identify it as of yet) that I could place on the desktop?

I have looked at posts which advise to restart the IPhelper service, but this appears to be unsupported / not recommended by Microsoft.

TIA for any help you can give.

Technologies:  Windows 7, Server 2012 R2.

Thanks

G


Regards Gordie

DirectAccess - Computer fails to authenticate, error 0xC000006A

$
0
0

I have a computer that was successfully connecting to our AD network via DirectAccess 2012. Yesterday I had to do a full system recovery on the computer. After rebooted it would not connect to DirectAccess. In the security log of the direct access server I see the error:

An IPsec extended mode negotiation failed. The corresponding main mode security association has been deleted.

Local Endpoint:
Principal Name:host/DIRECTACCESS.ad.milwaukee.gov
Network Address:2002:c7c4:5439::c7c4:5439
Keying Module Port:500

Remote Endpoint:
Principal Name:-
Network Address:2002:c7c4:5439:1000:c144:a2f4:e02f:b1c4
Keying Module Port:500

Additional Information:
Keying Module Name:AuthIP
Authentication Method:NTLM V2
Role:Responder
Impersonation State:Enabled
Quick Mode Filter ID:489337

Failure Information:
Failure Point:Local computer
Failure Reason:IKE authentication credentials are unacceptable

State:Sent second (SSPI) payload

On our domain controller I see this message:

The computer attempted to validate the credentials for an account.

Authentication Package:MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon Account:CHAPAN-HOME$
Source Workstation:CHAPAN-HOME
Error Code:0xC000006A

I turned on the CAPI2 log on the direct access server and it appears there is no problem with the certificate the computer is using, but for some reason the computer cannot authenticate to the domain.


Error:NameresolutionFailed

$
0
0

Hi All

I have an Direct Access 2012 R2 installation which have some problems in the initial setup.

Setup:
-Edge with two public ip's
-Non ipv6 on intranett
-NLS server on DA server
-Suport for win and win8
-Using internal CA server for alle certificates
-publicly available CRL is ok (its hosted on the DA server)

The remote clients appear in DA server console as connected with IPHTTPS, but when I run get-DAConnectionstatus I recieve Error:NameResolutionFailed

I have rerun the Step 3 wizard and saw that the IPv6 adress that was automaticly entered changed to a correct ipv4 address for the internal DNS server.

I will attach the DCA logs as well. 

RED: Corporate connectivity is not working.
Microsoft DirectAccess Connectivity Assistant is not properly configured. Please contact your administrator if this problem persists.
22/6/2015 12:42:23 (UTC)


C:\Windows\system32\LogSpace\{B99EDDED-02ED-4E74-8DCC-C02A0A688643}>ipconfig /all

Windows IP-konfigurasjon

   Vertsnavn   . . . . . . . . . . . : PB5236
   Prim‘r DNS-suffiks  . . . . . . . : hipad.no
   Nodetype  . . . . . . . . . . . . : Hybrid
   IP-ruting aktivert  . . . . . . . : Nei
   WINS Proxy aktivert . . . . . . . : Nei
   S›keliste for DNS-suffiks . . . . : hipad.no

Tr†dl›st LAN-kort Tr†dl›s nettverkstilkobling:

   Tilkoblingsspesifikt DNS-suffiks  :
   Beskrivelse   . . . . . . . . . . : Intel(R) Centrino(R) Advanced-N 6205
   Fysisk adresse  . . . . . . . . . : A0-88-B4-5C-CD-44
   DHCP aktivert . . . . . . . . . . : Ja
   Automatisk konfigurasjon aktivert : Ja
   Koblingslokal IPv6-adresse. . . . : fe80::a885:813a:4294:43a0%12(Foretrukket)
   IPv4-adresse. . . . . . . . . . . : 172.20.10.10(Foretrukket)
   Nettverksmaske . . . . . . . . . .: 255.255.255.240
   Leieavtale inng†tt. . . . . . . . : 22. juni 2015 14:41:34
   Leieavtale utl›per. . . . . . . . : 23. juni 2015 14:27:14
   Standard gateway . . . . . . . . .: 172.20.10.1
   DHCP-server . . . . . . . . . . . : 172.20.10.1
   DHCPv6-IAID . . . . . . . . . . . : 211847348
   DHCPv6 klient-DUID. . . . . . . . : 00-01-00-01-1D-10-40-86-5C-26-0A-64-55-7E
   DNS-servere . . . . . . . . . . . : 172.20.10.1
   NetBIOS over Tcpip. . . . . . . . : Aktivert

Ethernet-kort Lokal tilkobling:

   Medietilstand . . . . . . . . . . : Medium frakoblet
   Tilkoblingsspesifikt DNS-suffiks  : Hipad.no
   Beskrivelse   . . . . . . . . . . : Intel(R) 82579LM Gigabit Network Connection
   Fysisk adresse  . . . . . . . . . : 5C-26-0A-64-55-7E
   DHCP aktivert . . . . . . . . . . : Ja
   Automatisk konfigurasjon aktivert : Ja

Tunnelkort iphttpsinterface:

   Tilkoblingsspesifikt DNS-suffiks  :
   Beskrivelse   . . . . . . . . . . : iphttpsinterface
   Fysisk adresse  . . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP aktivert . . . . . . . . . . : Nei
   Automatisk konfigurasjon aktivert : Ja
   IPv6-adresse. . . . . . . . . . . : 2002:b91a:8207:1000:e5e6:6741:62f7:9527(Foretrukket)
   Midlertidig IPv6-adresse. . . . . : 2002:b91a:8207:1000:d847:3e9c:f144:57dd(Foretrukket)
   Koblingslokal IPv6-adresse. . . . : fe80::e5e6:6741:62f7:9527%13(Foretrukket)
   Standard gateway . . . . . . . . .:
   NetBIOS over Tcpip. . . . . . . . : Deaktivert

