NIS 2011 cause temporary drops of internet connection

Hi guys:) I'm using NIS 2011 (ver 19) on win7x64 and have some issue from 6 months now.

Atm NIS is unistalled fulled using norton remove tool. The problem is:

 

At random times during random periods of time throw 2-3 days, 4, sometime once,twice per day, random period of times, there is no some pattern,my norton is dropping my internet connection. I have read a lot during past 6 moths and has no solution at this. Yes i'm sure norton is causing this because i'm conneceted with windows firewall week and there is no single drop of internet connection. Using realtek fast ethernet adapter, with latest drivers, on freshly installed os with last updates.

I tried various metods - first without installing network security map, same result, then installing network security map - set trust to restricted,protected,shared. Even uninstalling symantec intermediate filter driver in tcp/ip properties in ethernet driver configuration - no effect at all.Write to realtek they told me that its not from my nic card, because i've been reading that some realtek nic cards are not "feeling" very well with NIS. When NIS is instaleed i have mirc client installed and when drop connection all fail - open NIS history log and says: your nic card pci realtek has been no longer protected/disappeared and then found new nic card and so on....The disconnect of internet is very limited time about 10 sec or less but drops all my mirc, file home network when copying files and its a problem to me. Try disabling/uninstall ipv6 no result. Apllication is at automatic control nothing is tuched on the configuration.

Please guys help/suggest me someting to resolve this problem, because don't want to give up from symantec at all. :)

 

p.s. tried also with NIS 2014 same result :(


milen15 wrote:

Hi guys:) I'm using NIS 2011 (ver 19) on win7x64 and have some issue from 6 months now.

Atm NIS is unistalled fulled using norton remove tool. The problem is:

 

At random times during random periods of time throw 2-3 days, 4, sometime once,twice per day, random period of times, there is no some pattern,my norton is dropping my internet connection. I have read a lot during past 6 moths and has no solution at this. Yes i'm sure norton is causing this because i'm conneceted with windows firewall week and there is no single drop of internet connection. Using realtek fast ethernet adapter, with latest drivers, on freshly installed os with last updates.

I tried various metods - first without installing network security map, same result, then installing network security map - set trust to restricted,protected,shared. Even uninstalling symantec intermediate filter driver in tcp/ip properties in ethernet driver configuration - no effect at all.Write to realtek they told me that its not from my nic card, because i've been reading that some realtek nic cards are not "feeling" very well with NIS. When NIS is instaleed i have mirc client installed and when drop connection all fail - open NIS history log and says: your nic card pci realtek has been no longer protected/disappeared and then found new nic card and so on....The disconnect of internet is very limited time about 10 sec or less but drops all my mirc, file home network when copying files and its a problem to me. Try disabling/uninstall ipv6 no result. Apllication is at automatic control nothing is tuched on the configuration.

Please guys help/suggest me someting to resolve this problem, because don't want to give up from symantec at all. :)

 

p.s. tried also with NIS 2014 same result :(


Hi,

Two suggestions.

First, please update to the current version. The protection is better regardless of the problem

Second, check the NIC. Norton is more active than the other firewall and may be finding a weakness in the card.

Keep us posted

Hi:)

First don;t want to update i'm fine with current version.

Secont its not my nic, or my nic driver, i tried with various firewalls like comodo,outpost,microsoft firewall and there is no single drop of internet connection for 7 days.

 

Could just be your ISP renewing the dhcp lease on your IP address.  In any event the Network Security Map controls LAN traffic entering your PC, not WAN (internet) traffic, so that would not be involved.  Are you using a wireless connection?  Interference from other devices can cause these sorts of dropouts, as can any number of other things.  I would contact your ISP to troubleshoot the issue.

Hi SendOfJive:)

Yes i'm using dhcp, 2nd not using wireless using wired connection with cable cat5 (change two times) brand new. Just installled again fresh instal NIS 2011, i hope this time there isn't any drop/disconnects, but i'm not big optimist. :(

Tried various things - turn off wf turn on no effect/ change speed duplex. Change 4 times the router with brand new.

Guys is there any way to see full log of what causing this drop/disconnect, except norton history log, something more detail?

I have been read years ago something about event viewer in win7, or some 3rd party software to see where is the problem.

When dropping internet connection for seconds is appeared yellow triangle with exclamation mark at network icon in right bottom corner.

 

 

What does the Windows event viewer show for the errors?

Very sorry  :( but can't remember the exact time of the last drop, and don't want to post any log that i'm not sure that is exact 100% of the internet drop, and just reinstalled freshly nis, when connection dropped again i will right away post a ms event viewer logs.

