Recommended Posts

I recently replaced a Linksys E900 router with a m0n0wall router distribution, and on my local LAN or external WAN I can not open custom ports. I need to open the following for active directory/dns/etc.. to authorize, sync, and update.

RPC endpoint mapper: 135/tcp, 135/udp
Network basic input/output system (NetBIOS) name service: 137/tcp, 137/udp
NetBIOS datagram service: 138/udp
NetBIOS session service: 139/tcp
RPC dynamic assignment: Win 2k/2003:1024-65535/tcp
Win 2008+:49152-65535/tcp
Server message block (SMB) over IP (Microsoft-DS): 445/tcp, 445/udp
Lightweight Directory Access Protocol (LDAP): 389/tcp
LDAP ping: 389/udp
LDAP over SSL: 636/tcp
Global catalog LDAP: 3268/tcp
Global catalog LDAP over SSL: 3269/tcp
Kerberos: 88/tcp, 88/udp
Domain Name Service (DNS): 53/tcp1, 53/udp

I have a default LAN rule of:

Proto: * / Source: Lan Net / Port: * / Destination: * / Description: Default LAN -> any

So ANY traffic should be able to flow freely, yet I am getting error messages such as:

The DNS server could not open socket for address 192.168.1.1. 
Verify that this is a valid IP address for the server computer. If it is NOT valid use the Interfaces dialog under Server Properties in the DNS Manager to remove it from the list of IP interfaces. Then stop and restart the DNS server. (If this was the only IP interface on this machine and the DNS server may not have started as a result of this error. In that case remove the DNS\Parameters\ ListenAddress value in the services section of the registry and restart.) 
 
If this is a valid IP address for this machine, make sure that no other application (e.g. another DNS server) is running that would attempt to use the DNS port. 
 
For more information, see "DNS server log reference" in the online Help.
 
The DNS server could not bind a Transmission Control Protocol (TCP) socket to address 192.168.1.1. The event data is the error code. An IP address of 0.0.0.0 can indicate a valid "any address" configuration in which all configured IP addresses on the computer are available for use.
Restart the DNS server or reboot the computer.

 

I've researched on m0n0walls forums and have had no luck, is this a bug with the distro?

 

 

 

Link to comment
https://www.neowin.net/forum/topic/1196185-cant-open-m0n0wall-ports-bug/
Share on other sites

I'm not sure what the NAT would look like to only allow these local services to talk amongst the LAN.

 

Edit: I set up a rule for RDP as a test

 

IF: WAN PROTO: TCP EXT PORT RANGE: 3389-3389 NAT IP: 192.168.1.1 (server) INT PORT: 3389 DESCRIPTION: RDP

 

which works...

 

So to get LDAP to authorize it should be

 

IF: WAN PROTO: TCP EXT PORT RANGE:389-389 NAT IP: 192.168.1.1 (server) INT PORT: 389 DESCRIPTION: LDAP

 

But I don't get how to do a UNIQUE range, such as RPC using something like 1024-65534, since I can only map it to one local port as opposed to a range.

Do you have more than 1 lan segment? Your gateway/router has NOTHING to do with traffic between lan machines on the same network.

So unless your routing traffic between say 192.168.1.0/24 and 192.168.2.0/24 through m0n0wall. It does not care nor even see traffic between say 192.168.1.14 and 192.168.1.52

These devices would only talk to m0n0wall to go to something off 192.168.1.0/24, like the internet. You would not be opening up most of the ports you listed inbound from the internet - nor would you believe would you even want that traffic going to the internet. Other than your dns listing port 53

Where are you seeing this error?

"The DNS server could not open socket for address 192.168.1.1"

And what is the IP address of your m0n0wall lan interface.. I believe it would default to something 192.168

But generally specking those ports would have NOTHING to do with your m0n0wall setup for your local lan. And seem unlikely you would want those forwarded from the internet, etc.

Let me see if I understand you correctly:

 

(1) These errors are on the m0n0wall setup.

(2) You setup an outbound rule to allow passing of ANY traffic out.

(3) You are seeing socket errors when M0n0wall tries to bind to the DNS port on your LAN interface.

 

The binding to ports and outbound rules issue appear to be unrelated to me. It appears that m0n0wall's DNS server service is failing to bind to the DNS port (53) for some reason. I assume you are saying that all of the services you listed also fail to bind to ports in the same manner. Out of curiosity is m0n0wall having issues binding to ports above 1024? If not, this would probably indicate an issue with root vs non-root binding. Also, is your m0n0wall LAN interface actually configured to use address 192.168.1.1? If not, it would fail to bind.

