Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jahidi
New Contributor

Windows notification on no internet access

Hi all, I have fortigate 80C running in tranparents mode. I add several policy by determined each by the IP and schedule. However, on windows connectivity notify me there is no internet connection even though there is a connection to the internet. Kindly please help me. Thank you in advance
~jahidi~
~jahidi~
5 REPLIES 5
Payton
New Contributor

Which Services are allowed?
Jahidi
New Contributor

Thanks Payton for your attention. I allow " ANY" service during the schedule to all the IPs. however, if I used " all to all, always, any " .. the notification disappear.
~jahidi~
~jahidi~
Dave_Hall
Honored Contributor

I personally only seen something like this happen when there was an issue with DNS resolving properly on a client' s network. Our client had " sh*tly" DNS service from their ISP and all their 100+ computers were configured staticly (don' t ask me why), so as a quick hack we did a port forwarding of all port 53 traffic to another DNS server. The hack worked, our client informed us they can access the Internet, even though Windows kept telling them they was no Internet connection.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
ede_pfau
SuperUser
SuperUser

According to this source http://technet.microsoft.com/en-us/library/cc766017(WS.10).aspx Windows 7 uses DNS and HTTP to test Internet connectivity:
The following list describes how NCSI might communicate with a Web site to determine whether a network has Internet connectivity: A request for DNS name resolution of dns.msftncsi.com A HTTP request for http://www.msftncsi.com/ncsi.txt returning 200 OK and the text Microsoft NCSI
So make sure DNS is always allowed out by putting in a specific policy just for DNS, not scheduled or restricted in any other way. On the other hand, if you don' t want to do this and get annoyed by the notification, you can disable the connectivity check by setting this in the Registry:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ NlaSvc\Parameters\Internet\EnableActiveProbing, DWORD, set to 0

Ede


"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
cmberry
New Contributor

I see this issue sometimes in Win7, but it is just cosmetic. Usually an ipconfig /release and ipconfig /renew make the issue go away on an individual pc' s.
Labels
Top Kudoed Authors