 

OK, it may give more information because something could be causing the conection to be dropped.

In the event viewer it would be listed under "system" and should be marked with the same yellow triangle.

Hi guys:) Just notice something i dno;t know if it is important but. I have mirc client with connection to 4 diffrent server (nothing common), and 2 of this irc server just disconnect at the same time.

Here is some log of NIS:

Category: Firewall - Network and Connections
Date & Time,Risk,Activity,Status,Recommended Action,Category
25.1.2014 г. 00:29 ч.,Info,"IP address has disappeared from adapter Teredo Tunneling Pseudo-Interface and is no longer being protected (IP address: 2001::5ef5:79fb:38a4:371:4ff3:d0b3).",Detected,No Action Required,Firewall - Network and Connections


Category: Firewall - Network and Connections
Date & Time,Risk,Activity,Status,Recommended Action,Category
25.1.2014 г. 00:29 ч.,Info,"IP address has disappeared from adapter Teredo Tunneling Pseudo-Interface and is no longer being protected (IP address: fe80::38a4:371:4ff3:d0b3).",Detected,No Action Required,Firewall - Network and Connections


Category: Firewall - Activities
Date & Time,Risk,Activity,Status,Recommended Action,Category
25.1.2014 г. 00:29 ч.,Info,"An instance of \"C:\Windows\System32\dllhost.exe\" is preparing to access the Internet.",Detected,No Action Required,Firewall - Activities


Category: Firewall - Network and Connections
Date & Time,Risk,Activity,Status,Recommended Action,Category
25.1.2014 г. 00:29 ч.,Info,"Protecting your connection to a newly detected network on adapter \"Teredo Tunneling Pseudo-Interface\" (IP address: fe80::10e0:212e:4ff3:d0b3).",Detected,No Action Required,Firewall - Network and Connections


Category: Firewall - Network and Connections
Date & Time,Risk,Activity,Status,Recommended Action,Category
25.1.2014 г. 00:29 ч.,Info,"Protecting your connection to a newly detected network on adapter \"Teredo Tunneling Pseudo-Interface\" (IP address: 2001::9d38:6abd:10e0:212e:4ff3:d0b3).",Detected,No Action Required,Firewall - Network and Connections

 


Is it possible the drops of internet to have something common with ipv6 teredo?

If a disable it (ipv6) i can't access work network..

In norton there is some option about IPv6: (in firewall options)  Automatic Learn IPv6 NAT Traversal Traffic


If i turn it off maybe..or?

Hi,milen15. Ipv6 is the new Internet Protocol. Currently, most traffic is under the current one, Ipv4.

 

I'd suggest keeping the Automatic learn Ipv6 feature on, for the reasons listed below, from the Help page.

 

The Automatic Learn IPv6 NAT Traversal Traffic option is available only when Automatic Program Control is set to Aggressive or Automatic. By default, Automatic Learn IPv6 NAT Traversal Traffic is turned on. In this case, Norton Internet Security allows all IPv6 NAT Traversal traffic.

When you turn off Automatic Learn IPv6 NAT Traversal Traffic, Norton Internet Security blocks IPv6 NAT Traversal traffic. If Automatic Program Control is also disabled, Norton Internet Security displays alerts whenever it detects IPv6 NAT traversal traffic. The alerts prompt you to specify whether you want Norton Internet Security allow or block the traffic.

Some of the Windows 7 and Windows 8 features such as Remote Media Experience and Remote Assistance work only when Automatic Learn IPv6 NAT Traversal Traffic is on.

All firewall alerts that appear when an unrecognized program tries to access the Internet contain the information that indicates whether the network traffic is from Teredo.

Hi guys:) Just dropped connection :((( here is log with the yellow tirangle only from windows event viewer/sytem:

One more thing just notice that link network speed was about 11 MB/s  i don't know is it matter.