C:\Windows\system32\LogSpace\{B99EDDED-02ED-4E74-8DCC-C02A0A688643}>netsh int teredo show state
Teredo-parametere
---------------------------------------------
Type                    : disabled
Servernavn             : da.domain.com (Group Policy)
Oppdateringsintervall for klient : 30 sekunder
Klientport              : unspecified
Tilstand                : offline
Feil                    : ingen


C:\Windows\system32\LogSpace\{B99EDDED-02ED-4E74-8DCC-C02A0A688643}>netsh int httpstunnel show interfaces

Grensesnitt IPHTTPSInterface (Group Policy)  Parametere
------------------------------------------------------------
Rolle                       : client
URL                        : https://da.domain.com:443/IPHTTPS
Siste feilkode            : 0x0
Grensesnittstatus           : IPHTTPS-grensesnitt er aktivt


C:\Windows\system32\LogSpace\{B99EDDED-02ED-4E74-8DCC-C02A0A688643}>netsh dns show state

Tabellalternativer for navnel›sningspolicy
--------------------------------------------------------------------

Virkem†te ved sp›rringsfeil                : G† alltid tilbake til LLMNR og NetBIOS
                                        hvis navnet ikke finnes i DNS eller
                                        hvis DNS-serverne ikke kan n†s
                                        n†r du er p† et privat nettverk

Virkem†te for sp›rringsl›sning             : L›s bare IPv6-adresser for navn

Virkem†te for nettverksplassering             : La nettverks-ID bestemme n†r innstillinger
                                        for direkte tilgang skal brukes

Maskinplassering                      : Utenfor firmanettverket

Innstillinger for direkte tilgang                : Konfigurert og aktivert

DNSSEC-innstillinger                       : Ikke konfigurert


C:\Windows\system32\LogSpace\{B99EDDED-02ED-4E74-8DCC-C02A0A688643}>netsh name show policy

Tabellinnstillinger for DNS-navnel›singspolicy

Innstillinger for nls.domain.com
----------------------------------------------------------------------
Sertifiseringsmyndighet                 :
DNSSEC (validering)                     : disabled
DNSSEC (IPsec)                          : disabled
DirectAccess (DNS-servere)              :
DirectAccess (IPsec)                    : disabled
DirectAccess (Proxy-innstillinger)           : Bruk standard nettleserinnstillinger



Innstillinger for .hipad.no
----------------------------------------------------------------------
Sertifiseringsmyndighet                 :
DNSSEC (validering)                     : disabled
DNSSEC (IPsec)                          : disabled
DirectAccess (DNS-servere)              : fd2d:5548:a18f:7777::ac13:30b
DirectAccess (IPsec)                    : disabled
DirectAccess (Proxy-innstillinger)           : Omg† proxy




C:\Windows\system32\LogSpace\{B99EDDED-02ED-4E74-8DCC-C02A0A688643}>netsh name show effective

Effektive tabellinnstillinger for DNS-navnel›singspolicy


Innstillinger for nls.domain.com
----------------------------------------------------------------------
Sertifiseringsmyndighet                 :
DNSSEC (validering)                     : disabled
IPsec-innstillinger                          : disabled
DirectAccess (DNS-servere)              :
DirectAccess (Proxy-innstillinger)           : Bruk standard nettleserinnstillinger



Innstillinger for .hipad.no
----------------------------------------------------------------------
Sertifiseringsmyndighet                 :
DNSSEC (validering)                     : disabled
IPsec-innstillinger                          : disabled
DirectAccess (DNS-servere)              : fd2d:5548:a18f:7777::ac13:30b
DirectAccess (Proxy-innstillinger)           : Omg† proxy




C:\Windows\system32\LogSpace\{B99EDDED-02ED-4E74-8DCC-C02A0A688643}>netsh int ipv6 show int level=verbose

Grensesnitt Loopback Pseudo-Interface 1 Parametere
----------------------------------------------
IfLuid                             : loopback_0
IfIndex                            : 1
Tilstand                           : connected
Metrikk                            : 50
Koblings-MTU                       : 4294967295 byte
Tid for † n† m†let                 : 24000 ms
Grunntid for † n† m†let            : 30000 ms
Omsendingsintervall                : 1000 ms
DAD-sendinger                      : 0
Omr†deprefikslengde                : 64
Omr†de-ID                          : 1
Videresending                      : disabled
Annonsering                        : disabled
Nabooppdagelse                     : disabled
Oppdagelse av naboutilgjengelighet : disabled
Ruters›k                           : enabled
Administrert adressekonfigurasjon  : disabled
Annen tilstandsfull konfigurasjon  : disabled
Svak vert-sendinger                : disabled
Svak vert-mottak                   : disabled
Bruk automatisk metrikk            : enabled
Ignorer standardruter              : disabled
Annonsert ruterlevetid         : 1800 sekunder
Annonsert standardrute            : disabled
Gjeldende hoppgrense                  : 0
Tvungne ARPND-oppv†kningsm›nstre       : disabled
Retningsstyrte MAC-oppv†kningsm›nstre      : disabled

Grensesnitt Tr†dl›s nettverkstilkobling Parametere
----------------------------------------------
IfLuid                             : wireless_0
IfIndex                            : 12
Tilstand                           : connected
Metrikk                            : 25
Koblings-MTU                       : 1500 byte
Tid for † n† m†let                 : 23000 ms
Grunntid for † n† m†let            : 30000 ms
Omsendingsintervall                : 1000 ms
DAD-sendinger                      : 1
Omr†deprefikslengde                : 64
Omr†de-ID                          : 1
Videresending                      : disabled
Annonsering                        : disabled
Nabooppdagelse                     : enabled
Oppdagelse av naboutilgjengelighet : enabled
Ruters›k                           : enabled
Administrert adressekonfigurasjon  : enabled
Annen tilstandsfull konfigurasjon  : enabled
Svak vert-sendinger                : disabled
Svak vert-mottak                   : disabled
Bruk automatisk metrikk            : enabled
Ignorer standardruter              : disabled
Annonsert ruterlevetid         : 1800 sekunder
Annonsert standardrute            : disabled
Gjeldende hoppgrense                  : 0
Tvungne ARPND-oppv†kningsm›nstre       : disabled
Retningsstyrte MAC-oppv†kningsm›nstre      : disabled