Do you have more than 1 lan segment? Your gateway/router has NOTHING to do with traffic between lan machines on the same network.

So unless your routing traffic between say 192.168.1.0/24 and 192.168.2.0/24 through m0n0wall. It does not care nor even see traffic between say 192.168.1.14 and 192.168.1.52

These devices would only talk to m0n0wall to go to something off 192.168.1.0/24, like the internet. You would not be opening up most of the ports you listed inbound from the internet - nor would you believe would you even want that traffic going to the internet. Other than your dns listing port 53

Where are you seeing this error?

"The DNS server could not open socket for address 192.168.1.1"

And what is the IP address of your m0n0wall lan interface.. I believe it would default to something 192.168

But generally specking those ports would have NOTHING to do with your m0n0wall setup for your local lan. And seem unlikely you would want those forwarded from the internet, etc.

 

1) no, it is just one lan segment (192.168.1.x)

2) I am seeing this error in my DNS event viewer

3) The m0n0wall is 192.168.1.2 (firewall.eatvac.local) and the server is is 192.168.1.1 (zeus.eatvac.local)

 

Let me see if I understand you correctly:

 

(1) These errors are on the m0n0wall setup.

(2) You setup an outbound rule to allow passing of ANY traffic out.

(3) You are seeing socket errors when M0n0wall tries to bind to the DNS port on your LAN interface.

 

The binding to ports and outbound rules issue appear to be unrelated to me. It appears that m0n0wall's DNS server service is failing to bind to the DNS port (53) for some reason. I assume you are saying that all of the services you listed also fail to bind to ports in the same manner. Out of curiosity is m0n0wall having issues binding to ports above 1024? If not, this would probably indicate an issue with root vs non-root binding. Also, is your m0n0wall LAN interface actually configured to use address 192.168.1.1? If not, it would fail to bind.

 

1) the dns errors are from the server, I KNOW m0n0wall is the culprit, because if I put in a little SOHO router I do not have these issues

2) that is the default firewall rule that m0n0wall ships with

3) Yes, I believe that m0n0wall is preventing DNS from binding a port on the LAN interface. In m0n0wall my DNS is set to 192.168.1.1 (my DNS server - Standard 2008 R2)

 

Also, every so often I get internet disconnects (page can not be displayed) yet DCDIAG shows NO errors and passes everything.

So those errors are NOT from m0n0wall? They are from logs on a Windows machine running a DNS server? if so, it really has nothing to do with m0n0wall because m0n0wall cannot control what ports a completely separate machine is able to listening on. The best I can come up with is that possibly your Windows Server isn't keeping its 192.168.1.1 IP whenever m0n0wall is hooked up and as such can't listen to any ports on that address.

  • Like 1

So those errors are NOT from m0n0wall? They are from logs on a Windows machine running a DNS server? if so, it really has nothing to do with m0n0wall because m0n0wall cannot control what ports a completely separate machine is able to listening on. The best I can come up with is that possibly your Windows Server isn't keeping its 192.168.1.1 IP whenever m0n0wall is hooked up and as such can't listen to any ports on that address.

 

Which is totally a possiblity, except everything is hard coded... I'm not sure how it would "forget" - the issue does not occur though when I have a SOHO router on the network and remove m0n0wall from the equation.

Which is totally a possiblity, except everything is hard coded... I'm not sure how it would "forget" - the issue does not occur though when I have a SOHO router on the network and remove m0n0wall from the equation.

 

Is it possible that m0n0wall has control of the 192.168.1.1 address (e.g. to hand it out via dhcp or something) and a conflict is occurring?

 

EDIT: http://support.microsoft.com/kb/279678 could this be relevant?

  • Like 1

m0n0wall is static to 192.168.1.2 (firewall.eatvac.local) all DHCP services are disabled on m0n0wall.

 

Edit: If I follow the advice of the article and set the DNS server to only listen on 192.168.1.1 I lose all functionality of DNS.

If m0n0wall is actually on 192.168.1.2 and your dns server is on 192.168.1.1, and your seeing this error on your dns server.

WTF can that have to do with m0n0wall? There is NOTHING that m0n0wall could be doing that would effect anything your dns server on a different IP address does - nothing!!

So we are missing something here.. But I assure you if what your saying is correct m0n0wall is not part of the puzzle.

  • Like 1

If m0n0wall is actually on 192.168.1.2 and your dns server is on 192.168.1.1, and your seeing this error on your dns server.

