You guys have any idea why we would be getting this error after a fresh Vista installment "Routing tables changes violate security policy"
Only have the 1 NIC card so its not that?
Vista Question?
- Main4ce
- Posts: 1919
- Joined: Sun May 22, 2005 4:06 pm
- Location: Gütersloh, NRW, West Germany
- Contact:
- thor
- Posts: 1367
- Joined: Sat Mar 20, 2004 10:33 am
- Location: norway; eiker (GMT+1)
- Contact:
a fresh new formated disk? I have no clue? Not my field... sorry.
But since you already are here; shall we fly one day? I got my new yoke thing going. need some adjustments on rudder pedals, but all in all it works. (my g15 keyboard's special keys don't work...)
But since you already are here; shall we fly one day? I got my new yoke thing going. need some adjustments on rudder pedals, but all in all it works. (my g15 keyboard's special keys don't work...)
Thor
Pilot Officer
RAF 617 The DamBusters
I was a bit unclear... I mean I don't give a sh..t what I'm bombing - as long as I fly with my friends.
I'm a happy bomber
Gulden Kunstverk.com | Gulden Kunstverk.no | Nettgalleri
Pilot Officer
RAF 617 The DamBusters
I was a bit unclear... I mean I don't give a sh..t what I'm bombing - as long as I fly with my friends.
I'm a happy bomber
Gulden Kunstverk.com | Gulden Kunstverk.no | Nettgalleri
- Main4ce
- Posts: 1919
- Joined: Sun May 22, 2005 4:06 pm
- Location: Gütersloh, NRW, West Germany
- Contact:
- thor
- Posts: 1367
- Joined: Sat Mar 20, 2004 10:33 am
- Location: norway; eiker (GMT+1)
- Contact:
CC main! I'll be home about 21.30 CET (19.30 GMT)
Thor
Pilot Officer
RAF 617 The DamBusters
I was a bit unclear... I mean I don't give a sh..t what I'm bombing - as long as I fly with my friends.
I'm a happy bomber
Gulden Kunstverk.com | Gulden Kunstverk.no | Nettgalleri
Pilot Officer
RAF 617 The DamBusters
I was a bit unclear... I mean I don't give a sh..t what I'm bombing - as long as I fly with my friends.
I'm a happy bomber
Gulden Kunstverk.com | Gulden Kunstverk.no | Nettgalleri
- Codguy
- Posts: 611
- Joined: Tue May 10, 2005 10:51 am
- Location: Gate B15
- Contact:
- thor
- Posts: 1367
- Joined: Sat Mar 20, 2004 10:33 am
- Location: norway; eiker (GMT+1)
- Contact:
Secret party with a scott? They are to loud...Codguy wrote: ...
Unless you two want to have some sort of super-secret Euro party and don't want some rude American crashing it
Thor
Pilot Officer
RAF 617 The DamBusters
I was a bit unclear... I mean I don't give a sh..t what I'm bombing - as long as I fly with my friends.
I'm a happy bomber
Gulden Kunstverk.com | Gulden Kunstverk.no | Nettgalleri
Pilot Officer
RAF 617 The DamBusters
I was a bit unclear... I mean I don't give a sh..t what I'm bombing - as long as I fly with my friends.
I'm a happy bomber
Gulden Kunstverk.com | Gulden Kunstverk.no | Nettgalleri
- Codguy
- Posts: 611
- Joined: Tue May 10, 2005 10:51 am
- Location: Gate B15
- Contact:
- Reddog
- Site Admin
- Posts: 2602
- Joined: Sun Jul 18, 2004 8:22 pm
- Location: Stone Mountain, GA
- Main4ce
- Posts: 1919
- Joined: Sun May 22, 2005 4:06 pm
- Location: Gütersloh, NRW, West Germany
- Contact:
No no...Our company IT admin drop by today and ask me if I knew what his problem could be ...a fresh installment of Vista on a laptop that give the above error when trying to connect to the VPN which seems to be down ...
I found this but it didn't help:
Q:
I am using a Nortel Contivity client to connect to a vendor network. Usually within a few minutes of connecting I get an error stating "Routing tables changes violate security policy". I have been running ethereal to see what is going on. At the moment the tunnel disconnects, the remote host sends me an ISAKMP packet to the destination port that I sent my last ISAKMP packet from. Then my pc sends an ICMP packet back with "Destination Unreachable (Port Unreachable)". It seems like after a variable amount of time the port becomes unavailable. This is happening on every pc I try on this network. I have setup a test pc and tried changing some registry parameters such as the MTU size and EnablePMTUDiscovery='0' but it still does not work.
Does anyone have any suggestions or run into this problem before?
Answer:
I ran into this problem before. Even if it says Routing tables changed... it's not. It's actually because your TCP MSS value has changed.
You have your MTU set, but your MSS is MTU - TCP Header - IP header.
What does that mean. You're sending packets that have the DF bit set. Meaning, they can't be fragmented. They reach a certain router that will need to fragment your packet, so he will send you back a packet Destination Unreachable. In that same packet, he's sending you the Maximum Segment Size (MSS). Your computer will take it and will change his own MSS. This is where you get your Violation in your Security Policy.
But I guess its something similar as we do have Nortel!
btw: Jocks are only loud after 4 beers!
I found this but it didn't help:
Q:
I am using a Nortel Contivity client to connect to a vendor network. Usually within a few minutes of connecting I get an error stating "Routing tables changes violate security policy". I have been running ethereal to see what is going on. At the moment the tunnel disconnects, the remote host sends me an ISAKMP packet to the destination port that I sent my last ISAKMP packet from. Then my pc sends an ICMP packet back with "Destination Unreachable (Port Unreachable)". It seems like after a variable amount of time the port becomes unavailable. This is happening on every pc I try on this network. I have setup a test pc and tried changing some registry parameters such as the MTU size and EnablePMTUDiscovery='0' but it still does not work.
Does anyone have any suggestions or run into this problem before?
Answer:
I ran into this problem before. Even if it says Routing tables changed... it's not. It's actually because your TCP MSS value has changed.
You have your MTU set, but your MSS is MTU - TCP Header - IP header.
What does that mean. You're sending packets that have the DF bit set. Meaning, they can't be fragmented. They reach a certain router that will need to fragment your packet, so he will send you back a packet Destination Unreachable. In that same packet, he's sending you the Maximum Segment Size (MSS). Your computer will take it and will change his own MSS. This is where you get your Violation in your Security Policy.
But I guess its something similar as we do have Nortel!
btw: Jocks are only loud after 4 beers!