Grensesnitt iphttpsinterface Parametere
----------------------------------------------
IfLuid                             : tunnel_5
IfIndex                            : 13
Tilstand                           : connected
Metrikk                            : 50
Koblings-MTU                       : 1280 byte
Tid for † n† m†let                 : 22500 ms
Grunntid for † n† m†let            : 30000 ms
Omsendingsintervall                : 1000 ms
DAD-sendinger                      : 1
Omr†deprefikslengde                : 64
Omr†de-ID                          : 1
Videresending                      : disabled
Annonsering                        : disabled
Nabooppdagelse                     : enabled
Oppdagelse av naboutilgjengelighet : enabled
Ruters›k                           : enabled
Administrert adressekonfigurasjon  : disabled
Annen tilstandsfull konfigurasjon  : disabled
Svak vert-sendinger                : disabled
Svak vert-mottak                   : disabled
Bruk automatisk metrikk            : enabled
Ignorer standardruter              : disabled
Annonsert ruterlevetid         : 1800 sekunder
Annonsert standardrute            : disabled
Gjeldende hoppgrense                  : 0
Tvungne ARPND-oppv†kningsm›nstre       : disabled
Retningsstyrte MAC-oppv†kningsm›nstre      : disabled

Grensesnitt Lokal tilkobling Parametere
----------------------------------------------
IfLuid                             : ethernet_6
IfIndex                            : 11
Tilstand                           : disconnected
Metrikk                            : 5
Koblings-MTU                       : 1500 byte
Tid for † n† m†let                 : 33000 ms
Grunntid for † n† m†let            : 30000 ms
Omsendingsintervall                : 1000 ms
DAD-sendinger                      : 1
Omr†deprefikslengde                : 64
Omr†de-ID                          : 1
Videresending                      : disabled
Annonsering                        : disabled
Nabooppdagelse                     : enabled
Oppdagelse av naboutilgjengelighet : enabled
Ruters›k                           : enabled
Administrert adressekonfigurasjon  : enabled
Annen tilstandsfull konfigurasjon  : enabled
Svak vert-sendinger                : disabled
Svak vert-mottak                   : disabled
Bruk automatisk metrikk            : enabled
Ignorer standardruter              : disabled
Annonsert ruterlevetid         : 1800 sekunder
Annonsert standardrute            : disabled
Gjeldende hoppgrense                  : 0
Tvungne ARPND-oppv†kningsm›nstre       : disabled
Retningsstyrte MAC-oppv†kningsm›nstre      : disabled


C:\Windows\system32\LogSpace\{B99EDDED-02ED-4E74-8DCC-C02A0A688643}>netsh advf show currentprofile

Privat profil Innstillinger:
----------------------------------------------------------------------
Tilstand                              P
Brannmurpolicy                        BlockInbound,AllowOutbound
LocalFirewallRules                    I/T (bare GPO-lagre)
LocalConSecRules                      I/T (bare GPO-lagre)
InboundUserNotification               Aktiver
RemoteManagement                      Deaktiver
UnicastResponseToMulticast            Aktiver

Logging:
LogAllowedConnections                 Deaktiver
LogDroppedConnections                 Deaktiver
FileName                              %systemroot%\system32\LogFiles\Firewall\pfirewall.log
MaxFileSize                           4096

OK.


C:\Windows\system32\LogSpace\{B99EDDED-02ED-4E74-8DCC-C02A0A688643}>netsh advfirewall monitor show consec

Global Innstillinger:
----------------------------------------------------------------------
IPsec:
StrongCRLCheck                        0:Deaktivert
SAIdleTimeMin                         5min
DefaultExemptions                     ICMP
IPsecThroughNAT                       Aldri
AuthzUserGrp                          Ingen
AuthzComputerGrp                      Ingen

StatefulFTP                           Aktiver
StatefulPPTP                          Aktiver

Hovedmodus:
KeyLifetime                           480min,0sess
SecMethods                            DHGroup2-AES128-SHA256,DHGroup2-AES128-SHA1,DHGroup2-3DES-SHA1
ForceDH                               No

Kategorier:
BootTimeRuleCategory                  Windows-brannmur
FirewallRuleCategory                  Windows-brannmur
StealthRuleCategory                   Windows-brannmur
ConSecRuleRuleCategory                Windows-brannmur


Hurtigmodus:
QuickModeSecMethods                   ESP:SHA1-Ingen+60min+100000kb,ESP:SHA1-AES128+60min+100000kb,ESP:SHA1-3DES+60min+100000kb,AH:SHA1+60min+100000kb
QuickModePFS                          None

Sikkerhetstilordninger:

Hovedmodus SA ved 06/22/2015 14:42:24
----------------------------------------------------------------------
Lokal IP-adresse:                     2002:b91a:8207:1000:d847:3e9c:f144:57dd
Ekstern IP-adresse:                   2002:b91a:8208::b91a:8208
Auth1:                                ComputerCert
Auth2:                                UserNTLM
MM-tilbud:                            Ingen-AES128-SHA256
Informasjonskapselpar:                          8ba81fbcc6aecb99:3e482c009ff50fc1
Helsesertifikat:                      Nei

Hurtigmodus SA ved 06/22/2015 14:42:24
----------------------------------------------------------------------
Lokal IP-adresse:                     2002:b91a:8207:1000:d847:3e9c:f144:57dd
Ekstern IP-adresse:                   2002:b91a:8208::b91a:8208
Lokal port:                           Hvilken som helst
Ekstern port:                         Hvilken som helst
Protokoll:                            Hvilken som helst
Retning:                              Begge
QM-tilbud:                            ESP:SHA1-AES192+60min+100000kb
PFS:                                  Ingen


