Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Windows shows "No Internet Access", but internet is working fine ?!

    Scheduled Pinned Locked Moved pfBlockerNG
    16 Posts 7 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • HermanH
      Herman
      last edited by

      Hi Folks,

      Since I have installed the last update of pfSense2.4.5-RELEASE and pfBlockerNG-devel 2.2.5_32 all my Windows machines are showing “No Internet Access” at the network connection icon in the taskbar. Despite this notification, internet on all Windows machines is working just fine…

      Does anyone also experience this strange behavior?

      Please let me know your thoughts about this…

      Kind regards,
      Herman F.

      Limburg | The Netherlands.
      It is nice to be important. But it is more important to be nice! | Failure, the best teacher it is!

      NollipfSenseN 1 Reply Last reply Reply Quote 0
      • NollipfSenseN
        NollipfSense @Herman
        last edited by

        @Herman It sounds as if you're running pfSense in a virtual environment ... are you?

        pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
        pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

        HermanH 1 Reply Last reply Reply Quote 0
        • HermanH
          Herman @NollipfSense
          last edited by

          @NollipfSense, thank you for your fast reply.

          Yes that is correct. Running pfSense on a Windows Server 2019 Hyper-V host.
          The VM is hosting 3 virtual switches. 2 LAN connections and 1 WAN connection.

          Hope this helps...

          Regards Herman F.

          Limburg | The Netherlands.
          It is nice to be important. But it is more important to be nice! | Failure, the best teacher it is!

          NollipfSenseN 1 Reply Last reply Reply Quote 0
          • NollipfSenseN
            NollipfSense @Herman
            last edited by

            @Herman You might need the set the virtual machine in bridge mode.

            pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
            pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

            HermanH 1 Reply Last reply Reply Quote 0
            • HermanH
              Herman @NollipfSense
              last edited by Herman

              @NollipfSense can you explain this to me in detail? What is changed that this suddenly occurs? Never had problems with the 2.4.4 version.

              Kind regards,
              Herman

              Limburg | The Netherlands.
              It is nice to be important. But it is more important to be nice! | Failure, the best teacher it is!

              NollipfSenseN 1 Reply Last reply Reply Quote 0
              • NollipfSenseN
                NollipfSense @Herman
                last edited by

                @Herman Well, I don't know what to say especially since you had the way you wanted under v2.4.4. So, I'll link Steve with hope he might be to offer an explanation @stephenw10

                pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                1 Reply Last reply Reply Quote 0
                • RonpfSR
                  RonpfS
                  last edited by

                  Do you have DNSBL enabled? Inspect the Reports/Alerts tab, maybe you have some microsoft.com site being blocked.

                  2.4.5-RELEASE-p1 (amd64)
                  Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                  Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                  NollipfSenseN 1 Reply Last reply Reply Quote 0
                  • NollipfSenseN
                    NollipfSense @RonpfS
                    last edited by

                    @RonpfS He said "all my Windows machines are showing “No Internet Access” at the network connection icon in the taskbar." So, his Windows OS is not showing connection and not that he was say downloading update or that his machines were calling home. Or, are you saying when the machines cannot call home, he'll get no Internet connections! Everything was working under v2.4.4; so, it seems he had pfBlockerNG installed. I hardly use Windows.

                    pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                    pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                    1 Reply Last reply Reply Quote 0
                    • RonpfSR
                      RonpfS
                      last edited by RonpfS

                      Well my Window 7 calls home every time it boots. When it doesn't reach it's server, it display the “No Internet Access” warning.
                      I don't remember which domain was used at the time but logging.windows.microsoft.com and watson.microsoft.com are in my DNSBL whitelist.

                      Herman can disable DNSBL, reboot a Window machine and see if the issue is still present. If the issue is still present, disabling pfblockerng and reboot a Windows to rule out and IP being blocked.

                      Maybe things were running fine under 2.4.4, but on a new installation, file are created from scratch and what if some whitelisting gone missing.

