Inbound connections are being blocked!!!
Dear Sirs, I installed "Windows Server 2008,32-bit" latest, full release available on the net. The installation process went smooth, quick and succesfull. Step-by-step:1.I disabled the integrated Windows Firewall and then I installed "Kerio Mail Server" and "Kerio WinRoute Firewall"2. IN WORKGROUP MODE - The computers in our company were able to receive/send mail aswell as get access to the Internet from inside the office. 3. Then, when I tried to access the Mail Server outside the office from the home pc. I wasn't able to startup the web-mail page and wasn't able to ping the server.The web-mail page should have loaded when I input the following in the web-browser address bar:http://external-IP/external-IP: 195.138.xx.xxxTHIS IS WHEN THE PROBLEM STARTEDThe paged should have loaded a LOGIN PAGE as before. But now it doesn't reply at all. As if inbound connections are blocked. Then I finally managed to recieve/send mail from home using an "Outlook 2007" and "The Bat" mail clients downloading mail through pop3 and smtp protocols that are the same as the external-IP.POP3: 195.138.xx.xxxSMTP: 195.138.xx.xxx4. I installed and configured Active Directory correctly using the Wizard and also installed a (DNS server, currently haven't configured it yet).5. I left the default domain policy settings as they are by-default. I only created a different Password Policy Profile for creating Domain users without complexed passwords.The client PCs joined domain(Active Directory) and are able to work properly receiving/sending mail and using internet aswell in the domain.So please advise accordingly what could be the problem ?The problem occured right after I installed Kerio WinRoute Firewall and Mail Server before Installing Active Directory.Do you think it is the problem with the Kerio Firewall? or there are any group policy or other Windows Server 2008 settings that may be blocking the inbound connections ?REPEATING THE PROBLEM:1. Can't ping the server by it's external IP from home (outside office)2. Can't load the web-mail page as server doesn't even respond to the http query.Please provide qualified help.This is very urgentwith best regards,Alexander Kozubay
February 22nd, 2008 8:47pm
I think that there is a high likelihood that there is a group policy setting in the default domain GPO that is touching the Firewall.
You should check that out - look in your Group Policy object at:
Computer Configuration
Windows Settings
Security Settings
Windows Firewall with Advance Security
Let me know what you find,
Free Windows Admin Tool Kit Click here and download it now
February 22nd, 2008 9:20pm
Dear Aaron,
Following your recommendation I did the following:
Start -> Programs -> Administrative Tools -> Group Policy Management
Group Policy Management Window opened.
There I expanded the +Forest:<Domain Name>
-Domains
-<Domain Name>
Under Domain name I clicked on the Default domain policy with the right mouse button and selected Edit
A Group Policy Management Editor window popped up. There I expanded Computer Configuration->Policies->Windows Settings->Security Settings->Windows Firewall with Advanced Security->
I got the following:
At the top Overview section
Domain Profile
<!--[if !supportLists]-->1. <!--[endif]-->Windows Firewall State is not configured
Private Profile
<!--[if !supportLists]-->1. <!--[endif]-->Windows Firewall State is not configured
Public Profile
<!--[if !supportLists]-->1. <!--[endif]-->Windows Firewall State is not configured
InfIInbound Rules subsection - empty
OuOutbound Rules subsection - empty
CoConnection Security Rules subsection - empty
February 23rd, 2008 3:47pm
Aaron,No need to worry now. I fixed the problem myself.The actuall problem was with the Kerio WinRoute Firewall. To be more exact, the Rules for incoming connection on Kerio weren't correctly configured (HTTP ports were blocked some unkown reason). I reconfigured the rules and it is all fine now.I checked it all remotely works now.Thanks for your help with best regards,Alexander Kozubay
Free Windows Admin Tool Kit Click here and download it now
February 23rd, 2008 6:39pm