IPSec-statistikk
----------------

Aktive tilknytninger        : 1
Avlast sikkerhetstilknytninger : 0
Ventende n›kkelop.          : 0
N›kler lagt til             : 9
N›kler slettet              : 18
Omn›klinger                 : 0
Aktive tunneler             : 1
Skadete SPI-pakker          : 0
Pakker ikke dekryptert      : 0
Pakker ikke godkjent        : 0
Pakker med repetisjonsregistrering: 0
Sendte konfidensialitetsbyte: 20,384
Mottatte konfidensialitetsbyte : 46,248
Sendte godkjenningsbyte     : 24,920
Mottatte godkjenningsbyte   : 46,248
Overf›ringsbyte sendt       : 0
Overf›ringsbyte mottatt     : 0
Byte sendt i tunneler       : 24,920
Byte mottatt i tunneler     : 46,248
Avlastede byte sendt        : 0
Avlastede byte mottatt      : 0

OK.


C:\Windows\system32\LogSpace\{B99EDDED-02ED-4E74-8DCC-C02A0A688643}>Certutil -store my
my
================ Sertifikat 0 ================
Serienummer: 6c88b34e00000000741d
Utsteder: CN=Hipad Issuing Certification Authority, DC=hipad, DC=no
 Ikke før: 22.06.2015 11:42
 Ikke etter: 09.11.2016 14:22
Emne: TOM (DNS-navn=pb5236.hipad.no)
Ikke rotsertifikat
Mal: 1.3.6.1.4.1.311.21.8.13759381.10694260.3229619.8823333.5769967.38.14779166.12251370
Sertifikatnummer(sha1): 34 0b b9 03 4a bd ff 39 be 7c 2f fb ce d6 08 fe 04 de b1 ae
  Nøkkelbeholder = cbb8cae85203e88ac2d0f8790008898b_f60ebb01-f4bf-4460-adf9-a78f090afffc
  Enkelt beholdernavn: le-WirelessWindowsWorkstationAuthentication-3676b618-7d39-44ff-9a69-010b5e5bec3d
  Leverandør = Microsoft RSA SChannel Cryptographic Provider
Privatnøkkel kan IKKE eksporteres
Krypteringstest godkjent
CertUtil: -store-kommandoen er utført.