                      2.4.5-RELEASE-p1 (amd64)
                      Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
                      Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

                      1 Reply Last reply Reply Quote 0
                      • HermanH
                        Herman
                        last edited by

                        @NollipfSense, @RonpfS Thanks to both of you. Appreciate all your effort helping me.

                        When disable DNSBL and reboot the machine(s) the problem does not occur. So there must be something blocked I assume. By the way I didn’t know that Microsoft checks online if the machine has internet connection yes or no?

                        Thanks to both of you. Appreciate all your effort helping me.
                        When disabling DNSBL and reboot the machine the problem does not occur. So there must be something blocked I assume. By the way I didn’t know that MS checks online if the machine has internet connection yes or no?

                        Hope this helps,
                        Herman

                        Limburg | The Netherlands.
                        It is nice to be important. But it is more important to be nice! | Failure, the best teacher it is!

                        GertjanG 1 Reply Last reply Reply Quote 0
                        • GertjanG
                          Gertjan @Herman
                          last edited by Gertjan

                          @Herman said in Windows shows "No Internet Access", but internet is working fine ?!:

                          By the way I didn’t know that Microsoft checks online if the machine has internet connection

                          Like a phone, you have to pick it up, and hear a dail tone. That somewhat gives a proof that the local network, from the phone to the operators trunk, is operational. Not the entire world wide phone network.
                          To really make sure "it" actually work, you have to compose some (random) number and see if they answer.
                          Seems logic, right ?!

                          No "help me" PM's please. Use the forum, the community will thank you.
                          Edit : and where are the logs ??

                          1 Reply Last reply Reply Quote 0
                          • SpearfootS
                            Spearfoot
                            last edited by

                            Sounds like you're blocking Microsoft's NCIS (Network Connectivity Status Indicator) subsystem. Windows systems -- or at least some of them -- query website www (dot) msftncsi (dot) com to verify connectivity. Details here:

                            https://blog.superuser.com/2011/05/16/windows-7-network-awareness/

                            1 Reply Last reply Reply Quote 0
                            • R
                              riften
                              last edited by

                              On my Windows 10 machines, they are probing for www.msftconnecttest.com
                              and ipv6.msftconnecttest.com. And at least one of my DNSBL lists was blocking them so I put them in the white list. Problem solved. Don't need some family member complaining "there's no internet!".

                              1 Reply Last reply Reply Quote 0
                              • DaddyGoD
                                DaddyGo
                                last edited by

                                I don't think the status of the icon is a big problem, as opposed to MicroSoft collecting possible data with ping responses from www.msftncsi.com

                                this telemetry is not in vain on the ban list.....!
                                Create a batch file (ping.bat) that will ping from your Windows-based machine after boot to a few known DNS providers, such as 8.8.8.8, 1.1.1.1.
                                The icon changes state after a short time - to internet status is ON :-)

                                Like:
                                b7b75bd9-8b98-49e5-a9fb-f1e437a8b8df-image.png

                                Cats bury it so they can't see it!
                                (You know what I mean if you have a cat)

                                1 Reply Last reply Reply Quote 1
                                • R
                                  riften
                                  last edited by

                                  I'm sure there are so many back doors that an obvious 'front door' like these MS 'internet test' sites just aren't a big deal to me. How many of us have a you-know-where made cellphone on our person, sending telemetry to you-know-who country. They know more about us than we know. I don't worry much about MS knowing where I am. I am sure that they don't need this 'connection test' to tell them.

                                  1 Reply Last reply Reply Quote 0
                                  • DaddyGoD
                                    DaddyGo
                                    last edited by DaddyGo

                                    I actually agree with you, but if I think about it better, then not. ☺
                                    In case, if we always let them to observe us and let's say it still fits, it will only be catastrophic this situacion.
                                    The people you're talking about on flower language, we gave them all the technology to make them for us afterwards.
                                    They’re just smoothly seizing the opportunity and have grown bigger ever since.
                                    Maybe it’s basically our fault for getting here.
                                    So I destroy down telemetry as much as possible.

                                    Cats bury it so they can't see it!
                                    (You know what I mean if you have a cat)

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.