 

Log Name: System
Source: Microsoft-Windows-DNS-Client
Date: 26.1.2014 г. 22:37:41 ч.
Event ID: 1014
Task Category: None
Level: Warning
Keywords:
User: NETWORK SERVICE
Computer: Delta-PC
Description:
Name resolution for the name dns.msftncsi.com timed out after none of the configured DNS servers responded.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-DNS-Client" Guid="{1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}" />
<EventID>1014</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x4000000000000000</Keywords>
<TimeCreated SystemTime="2014-01-26T20:37:41.092192100Z" />
<EventRecordID>24122</EventRecordID>
<Correlation />
<Execution ProcessID="1184" ThreadID="6532" />
<Channel>System</Channel>
<Computer>Delta-PC</Computer>
<Security UserID="S-1-5-20" />
</System>
<EventData>
<Data Name="QueryName">dns.msftncsi.com</Data>
<Data Name="AddressLength">16</Data>
<Data Name="Address">02000035D4320A330000000000000000</Data>
</EventData>
</Event>
========================================================================================================
Log Name: System
Source: Microsoft-Windows-DNS-Client
Date: 26.1.2014 г. 22:38:34 ч.
Event ID: 1014
Task Category: None
Level: Warning
Keywords:
User: SYSTEM
Computer: Delta-PC
Description:
Name resolution for the name liveupdate.symantecliveupdate.com timed out after none of the configured DNS servers responded.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-DNS-Client" Guid="{1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}" />
<EventID>1014</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x4000000000000000</Keywords>
<TimeCreated SystemTime="2014-01-26T20:38:34.854267100Z" />
<EventRecordID>24125</EventRecordID>
<Correlation />
<Execution ProcessID="1996" ThreadID="12788" />
<Channel>System</Channel>
<Computer>Delta-PC</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="QueryName">liveupdate.symantecliveupdate.com</Data>
<Data Name="AddressLength">16</Data>
<Data Name="Address">020000354066FF2C0000000000000000</Data>
</EventData>
</Event>
========================================================================================================
Log Name: System
Source: Microsoft-Windows-DNS-Client
Date: 26.1.2014 г. 22:38:58 ч.
Event ID: 1014
Task Category: None
Level: Warning
Keywords:
User: NETWORK SERVICE
Computer: Delta-PC
Description:
Name resolution for the name wpad.spnet.net timed out after none of the configured DNS servers responded.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-DNS-Client" Guid="{1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}" />
<EventID>1014</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x4000000000000000</Keywords>
<TimeCreated SystemTime="2014-01-26T20:38:58.910643000Z" />
<EventRecordID>24126</EventRecordID>
<Correlation />
<Execution ProcessID="1184" ThreadID="11164" />
<Channel>System</Channel>
<Computer>Delta-PC</Computer>
<Security UserID="S-1-5-20" />
</System>
<EventData>
<Data Name="QueryName">wpad.spnet.net</Data>
<Data Name="AddressLength">16</Data>
<Data Name="Address">02000035D4320A320000000000000000</Data>
</EventData>
</Event>
========================================================================================================
Log Name: System
Source: Microsoft-Windows-DNS-Client
Date: 26.1.2014 г. 22:39:13 ч.
Event ID: 1014
Task Category: None
Level: Warning
Keywords:
User: NETWORK SERVICE
Computer: Delta-PC
Description:
Name resolution for the name wpad.spnet.net timed out after none of the configured DNS servers responded.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-DNS-Client" Guid="{1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}" />
<EventID>1014</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x4000000000000000</Keywords>
<TimeCreated SystemTime="2014-01-26T20:39:13.329152500Z" />
<EventRecordID>24130</EventRecordID>
<Correlation />
<Execution ProcessID="1184" ThreadID="6532" />
<Channel>System</Channel>
<Computer>Delta-PC</Computer>
<Security UserID="S-1-5-20" />
</System>
<EventData>
<Data Name="QueryName">wpad.spnet.net</Data>
<Data Name="AddressLength">16</Data>
<Data Name="Address">02000035D4320A320000000000000000</Data>
</EventData>
</Event>
========================================================================================================
Log Name: System
Source: Microsoft-Windows-DNS-Client
Date: 26.1.2014 г. 22:39:24 ч.
Event ID: 1014
Task Category: None
Level: Warning
Keywords:
User: NETWORK SERVICE
Computer: Delta-PC
Description:
Name resolution for the name isatap.spnet.net timed out after none of the configured DNS servers responded.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-DNS-Client" Guid="{1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}" />
<EventID>1014</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x4000000000000000</Keywords>
<TimeCreated SystemTime="2014-01-26T20:39:24.467572000Z" />
<EventRecordID>24132</EventRecordID>
<Correlation />
<Execution ProcessID="1184" ThreadID="7616" />
<Channel>System</Channel>
<Computer>Delta-PC</Computer>
<Security UserID="S-1-5-20" />
</System>
<EventData>
<Data Name="QueryName">isatap.spnet.net</Data>
<Data Name="AddressLength">16</Data>
<Data Name="Address">02000035D4320A320000000000000000</Data>
</EventData>
</Event>
========================================================================================================

 

 

 

 

Good catch, it's a DNS problem.

