Anybody with Zone Alarm Pro 3 and Internet Connection Sharing? Help.

I have followed all the help and the faqs on ZL site and I cannot make this to work @$€¤%#!!!!
I am gonna copy the email that I sent them here, I don't think they will answer me. I need help please.

Thanks as always!

COPY OF EMAIL TO ZONE LABS:

Hello
Have 2 machines: A desktop and a notebook PC.
When I am home my desktop is the Internet Gateway for the laptop, via XP ICS. Everything works ok when ZAP 3 is OFF on the gateway (the desktop), but when it is ON the notebook cannot access Internet.
I have done all that is explained in the HELP of ZAP, and have seen the faqs on Zone Labs website.
This is my configuration:

DESKTOP:
Network connections:
1. NIC To the Internet (cable modem) with ICS activated. Configured via DHCP, DNS is configured manually. Only TCP/IP and Client for MS network.
2. Firewall 1394 connection: To the notebook. Manually configured as follows: Static IP: 192.168.0.1, subnet mask: 255.255.255.0, no DNS, no gateway. Activated: Client for MS networks, File and printer sharing, TCP/IP.

NOTEBOOK:
1. NIC: Disabled.
2. Firewall 1394 connection: To the desktop. Configured via DHCP now. Has tested it also manually configured as follows: IP:192.168.0.2, Sub:255.255.255.0, Default gateway: 192.168.0.1, DNS: The same ones as in the desktop machine. Has activated: Cliento for MS networks, File and printer sharing, TCP(IP.

Zone Alarm 3.0.133 in both machines configured as follows:

DESKTOP:
Firewall Local Net: Added to the Trusted Zone
NIC: In the Internet Zone
Internet Zone: HIGH
Trusted Zone: MEDIUM
Advanced:
This computer is an ICS/NAT gateway. Local address: 192.168.0.1
General settings: Only Aollow VPN protocols at high security checked.

NOTEBOOK:
Firewall Local Net: In the Trusted Zone
Internet Zone: HIGH
Trusted Zone: MEDIUM
Advanced:
This computer is a client of an ICS/NAT gateway running ZAP. Gateway address: 192.168.0.1
Forward alerts from gateway to this computer checked.
General settings: Only Aollow VPN protocols at high security checked.

I don't know what I am missing here, but everything looks correctly configured, and I cannot access the Internet when ZAP is ON on the gateway. The 2 ZAPs are communicating ok because I get messages on the notebook like "The gateway firewall has been stoped" when I turn off ZAP 3 on the desktop pc.

Please help me with this problem.

I really apreciate your collaboration. Thank you.
 
No need to enter any data in your NOTEBOOK for TCP/IP:

check
Obtain An IP Address Automatically and
Obtain DNS Server Address Automatically.
 
er you only really need zone alarm on the gateway puter as all traffic comes thro the gateway regardless it has to there is no other way the data can get to the other machine unless it goes thro the main puter that connects directly to the net ! ;)

i have a lan and the server /gateway puter is the only system with zone alarm installed install zonealarm clean install on the gateway puter and follow the instructions when it asks how many puters answer 2 and choose this puter is an ics gateway follow the instructions as per the wizard and it should sort the problems out ;)
 
thorz:

VIPER_1069 is right.

Following Viper_1609 instructions, you also need to install any of remote control apps. ZAP knows to block some activities of your notebook. How to unblock it without RC?

I use for years the same option like you in my Win2K machines, including Radmin Administrator 2.1
 
No my friends, its not ZAP on the notebook that is the problem, it is ZAP on the gateway.
If I put ZAP on the gateway on MEDIUM security for the Internet Zone then the notebook can come trough perfectly. It is something with ZAP3 that blocks the traffic generated on the notebook when it is in HIGH for the Internet Zone.
It doesn't matter if I have ZAP ON or OFF on the notebook, the problem is the same.

Look, this is a tipical log on ZAP 3 on the gateway when I try to surf from the notebook, put attention to all the FWOUT entries, they are all blocked accesses from my notebook to the internet.

ZoneAlarm Logging Client v3.0.133
Windows XP-5.1.2600--SP
type,date,time,source,destination,transport
FWOUT,2002/08/19,21:47:38 +2:00 GMT,193.x.x.x:1041,164.109.33.31:80,TCP (flags:S)
FWOUT,2002/08/19,21:49:34 +2:00 GMT,193.x.x.x:1044,164.109.33.31:80,TCP (flags:S)
FWOUT,2002/08/19,21:53:10 +2:00 GMT,193.x.x.x:1046,164.109.33.31:80,TCP (flags:S)
PE,2002/08/19,21:55:40 +2:00 GMT,vrdns2.exe,148.122.208.99:53,N/A
FWOUT,2002/08/19,21:57:32 +2:00 GMT,193.x.x.x:1047,140.99.99.90:80,TCP (flags:S)
FWOUT,2002/08/19,21:57:52 +2:00 GMT,193.x.x.x:1048,207.68.176.190:80,TCP (flags:S)
FWOUT,2002/08/19,21:58:14 +2:00 GMT,193.x.x.x:1049,207.68.176.250:80,TCP (flags:S)
FWOUT,2002/08/19,21:58:34 +2:00 GMT,193.x.x.x:1050,207.68.185.58:80,TCP (flags:S)
FWOUT,2002/08/19,21:58:58 +2:00 GMT,193.x.x.x:1051,10.0.1.128:80,TCP (flags:S)
FWOUT,2002/08/19,21:59:18 +2:00 GMT,193.x.x.x:1052,207.68.176.250:80,TCP (flags:S)
FWOUT,2002/08/19,21:59:40 +2:00 GMT,193.x.x.x:1053,207.68.185.58:80,TCP (flags:S)
FWOUT,2002/08/19,22:00:00 +2:00 GMT,193.x.x.x:1054,207.68.176.190:80,TCP (flags:S)
FWOUT,2002/08/19,22:00:44 +2:00 GMT,193.x.x.x:1055,207.68.176.250:80,TCP (flags:S)
FWOUT,2002/08/19,22:01:22 +2:00 GMT,193.x.x.x:1056,207.188.7.131:80,TCP (flags:S)
 
Last edited:
Try the following trick:

Exit ZAP
Start to surf
Start ZAP

You will see in Desktop what is going on starting ZAP.

I supose ZAP will then configure in right way access of Notebook to Desktop.

I have had similar problems accessing Internet from my client machine, attempting to use some apps.
 
Yeah, but do you know another firewall that closes everything with ICS activated? I could be interested in it.
 
i can see that the windows XP firewall does it with ICS activated!!!!
so, i don't understand why ZoneAlarm don't Stealth the port 5000.
 
before setting up zone alarm pro 3, i used norton internet security 2002, and my network works well (ics activated) and the port 5000 Stealth (others too).
Because of an abnormal reaction with msn messenger and ADSL (rules was good, but it was impossible for me to use "file transfert" or "audio/video"), i have to choose another one like ZoneAlarm.
 
Top