WTF can that have to do with m0n0wall? There is NOTHING that m0n0wall could be doing that would effect anything your dns server on a different IP address does - nothing!!

So we are missing something here.. But I assure you if what your saying is correct m0n0wall is not part of the puzzle.

 

I'm sure you are correct, originally I thought it may have something to do, but I have since resolved SOME of those issues. The issue at hand is still that the DNS/AD server hasn't signaled a sync yet.. (EVENT 4013 - http://gslink.us/B8syka)

It was some weird DNS settings and I used kept running "best practice analyzer" and isolating down issues, event by event. I still actually have TWO issues, but I don't want to trouble others with this...

 

The best practice I DONT UNDERSTAND. I have my loopback as a secondary server.. in the adapter properties and in the DNS server.

 

 

 

 

DNS-4013.txt

DNS-Best-Practice-Error.txt

You normally point to 127.0.0.1 as secondary in case something wrong with the IP binding, or stack that prevents dns working on the IP assigned. It's really hard to break loopback ;)

does this server have more than 1 network interface - where exactly are you going to sync too. Do you have more than 1 AD dns server in your network. Do you have more than 1 DC? Where are all the roles located?

does this server have more than 1 network interface - where exactly are you going to sync too. Do you have more than 1 AD dns server in your network. Do you have more than 1 DC? Where are all the roles located?

 

It has 4, they are all disabled except for the one in use (since I do not have need for them). 1 AD DNS server only, and 1 DC only. Roles are all on the central/primary DC.