C:\Windows\system32\LogSpace\{B99EDDED-02ED-4E74-8DCC-C02A0A688643}>Systeminfo

Vertsnavn:                          PB5236
OS-navn:                            Microsoft Windows 7 Enterprise
OS-versjon:                         6.1.7601 Service Pack 1 Build 7601
OS-produsent:                       Microsoft Corporation
OS-konfigurasjon:                   Medlemsarbeidsstasjon
OS-buildtype:                       Multiprocessor Free
Registrert eier:                    Contoso
Registrert organisasjon:            Contoso
Produkt-ID:                         00392-918-5000002-85782
Opprinnelig installasjonsdato:      15.06.2015, 10:32:21
Oppstartstid for datamaskinen:      22.06.2015, 12:10:37
Systemprodusent:                    Dell Inc.
Systemmodell:                       Latitude E6420
Systemtype:                         x64-based PC
Prosessor(er):                      1 prosessor(er) installert.
                                    [01]: Intel64 Family 6 Model 42 Stepping 7 GenuineIntel ~2501 Mhz
BIOS-versjon:                       Dell Inc. A05, 24.05.2011
Windows-mappe:                      C:\Windows
Systemmappe:                        C:\Windows\system32
Oppstartsenhet:                     \Device\HarddiskVolume1
Nasjonal innstilling:               no;Norsk (bokm†l)
Inndataspr†k:                       no;Norsk (bokm†l)
Tidssone:                           (UTC+01:00) Amsterdam, Berlin, Bern, Oslo, Roma, Wien
Totalt fysisk minne:                8ÿ073 MB
Tilgjengelig fysisk minne:          6ÿ767 MB
Virtuelt minne: Maksimal st›rrelse: 16ÿ144 MB
Virtuelt minne: Tilgjengelig:       14ÿ247 MB
Virtuelt minne: I bruk:             1ÿ897 MB
Plassering(er) av sidevekslingsfil: C:\pagefile.sys
Domene:                             hipad.no
P†loggingsserver:                   I/T
Hurtigreparasjon(er):               252 hurtigreparasjon(er) installert.
                                    [01]: KB2849697
                                    [02]: KB2849697
                                    [03]: KB2849696
                                    [04]: KB2849696
                                    [05]: KB2841134
                                    [06]: KB2841134
                                    [07]: KB2670838
                                    [08]: KB2592687
                                    [09]: KB971033
                                    [10]: KB2425227
                                    [11]: KB2479943
                                    [12]: KB2484033
                                    [13]: KB2488113
                                    [14]: KB2491683
                                    [15]: KB2492386
                                    [16]: KB2505438
                                    [17]: KB2506014
                                    [18]: KB2506212
                                    [19]: KB2506928
                                    [20]: KB2507618
                                    [21]: KB2509553
                                    [22]: KB2511250
                                    [23]: KB2511455
                                    [24]: KB2515325
                                    [25]: KB2522422
                                    [26]: KB2529073
                                    [27]: KB2532531
                                    [28]: KB2533552
                                    [29]: KB2534111
                                    [30]: KB2536275
                                    [31]: KB2536276
                                    [32]: KB2541014
                                    [33]: KB2544893
                                    [34]: KB2545698
                                    [35]: KB2547666
                                    [36]: KB2552343
                                    [37]: KB2560656
                                    [38]: KB2563227
                                    [39]: KB2564958
                                    [40]: KB2567680
                                    [41]: KB2570947
                                    [42]: KB2574819
                                    [43]: KB2579686
                                    [44]: KB2584146
                                    [45]: KB2585542
                                    [46]: KB2603229
                                    [47]: KB2604115
                                    [48]: KB2618451
                                    [49]: KB2619339
                                    [50]: KB2620704
                                    [51]: KB2620712
                                    [52]: KB2621440
                                    [53]: KB2631813
                                    [54]: KB2633952
                                    [55]: KB2640148
                                    [56]: KB2644615
                                    [57]: KB2645640
                                    [58]: KB2647753
                                    [59]: KB2653956
                                    [60]: KB2654428
                                    [61]: KB2655992
                                    [62]: KB2656356
                                    [63]: KB2656373
                                    [64]: KB2656411
                                    [65]: KB2658846
                                    [66]: KB2659262
                                    [67]: KB2660075
                                    [68]: KB2660649
                                    [69]: KB2667402
                                    [70]: KB2676562
                                    [71]: KB2677070
                                    [72]: KB2679255
                                    [73]: KB2685811
                                    [74]: KB2685813
                                    [75]: KB2685939
                                    [76]: KB2686831
                                    [77]: KB2688338
                                    [78]: KB2690533
                                    [79]: KB2691442
                                    [80]: KB2698365
                                    [81]: KB2699779
                                    [82]: KB2705219
                                    [83]: KB2706045
                                    [84]: KB2709630
                                    [85]: KB2709715
                                    [86]: KB2709981
                                    [87]: KB2712808
                                    [88]: KB2718704
                                    [89]: KB2719857
                                    [90]: KB2719985
                                    [91]: KB2726535
                                    [92]: KB2727528
                                    [93]: KB2729094
                                    [94]: KB2729452
                                    [95]: KB2731771
                                    [96]: KB2731847
                                    [97]: KB2732059
                                    [98]: KB2732487
                                    [99]: KB2732500
                                    [100]: KB2735855
                                    [101]: KB2736233
                                    [102]: KB2736422
                                    [103]: KB2741355
                                    [104]: KB2742599
                                    [105]: KB2743555
                                    [106]: KB2744842
                                    [107]: KB2750841
                                    [108]: KB2758857
                                    [109]: KB2761217
                                    [110]: KB2763523
                                    [111]: KB2770660
                                    [112]: KB2773072
                                    [113]: KB2785220
                                    [114]: KB2786081
                                    [115]: KB2789645
                                    [116]: KB2791765
                                    [117]: KB2798162
                                    [118]: KB2799926
                                    [119]: KB2800095
                                    [120]: KB2803821
                                    [121]: KB2807986
                                    [122]: KB2808679
                                    [123]: KB2813347
                                    [124]: KB2813430
                                    [125]: KB2820331
                                    [126]: KB2832414
                                    [127]: KB2834140
                                    [128]: KB2836942
                                    [129]: KB2836943
                                    [130]: KB2839894
                                    [131]: KB2840149
                                    [132]: KB2840631
                                    [133]: KB2843630
                                    [134]: KB2846960
                                    [135]: KB2847077
                                    [136]: KB2847311
                                    [137]: KB2847927
                                    [138]: KB2852386
                                    [139]: KB2853952
                                    [140]: KB2855844
                                    [141]: KB2861191
                                    [142]: KB2861698
                                    [143]: KB2861855
                                    [144]: KB2862152
                                    [145]: KB2862330
                                    [146]: KB2862335
                                    [147]: KB2862966
                                    [148]: KB2862973
                                    [149]: KB2864058
                                    [150]: KB2864202
                                    [151]: KB2868038
                                    [152]: KB2868116
                                    [153]: KB2868626
                                    [154]: KB2871997
                                    [155]: KB2872339
                                    [156]: KB2882822
                                    [157]: KB2884256
                                    [158]: KB2887069
                                    [159]: KB2888049
                                    [160]: KB2891804
                                    [161]: KB2892074
                                    [162]: KB2893294
                                    [163]: KB2893519
                                    [164]: KB2894844
                                    [165]: KB2900986
                                    [166]: KB2908783
                                    [167]: KB2911501
                                    [168]: KB2912390
                                    [169]: KB2913152
                                    [170]: KB2918077
                                    [171]: KB2918614
                                    [172]: KB2919469
                                    [173]: KB2922229
                                    [174]: KB2926765
                                    [175]: KB2928562
                                    [176]: KB2929437
                                    [177]: KB2929733
                                    [178]: KB2929755
                                    [179]: KB2931356
                                    [180]: KB2937610
                                    [181]: KB2939576
                                    [182]: KB2943357
                                    [183]: KB2952664
                                    [184]: KB2957189
                                    [185]: KB2957503
                                    [186]: KB2957509
                                    [187]: KB2961072
                                    [188]: KB2965788
                                    [189]: KB2966583
                                    [190]: KB2968294
                                    [191]: KB2971850
                                    [192]: KB2972100
                                    [193]: KB2972211
                                    [194]: KB2972280
                                    [195]: KB2973112
                                    [196]: KB2973201
                                    [197]: KB2973337
                                    [198]: KB2973351
                                    [199]: KB2976627
                                    [200]: KB2976897
                                    [201]: KB2977629
                                    [202]: KB2977728
                                    [203]: KB2978092
                                    [204]: KB2978120
                                    [205]: KB2978668
                                    [206]: KB2978742
                                    [207]: KB2979570
                                    [208]: KB2980245
                                    [209]: KB2981580
                                    [210]: KB2982378
                                    [211]: KB2984972
                                    [212]: KB2985461
                                    [213]: KB2991963
                                    [214]: KB2992611
                                    [215]: KB2993651
                                    [216]: KB3000483
                                    [217]: KB3003743
                                    [218]: KB3004361
                                    [219]: KB3004375
                                    [220]: KB3005607
                                    [221]: KB3006226
                                    [222]: KB3010788
                                    [223]: KB3023215
                                    [224]: KB3030377
                                    [225]: KB3032323
                                    [226]: KB3032655
                                    [227]: KB3033889
                                    [228]: KB3033890
                                    [229]: KB3035126
                                    [230]: KB3035132
                                    [231]: KB3036493
                                    [232]: KB3037574
                                    [233]: KB3039066
                                    [234]: KB3042553
                                    [235]: KB3045171
                                    [236]: KB3045685
                                    [237]: KB3045999
                                    [238]: KB3046002
                                    [239]: KB3046269
                                    [240]: KB3046306
                                    [241]: KB3046482
                                    [242]: KB3048070
                                    [243]: KB3055642
                                    [244]: KB3057839
                                    [245]: KB3
Nettverkskort:                      2 nettverkskort installert.
                                    [01]: Intel(R) 82579LM Gigabit Network Connection
                                          Navn p† tilkobling: Lokal tilkobling
                                          Status:          Media frakoblet
                                    [02]: Intel(R) Centrino(R) Advanced-N 6205
                                          Navn p† tilkobling: Tr†dl›s nettverkstilkobling
                                          DHCP aktivert:    Ja
                                          DHCP-server:     172.20.10.1
                                          IP-adresse(r)
                                          [01]: 172.20.10.10
                                          [02]: fe80::a885:813a:4294:43a0

