ZoneAlarm blocks client from network????

Thira

Member
Mar 2, 2000
81
0
0
Hi! My two home computers are in a network. I use D-Link DFE-910 and Wingate. I also have a cable modem that the two computers share on the network. ZoneAlarm is installed as a firewall. However when ZoneAlarm is running I cannot access the client from the server, nor can the client access the internet. If I disable ZoneAlarm I can access the client from the server, and the client can access the internet. Put another way, when ZoneAlarm is running, double clicking the Network Neighborhood on the desktop from the server only shows the server on the network. When I disable the ZoneAlarm the server & client are both shown on the network.
Can anyone assist me in properly setting ZoneAlarm so that the client is able to access the network & internet when ZoneAlarm is running.
Thank you in advance.
 

Jugernot

Diamond Member
Oct 12, 1999
6,889
0
0
I just setup ICS yesterday and finally got it working by turning Zone Alarm to Medium protection for internet. It works great now.
 

busterbrown

Junior Member
Oct 9, 1999
19
0
0
Get the latest version of ZoneAlarm, then set the security for medium. It works for me with Sygate. I can see all the client machines and they can connect to the Internet.
 

Thira

Member
Mar 2, 2000
81
0
0
Under Security, the Local is medium and the Internet is set to high. I do not see the client under network neighborhood.
Under security settings should I go to advanced and add the client under other computers? ZoneAlarm is installed only on the server. If I do need to add the client under other computers, do I do it under Host/Site, IP address, IP Range, or subnet?
Thanks
 

BCYL

Diamond Member
Jun 7, 2000
7,803
0
71
Thira:
Add your client computers in advance by IP address and the name of your computers in that network. The name has to be exactly the same as the ones you assigned to your PCs in Windows network settings. And the IP address is the internal IP for your clients.

Then set the Local Security to Medium, and your clients should be able to access the internet even with Internet security at High.

I am not sure about Wingate, but can you give Wingate access to the Internet in ZoneAlarm? If you can, do so...
 

Zach

Diamond Member
Oct 11, 1999
3,400
1
81
Do you have to set the local or internet security to medium?

I have sp1, ICS, and Zone Alarm all working. WOrks great.
 

Thira

Member
Mar 2, 2000
81
0
0
I received the following from Wingate support:
"Wingate does work in conjunction with ZoneAlarm. What we have learned is to pay attention to your boot sequence. Some users claim that ZA but start before Wingate and then whatever other applications they are running. Also, Wingate is apparently not compatible with some NICs.

Some useful links to help you get Wingate set up correctly:

http://kb.deerfield.com/index.cfm?k=1
http://members1.chello.nl/~m.joustra/
http://www.gw.total-web.net/~emailee/win2.htm
http://www.speedguide.net/

ZoneAlarm protects the computer it is installed on. Before ZoneAlarm is installed, please make sure you have your Wingate and ICS configuration set up correctly with the ability to connect to the Internet and have the functionality you want from all machines on your internal home network.

Once this is complete, you can install ZoneAlarm. If you set the security level (for the Internet Zone) to High, the computer running ICS will be protected by the firewall. However, Internet access for the other computers (that access the Internet through the ICS machine), will be blocked. As a workaround, you can set the security level on the ICS machine (for the Internet Zone) to medium.

When the security setting is set at medium (on the computer running ICS), the connection should work. You will still be able to use all the application access control features protecting you from Trojan horses and revealing all applications trying to access the Internet. You can set the ZoneAlarm Internet Security level to high on all other computers.

By default, ZoneAlarm does not include the adapter subnets that correspond to your network cards as part of your Local Zone. Therefore, computers on your Local Area Network will not be visible to each other.

To include the subnets of network adapter cards in your Local Zone do the following:

1.Click the ZoneAlarm "Security" button view the "Expanded Security panel"

2.Click the "Advanced" button

3.Under "Adapter Subnets", locate the network adapter that corresponds to your network and check the checkbox.

4.Click "Apply", then click "OK".

As long as you leave the Local Zone security level at Medium, your computer will have access to network resources.

If you have resources such as printers attached to your computer that others on the network need access to we recommend that you disable the ZoneAlarm "Automatic Lock" feature. When engaged, the Automatic Lock will block access to these resources from the Local Zone.

If you install ZoneAlarm on your Server, give the services that the server is running permission to access the Local Network, or the Internet if necessary. Some services may require "Allow Server" privilege. You can grant an application "Allow Server" privilege in the ZoneAlarm "Programs panel". In some rare instances it might be necessary to lower the Internet Zone security level to medium for all services to work on the server.

On occasion applications or services that are configured with server privileges start before ZoneAlarm. In these instances, these applications will not be granted server privilege and ZoneAlarm will block them. To resolve these instances, you will need to quit the application, or service, in question and then start it again.

Best regards,
Zone Labs Support"
 

ThurzNite

Senior member
Nov 15, 1999
977
0
0
Well, I knew about the medium level setting. I was hoping to set it to high. Also, client computer can't send email anymore. This started after I installed ZA. I disabled ZA (doesn't appear on taskbar and not running) and client still can't send. I'm gonna try uninstalling ZA. But ZA is definitely the cause cuz the night I tried it, client couldn't send.
Jay