This topic is now closed to further replies.
  • Posts

    • Rockstar gives last-gen GTA V players free upgrades tomorrow by Pulasthi Ariyasinghe Rockstar is preparing to launch Grand Theft Auto VI later this year, but ahead of that, the company has revealed a new offer for some Grand Theft Auto V owners. It today announced that Xbox One and PlayStation 4 version owners of the 2013-released title will soon be receiving a free upgrade to the current generation version. The studio released the Xbox Series X|S and PlayStation 5 version of Grand Theft Auto V back in 2022, bringing significant upgrades to the original console editions. This included 60 FPS gameplay at up to 4K resolution, as well as major upgrades to textures, draw distance, and audio. Faster load times, ray tracing elements, and HDR support were also added with it. While this new and enhanced version needed a new purchase of the game to jump in, now Rockstar has decided to make it a free upgrade, dropping the $40 price tag entirely on consoles. "Beginning tomorrow, those who own any PS4 version or the digital Xbox One version of Grand Theft Auto V will be able to upgrade to the PS5 or Xbox Series X|S versions at no additional cost, and experience the best versions of GTA V and GTA Online," said the company in an official blog post. The free upgrade offer will be released tomorrow, June 18, for all Xbox One and PlayStation 4 owners of Grand Theft Auto V. Players who will be jumping in on the offer will want to check how to migrate their GTA Online profile from last-generation to current-generation consoles by heading over here. The offer lands ahead of The Kortz Center Heist hitting Grand Theft Auto Online, where players and crews will be tasked with stealing priceless international art from a prestigious gallery in Pacific Bluffs. It doesn't look like Rockstar plans to stop updating its previous game even with Grand Theft Auto VI being on the horizon. The latest title is slated to launch on November 19, 2026, across Xbox Series X|S and PlayStation 5.
    • Now comes with a money back guarantee instead of a replacement! Hah
    • Rufus 4.15.2391 Beta by Razvan Serea Rufus is a small utility that helps format and create bootable USB flash drives, such as USB keys/pendrives, memory sticks, etc. Despite its small size, Rufus provides everything you need! Oh, and Rufus is fast. For instance it's about twice as fast as UNetbootin, Universal USB Installer or Windows 7 USB download tool, on the creation of a Windows 7 USB installation drive from an ISO (with honorable mention to WiNToBootic for managing to keep up). It is also marginally faster on the creation of Linux bootable USBs from ISOs. A non-exhaustive list of Rufus supported ISOs is available here. It can be especially useful for cases where: you need to create USB installation media from bootable ISOs (Windows, Linux, UEFI, etc.) you need to work on a system that doesn't have an OS installed you need to flash a BIOS or other firmware from DOS you want to run a low-level utility Rufus 4.15.2391 Beta changelog: Improve the guards for using the "silent" option Improve the ability to cancel during write retries Fix unrestricted XML entity expansion and integer overflow in ezxml parser (courtesy of @esadowski4) [GHSA-55r2-34wg-8mv9] Fix "silent" Windows installation failing at 75% in most cases [#2960] Fix a crash during boot when using UEFI:NTFS on Snapdragon X based ARM64 platforms [#2934] Fix the first WUE option always being checked by default [#2965] Fix an infinite loop when using Windows ISOs that contain multiple WIMs Fix "Enable runtime UEFI media validation" checkbox not always being properly enabled Other WUE improvements/fixes for OneDrive removal and username validation (with thanks to @christian8641) [#2984, #2991] Download: Rufus 4.15 Beta | 1.9 MB (Open Source) Links: Rufus Home Page | Project Page @GitHub | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Media Player Classic - Home Cinema 2.7.3 by Razvan Serea Media Player Classic - Home Cinema (MPC-HC) is a free and open-source video and audio player for Windows. MPC-HC is based on the original Guliverkli project (which is no longer maintained) and contains many additional features and bug fixes. As the continuation of the original Media Player Classic, MPC-HC isn’t flashy but it works with nearly any media format. MPC-HC uses DXVA technology to pass decoding operations to your modern video card, enhancing your viewing experience. And MPC-HC supports both physical and software DVDs with menus, chapter navigation, and subtitles. Overview of features A lot of people seem to be unaware of some of the awesome features that have been added to MPC-HC in the past years. Here is a list of useful options and features that everyone should know about: Dark interface Menu > View > Dark Theme When using dark theme it is also possible to change the height of the seekbar and size of the toolbar buttons. Options > Advanced Video preview on the seekbar Options > Tweaks > Show preview on seek bar Adjust playback speed Menu > Play > Playback rate The buttons in the player that control playback rate take a 2x step by default. This can be customized to smaller values (like 10%): Options > Playback > Speed step Adjusting playback speed works best with the internal audio renderer. This also has automatic pitch correction. Options > Playback > Output > Audio Renderer MPC-HC can remember playback position, so you can resume from that point later Options > Player > History You can quickly seek through a video with Ctrl + Mouse Scrollwheel. You can jump to next/previous file in a folder by pressing PageUp/PageDown. You can perform automatic actions at end of file. For example to go to next file or close player. Options > Playback > After Playback (permanent setting) Menu > Play > After Playback (for current file only) A-B repeat - You can loop a segment of a video. Press [ and ] to set start and stop markers. You can rotate/flip/mirror/stretch/zoom the video Menu > View > Pan&Scan This is also easily done with hotkeys (see below). There are lots of keyboard hotkeys and mouse actions to control the player. They can be customized as well. Options > Player > Keys Tip: there is a search box above the table. You can stream videos directly from Youtube and many other video websites You can stream videos directly from Youtube and many other video websites Put yt-dlp.exe or youtube-dl.exe in the MPC-HC installation folder. Then you can open website URLs in the player: Menu > File > Open File/URL You can even download those videos: Menu > File > Save a copy Tip: to be able to download in best quality with yt-dlp/youtube-dl, it is recommended to also put ffmpeg.exe in the MPC-HC folder. Several YDL configuration options are found here: Options > Advanced This includes an option to specify the location of the .exe in case you don't want to put it in MPC-HC folder. Play HDR video This requires using madVR or MPC Video Renderer. After installation these renderers can be selected here: Options > Playback > Output Ability to search for and download subtitles, either automatically or manually (press D): Options > Subtitles > Misc Besides all these (new) features, there have also been many bugfixes and internal improvements in the player in the past years that give better performance and stability. It also has updated internal codecs. Support was added for CUE sheets, WebVTT subtitles, etc. Media Player Classic - Home Cinema 2.7.3 changelog: Updated LAV Filters to version 0.82 Updated MPC Video Renderer to version 0.10.4.2550 Updated MPC Audio Renderer A few crash fixes, bug fixes and small improvements. Download: MPC-HC 2.7.3 (x64) | Standalone | ~20.0 MB (Open Source) Download: MPC-HC 2.7.3 (x86) | Standalone Links: MPC-HC Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • One Month Later
      Vincian earned a badge
      One Month Later
    • First Post
      Jocimo earned a badge
      First Post
    • Week One Done
      suprememobiles48 earned a badge
      Week One Done
    • One Month Later
      Windows Guy earned a badge
      One Month Later
    • One Month Later
      Prasann earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      510
    2. 2
      +Edouard
      172
    3. 3
      PsYcHoKiLLa
      89
    4. 4
      Steven P.
      76
    5. 5
      neufuse
      69
  • Tell a friend

    Love Neowin? Tell a friend!