C:\Windows\system32\LogSpace\{B99EDDED-02ED-4E74-8DCC-C02A0A688643}>whoami /groups

GRUPPEINFORMASJON
-----------------

Gruppenavn                                   Type            SID          Attributter
============================================ =============== ============ ===========================================================
BUILTIN\Administratorer                      Alias           S-1-5-32-544 Aktivert som standard, Aktivert gruppe, Gruppeeier
Alle                                         Velkjent gruppe S-1-1-0      Obligatorisk gruppe, Aktivert som standard, Aktivert gruppe
NT-MYNDIGHET\Godkjente brukere               Velkjent gruppe S-1-5-11     Obligatorisk gruppe, Aktivert som standard, Aktivert gruppe
Obligatorisk etikett\Obligatorisk systemniv† Etikett         S-1-16-16384                                                            



Andre

your computer is not configured correctly for directaccess. ipv6 is not enabled correctly

$
0
0

I have one user that is getting the message "your computer is not configured correctly for directaccess. ipv6 is not enabled correctly"  Any idea on how to fix?

I have tried resetting IPv6.

directaccess tunnels will not come up Windows 2012R2

$
0
0
Guys I'm having problems configuring Direct Access on Windows Server 2012R2. My network location server and Direct Access servers are on separate boxes. I am using a wildcard cert on the HTTPS listener. I am using our internal enterprise ca to issue certs to clients. Also I'm publishing Direct Access via TMG 2010. Basically the tunnels will not come up I have already verified the machine certs they are both configured for client and workstation authentication. If I connect in via a Windows 8.1 client and do a ipconfig/all I actually have addresses also the iphttps interface shows active. I can even ping the DA server by its ipv6 address and I can ping back to the client. So my question is what steps do I need to take in order to get the tunnels up? Everything I'm reading says its certs but I'm not seeing it.

SharePoint 2010 Publishing Through UAG - (/_layouts/ Nintex Issue)

$
0
0

Hi,

We are publishing SharePoint out through UAG in a reverse proxy scenario. We noticed a few issues with Nintex Workflow 2010 through UAG access. After closer inspection to the web monitor we see the following requests being blocked.

A request from source IP address 172.XXXXXXX, user xxx-sp-server-test on trunk extranetdev; Secure=1 for application SharePoint Extranet Dev of type SharePoint14AAM failed. The URL /_layouts/NintexWorkflow/undefined&ListId=8f234bf1-eebb-4115-b145-439183389b29 contains an illegal path. The rule applied is Default rule. The method is GET.

A request from source IP address 172.XXXXXXX, user XXXX on trunk extranetdev; Secure=1 for application SharePoint Extranet Dev of type SharePoint14AAM failed. The URL /_layouts/'%20+ contains an illegal path. The rule applied is Default rule. The method is GET.

It looks like some _layouts resources are blocked. Is there a way I can allow _layouts/* (all)? What would the RegExp be? Looking at the error messages, does anyone else see issues?

Thanks

Chris 

 



Direct access 2012 connectivity filas but registered on DA server

$
0
0

Hi all

 Im trying to get my windows 8.1 client to connect to my newly built DirectAcesss server 2012.

 The Direct access server is configured and running with all checks passed. (2 nic configuration)

 Client log:

 [22/09/2015 09:55:39]: In worker thread, going to start the tests.
 [22/09/2015 09:55:39]: Running Network Interfaces tests.
 [22/09/2015 09:55:39]: Wi-Fi (Intel(R) Centrino(R) Advanced-N 6205): fe80::a8e3:6fcb:56e6:c870%4;: 10.200.1.91/255.255.255.0;
 [22/09/2015 09:55:39]: Default gateway found for Wi-Fi.
 [22/09/2015 09:55:39]: iphttpsinterface (iphttpsinterface): 2002:6e6e:6e03:1000:d90c:6a4b:b092:1a08;: 2002:6e6e:6e03:1000:edf0:3395:bddc:ed9e;: fe80::d90c:6a4b:b092:1a08%9;
 [22/09/2015 09:55:39]: No default gateway found for iphttpsinterface.
 [22/09/2015 09:55:39]: Wi-Fi has configured the default gateway 10.200.1.1.
 [22/09/2015 09:55:39]: Default gateway 10.200.1.1 for Wi-Fi replies on ICMP Echo requests, RTT is 2 msec.
 [22/09/2015 09:55:39]: Received a response from the public DNS server (8.8.8.8), RTT is 16 msec.
 [22/09/2015 09:55:39]: The public DNS Server (2001:4860:4860::8888) does not reply on ICMP Echo requests, the request or response is maybe filtered?
 [22/09/2015 09:55:39]: Running Inside/Outside location tests.
 [22/09/2015 09:55:39]: NLS is https://nls.domain.local/.
 [22/09/2015 09:55:39]: NLS is not reachable via HTTPS, the client computer is not connected to the corporate network (external) or the NLS is offline.
 [22/09/2015 09:55:39]: NRPT contains 2 rules.
 [22/09/2015 09:55:39]:        Found (unique) DNS server: 2002:6e6e:6e03:3333::1
 [22/09/2015 09:55:39]:        Send an ICMP message to check if the server is reachable.
 [22/09/2015 09:55:51]: DNS Server 2002:6e6e:6e03:3333::1 does not reply on ICMP Echo requests.
 [22/09/2015 09:55:51]: Running IP connectivity tests.
 [22/09/2015 09:55:51]: The 6to4 interface is enabled.
 [22/09/2015 09:55:51]: Teredo inferface status is offline.
 [22/09/2015 09:55:51]:       The configured DirectAccess Teredo server is win8.ipv6.microsoft.com..
 [22/09/2015 09:55:51]: The IPHTTPS interface is operational.
 [22/09/2015 09:55:51]:       The IPHTTPS interface status is IPHTTPS interface active.
 [22/09/2015 09:55:51]:       The configured IPHTTPS URL ishttps://da.emo-domain:443.
 [22/09/2015 09:55:51]: IPHTTPS has a single site configuration.
 [22/09/2015 09:55:51]: IPHTTPS URL endpoint is: https://da.emo-domain:443.
 [22/09/2015 09:55:51]:       Successfully connected to endpointhttps://da.emo-domain:443.
 [22/09/2015 09:55:51]: No response received from domain.local.
 [22/09/2015 09:55:51]: Running Windows Firewall tests.
 [22/09/2015 09:55:51]: The current profile of the Windows Firewall is Private.
 [22/09/2015 09:55:51]: The Windows Firewall is enabled in the current profile Private.
 [22/09/2015 09:55:51]: The outbound Windows Firewall rule Core Networking - Teredo (UDP-Out) is enabled.
 [22/09/2015 09:55:51]: The outbound Windows Firewall rule Core Networking - IPHTTPS (TCP-Out) is enabled.
 [22/09/2015 09:55:51]: Running certificate tests.
 [22/09/2015 09:55:51]: Found 1 machine certificates on this client computer.
 [22/09/2015 09:55:51]: Checking certificate CN=mizlt458.domain.local with the serial number [serial].
 [22/09/2015 09:55:51]:       The certificate [serial] contains the EKU Client Authentication.
 [22/09/2015 09:55:51]:       The trust chain for the certificate [serial] was sucessfully verified.
 [22/09/2015 09:55:51]: Running IPsec infrastructure tunnel tests.
 [22/09/2015 09:55:51]: Failed to connect to domain sysvol share \\domain.local\sysvol\domain.local\Policies.
 [22/09/2015 09:55:51]: Running IPsec intranet tunnel tests.
 [22/09/2015 09:55:51]: Successfully reached 2002:6e6e:6e03::6e6e:6e03, RTT is 18 msec.
 [22/09/2015 09:56:03]: Failed to connect to 2002:6e6e:6e03:5::1 with status TimedOut.
 [22/09/2015 09:56:03]: Failed to connect to HTTP probe at http://directaccess-WebProbeHost.domain.local.
 [22/09/2015 09:56:03]: Running selected post-checks script.
 [22/09/2015 09:56:03]: No post-checks script specified or the file does not exist.
 [22/09/2015 09:56:03]: Finished running post-checks script.
 [22/09/2015 09:56:03]: Finished running all tests.


 netsh namespace show policy:

 DNS Name Resolution Policy Table Settings


 Settings for nls.domain-eu.local
 ----------------------------------------------------------------------
 DNSSEC (Certification Authority)        :
 DNSSEC (Validation)                     : disabled
 DNSSEC (IPsec)                          : disabled
 DirectAccess (Certification Authority)  :
 DirectAccess (DNS Servers)              :
 DirectAccess (IPsec)                    : disabled
 DirectAccess (Proxy Settings)           : Use default browser settings
 Generic (DNS Servers)                   :
 Generic (VPN Trigger)                   : disabled
 IDN (Encoding)                          : UTF-8 (default)


 Settings for .domain-eu.local
 ----------------------------------------------------------------------
 DNSSEC (Certification Authority)        :
 DNSSEC (Validation)                     : disabled
 DNSSEC (IPsec)                          : disabled
 DirectAccess (Certification Authority)  :
 DirectAccess (DNS Servers)              : 2002:6e6e:6e03:3333::1
 DirectAccess (IPsec)                    : disabled
 DirectAccess (Proxy Settings)           : Bypass proxy
 Generic (DNS Servers)                   :
 Generic (VPN Trigger)                   : disabled
 IDN (Encoding)                          : UTF-8 (default)

 netsh namespace show effective:

 DNS Effective Name Resolution Policy Table Settings


 Settings for nls.domain-eu.local
 ----------------------------------------------------------------------
 DirectAccess (Certification Authority)  :
 DirectAccess (IPsec)                    : disabled
 DirectAccess (DNS Servers)              :
 DirectAccess (Proxy Settings)           : Use default browser settings


 Settings for .domain-eu.local
 ----------------------------------------------------------------------
 DirectAccess (Certification Authority)  :
 DirectAccess (IPsec)                    : disabled
 DirectAccess (DNS Servers)              : 2002:6e6e:6e03:3333::1
 DirectAccess (Proxy Settings)           : Bypass proxy


 Ipconfig:

 Microsoft Windows [Version 6.3.9600]
 (c) 2013 Microsoft Corporation. All rights reserved.