"Name resolution for the name timed out after none of the configured DNS servers responded"

 

Sounds like your ISP's DNS server(s) are flakey or your not using enough of them.

Do you connect to the internet directly or through a router?

Do you know how the DNS settings are configured or the DNS servers from your ISP?

 

Dave

Hi:) Connecting throw huawei echoLife HG8245 some gigabit crappy switch from my isp that i have no admin rights on it. I notice i don;t know is it ipmortant when reach higher speeds 90-100 Mbps my connection is dropping with norton.

I connect throw dhcp with same ip adress (some they called from isp  bridge mode). Automatic setting two dns servers.

I don't know this problem is very annoing and there is no solution i think i will remove norton if problem continues 1 more time this time for good. I talk with isp its not from their side they told me. Try a lot of things drivers,ipv6 turning off, network security map, and many others lose count but no success. :((

Every thing is on dhcp automatic configuration on my isp (with so called bridge mode same ip adress to the 1st port of the switch = static ip). Connectiin with utp(cat5) cable (no wireless) I hope i help with this nfo.:)

 

log from NIS: 

 

Category: Firewall - Network and Connections
Date & Time,Risk,Activity,Status,Recommended Action,Category
26.1.2014 г. 22:39 ч.,Info,"Protecting your connection to a newly detected network on adapter \"Realtek PCIe FE Family Controller\" (IP address: xxxxx).",Detected,No Action Required,Firewall - Network and Connections
26.1.2014 г. 22:39 ч.,Info,"Protecting your connection to a newly detected network on adapter \"Realtek PCIe FE Family Controller\" (IP address: xxxxx).",Detected,No Action Required,Firewall - Network and Connections
26.1.2014 г. 22:39 ч.,Info,"IP address has disappeared from adapter Realtek PCIe FE Family Controller and is no longer being protected (IP address: xxxxx).",Detected,No Action Required,Firewall - Network and Connections
26.1.2014 г. 22:39 ч.,Info,"IP address has disappeared from adapter Realtek PCIe FE Family Controller and is no longer being protected (IP address: xxxxxxx).",Detected,No Action Required,Firewall - Network and Connections

 only remove the ip.

Try adding another DNS server so your not relying on just the iSP's.

put in as the third address 8.8.8.8

Thats a free unfiltered DNS server from google, it should always be up.

 

Dave

Thanks for quck answer DaveH. Just to ask you a few more things:)

Here is screen 3rd dns google added

dns configuration

 

On the down windows where i marked with yellow, shall i add some other dns or conigurate it with some other dns? Or leave it that way?

The settings are fine how they are, those 2 boxes should remain empty.

 

The addresses for your ISP's DNS servers are odd because they are only one number apart.

Using the same octet like that means they are both on the same server.  Usually the DNS servers are on seperate systems so if one goes down the others still work.  The other groups of numbers usually don't match so you can tell by looking at it they must be seperate systems.

 

Next time you talk to them you should ask if they have more DNS's you can use.

 

It's actually better to set them up in the router if at all possible, some routers have a way of ignoring a computer set a certain way.  But if thats not possible maybe down the line you can consider getting another one.

 

Dave

Hi guys:) And the problem continues. Who to blame i don't know Microsoft, Symantec, Realtek, Huawei, my isp. 

After a lot of time searching throw net. The only solution i found and i'm not 100% sure is it working testing atm is:

 

1. If the computers are connecting to a router, please ensure the router’s firmware is up-to-date.

2. Please run the following command in an elevated command prompt in Windows 7:

netsh interface tcp set global rss=disabled
netsh interface tcp set global autotuninglevel=disabled
netsh int ip set global taskoffload=disabled

3. Disable SNP in Windows 7 by setting Registry as following:
Note: Please perform a full-system backup first.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
EnableTCPChimney=dword:00000000
EnableTCPA=dword:00000000
EnableRSS=dword:00000000

 

From MS forums.

 

I talked with my friends who are using NIS 2014 and some other guy no one is facing this nasty issue.

Any ideas i read a lot that RSS SNP with 3rd party firewalls may cause this temporary drops, but i think that my isp is fault, someting in the huawei device but have not admin rights to it so i never know. The only best thing coming into mine brain is to chagne the isp after my contrcat is over.

Update: After six days with configuration in post above the connection was dropped. No logs in eventvwr this time. The drop was about 3-4 seconds and then connection restore itsself as always. :(