 C:\Users\adminbarnes>netsh namespace show policy

 DNS Name Resolution Policy Table Settings


 Settings for nls.mizuno-eu.local
 ----------------------------------------------------------------------
 DNSSEC (Certification Authority)        :
 DNSSEC (Validation)                     : disabled
 DNSSEC (IPsec)                          : disabled
 DirectAccess (Certification Authority)  :
 DirectAccess (DNS Servers)              :
 DirectAccess (IPsec)                    : disabled
 DirectAccess (Proxy Settings)           : Use default browser settings
 Generic (DNS Servers)                   :
 Generic (VPN Trigger)                   : disabled
 IDN (Encoding)                          : UTF-8 (default)


 Settings for .mizuno-eu.local
 ----------------------------------------------------------------------
 DNSSEC (Certification Authority)        :
 DNSSEC (Validation)                     : disabled
 DNSSEC (IPsec)                          : disabled
 DirectAccess (Certification Authority)  :
 DirectAccess (DNS Servers)              : 2002:6e6e:6e03:3333::1
 DirectAccess (IPsec)                    : disabled
 DirectAccess (Proxy Settings)           : Bypass proxy
 Generic (DNS Servers)                   :
 Generic (VPN Trigger)                   : disabled
 IDN (Encoding)                          : UTF-8 (default)

 C:\Users\adminbarnes>netsh namespace show effective

 DNS Effective Name Resolution Policy Table Settings


 Settings for nls.mizuno-eu.local
 ----------------------------------------------------------------------
 DirectAccess (Certification Authority)  :
 DirectAccess (IPsec)                    : disabled
 DirectAccess (DNS Servers)              :
 DirectAccess (Proxy Settings)           : Use default browser settings


 Settings for .mizuno-eu.local
 ----------------------------------------------------------------------
 DirectAccess (Certification Authority)  :
 DirectAccess (IPsec)                    : disabled
 DirectAccess (DNS Servers)              : 2002:6e6e:6e03:3333::1
 DirectAccess (Proxy Settings)           : Bypass proxy

 Windows IP Configuration

    Host Name . . . . . . . . . . . . : mizlt458
    Primary Dns Suffix  . . . . . . . : domain.local
    Node Type . . . . . . . . . . . . : Hybrid
    IP Routing Enabled. . . . . . . . : No
    WINS Proxy Enabled. . . . . . . . : No
    DNS Suffix Search List. . . . . . : domain.local

 Wireless LAN adapter Local Area Connection* 2:

    Media State . . . . . . . . . . . : Media disconnected
    Connection-specific DNS Suffix  . :
    Description . . . . . . . . . . . : Microsoft Wi-Fi Direct Virtual Adapter
    Physical Address. . . . . . . . . : 08-11-96-80-47-75
    DHCP Enabled. . . . . . . . . . . : Yes
    Autoconfiguration Enabled . . . . : Yes

 Wireless LAN adapter Wi-Fi:

    Connection-specific DNS Suffix  . :
    Description . . . . . . . . . . . : Intel(R) Centrino(R) Advanced-N 6205
    Physical Address. . . . . . . . . : 08-11-96-80-47-74
    DHCP Enabled. . . . . . . . . . . : Yes
    Autoconfiguration Enabled . . . . : Yes
    Link-local IPv6 Address . . . . . : fe80::a8e3:6fcb:56e6:c870%4(Preferred)
    IPv4 Address. . . . . . . . . . . : 10.200.1.91(Preferred)
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    Lease Obtained. . . . . . . . . . : 22 September 2015 09:39:26
    Lease Expires . . . . . . . . . . : 23 September 2015 10:25:00
    Default Gateway . . . . . . . . . : 10.200.1.1
    DHCP Server . . . . . . . . . . . : 10.200.1.1
    DHCPv6 IAID . . . . . . . . . . . : 67637654
    DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1D-8E-5F-0E-5C-26-0A-88-7B-FA

    DNS Servers . . . . . . . . . . . : 194.168.4.100
                                        194.168.8.100
    NetBIOS over Tcpip. . . . . . . . : Enabled

 Ethernet adapter Ethernet:

    Media State . . . . . . . . . . . : Media disconnected
    Connection-specific DNS Suffix  . : domain.local
    Description . . . . . . . . . . . : Intel(R) 82579LM Gigabit Network Connecti
 on
    Physical Address. . . . . . . . . : 5C-26-0A-88-7B-FA
    DHCP Enabled. . . . . . . . . . . : Yes
    Autoconfiguration Enabled . . . . : Yes

 Tunnel adapter isatap.{ABC7C9ED-8C92-4CCB-8}:

    Media State . . . . . . . . . . . : Media disconnected
    Connection-specific DNS Suffix  . :
    Description . . . . . . . . . . . : Microsoft ISATAP Adapter #2
    Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
    DHCP Enabled. . . . . . . . . . . : No
    Autoconfiguration Enabled . . . . : Yes

 Tunnel adapter iphttpsinterface:

    Connection-specific DNS Suffix  . :
    Description . . . . . . . . . . . : iphttpsinterface
    Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
    DHCP Enabled. . . . . . . . . . . : No
    Autoconfiguration Enabled . . . . : Yes
    IPv6 Address. . . . . . . . . . . : 2002:6e6e:6e03:1000:d90c:(P
 referred)
    Temporary IPv6 Address. . . . . . : 2002:6e6e:6e03:1000:edf0:3395:bddc:ed9e(P
 referred)
    Link-local IPv6 Address . . . . . : fe80::d90c:6a4b:(Preferred)
    Default Gateway . . . . . . . . . :
    DHCPv6 IAID . . . . . . . . . . . : 352321536
    DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1D-8E-5F-
   NetBIOS over Tcpip. . . . . . . . : Disabled

 Tunnel adapter 6TO4 Adapter:

    Media State . . . . . . . . . . . : Media disconnected
    Connection-specific DNS Suffix  . :
    Description . . . . . . . . . . . : Microsoft 6to4 Adapter
    Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
    DHCP Enabled. . . . . . . . . . . : No
    Autoconfiguration Enabled . . . . : Yes


matt barnes

Viewing all 1485 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>