Jump to content

Recommended Posts

Posted

Hi, this issue keeps re-occuring on a few of our machines.

 

They are fully up to date Windows 10 stations.

Ping command to google or similar returns perfectly, no issues.

If you run Chrome, or IE, no internet.

 

Have reset DNS, done DNS flush and netsh int ip reset.

Nothing works.

If I run a Chrome Portable, it works perfectly.

However, after a while, Chrome crashes and computer seems to run really slowly, however pings continue to reply.

Can't be firewall related or it would happen all the time, and firewall is just Defender anyway.

 

Does anyone know what could be causing this? We use Cisco AnyConnect for remote connections and this is the only piece of software I can see that seems to be on the stations that have the issue.

Rebooting the computer will make the internet work for a few minutes and then it stops again.

 

Thanks in advance.

Posted
What AV and filtering do you use?

Does the tray icon in Windows 10 indicate a net connection?

 

AV is Sophos, internet will be irrelevant as this also happens at home for people who work from home.

Tray icon also showing connection.

Posted
Are they transparent proxied I take it?

I recall there was a bug that affected GP deploying Internet settings with certain builds of Windows 10.

 

Yes, no proxies.

Just checked, one is a fully up to date 10 Pro and by up to date, I mean literally latest SP, everything.

And same for the other but Windows 10 Edu.

 

In the past, uninstalling and re-installing Chrome has done the job, but this is becoming a real pain. There must be some sort of reason for it.

Posted

I had similar thing many years ago and had to run the command to reset the winsocks or something similar.

 

When it happens can you ping say 8.8.8.8 or google.com?

  • Thanks 1
Posted
I had similar thing many years ago and had to run the command to reset the winsocks or something similar.

 

When it happens can you ping say 8.8.8.8 or google.com?

 

Yup, ping works perfectly to any host, internal or on internet.

 

When you have the issue, do you get a yellow triangle over the network icon near the clock?

No, it all shows as normal as though there is no issue.

It is just the browsers which play up.

Posted

We are still on 1709 for this very reason. One minute the internet is fine and next it’s stopped. And it’s down to an issue with the cryptography service and specific registry permissions. If you were to restart the service remotely the internet would start working again.

 

So we skipped builds 1803,1809 and have deployed 1903 on a small selection on PCs with the hope that this issue has been resolved.

 

With regards the registry keys, this below has fixed it for some people so you could try it:

 

1. Open Run and type in regedit

2. Go here: HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\

3. Right-click ProtectedRoots > Permissions and pick your account .

Tick Allow Full Control

4. Right-click Root and Export

5. Open Task Manager > stop Cryptographic Service and Delete Root(HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\) key in Regedit.

6. Restart your Windows.

 

 

I’ve also seen that Disabling user trusted root CAs can fix the issue with these reg entries:

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots]

"Flags"=dword:00000001

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots]

"PeerUsages"=hex(7):31,00,2e,00,33,00,2e,00,36,00,2e,00,31,00,2e,00,35,00,2e,\

00,35,00,2e,00,37,00,2e,00,33,00,2e,00,32,00,00,00,31,00,2e,00,33,00,2e,00,\

36,00,2e,00,31,00,2e,00,35,00,2e,00,35,00,2e,00,37,00,2e,00,33,00,2e,00,34,\

00,00,00,31,00,2e,00,33,00,2e,00,36,00,2e,00,31,00,2e,00,34,00,2e,00,31,00,\

2e,00,33,00,31,00,31,00,2e,00,31,00,30,00,2e,00,33,00,2e,00,34,00,00,00,00,\

00

 

 

Or if you wish to try GPO way:

 

Group Policy Management: go ...

Windows Settings>Security Settings>Public Key Policies>

Certificate Path Validation Settings> check Define Policy Settings>

uncheck Allow user trusted root CAs, accept, done.

 

Hopefully I have given you enough to go on with.

  • Thanks 1
Posted
Does nslookup work okay? I expect it would tbh but its worth a look.

You could try:

netsh winsock reset c:\winsocklog.txt

 

Thank you, tried it, it didn't make a difference. I couldn't locate the text file after. It didn't seem to save.

 

We are still on 1709 for this very reason. One minute the internet is fine and next it’s stopped. And it’s down to an issue with the cryptography service and specific registry permissions. If you were to restart the service remotely the internet would start working again.

 

So we skipped builds 1803,1809 and have deployed 1903 on a small selection on PCs with the hope that this issue has been resolved.

 

With regards the registry keys, this below has fixed it for some people so you could try it:

 

1. Open Run and type in regedit

2. Go here: HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\Root\

3. Right-click ProtectedRoots > Permissions and pick your account .

Tick Allow Full Control

4. Right-click Root and Export

5. Open Task Manager > stop Cryptographic Service and Delete Root(HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\) key in Regedit.

6. Restart your Windows.

 

 

I’ve also seen that Disabling user trusted root CAs can fix the issue with these reg entries:

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots]

"Flags"=dword:00000001

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots]

"PeerUsages"=hex(7):31,00,2e,00,33,00,2e,00,36,00,2e,00,31,00,2e,00,35,00,2e,\

00,35,00,2e,00,37,00,2e,00,33,00,2e,00,32,00,00,00,31,00,2e,00,33,00,2e,00,\

36,00,2e,00,31,00,2e,00,35,00,2e,00,35,00,2e,00,37,00,2e,00,33,00,2e,00,34,\

00,00,00,31,00,2e,00,33,00,2e,00,36,00,2e,00,31,00,2e,00,34,00,2e,00,31,00,\

2e,00,33,00,31,00,31,00,2e,00,31,00,30,00,2e,00,33,00,2e,00,34,00,00,00,00,\

00

 

 

Or if you wish to try GPO way:

 

Group Policy Management: go ...

Windows Settings>Security Settings>Public Key Policies>

Certificate Path Validation Settings> check Define Policy Settings>

uncheck Allow user trusted root CAs, accept, done.

 

Hopefully I have given you enough to go on with.

 

To be honest, it hasn't made any difference which version we have used. I have some on 1903 and others on 1809 and they have all done this.

I used gpedit.msc and updated the settings as per the end of your post.

Now, when I open the browser, it doesn't load anything. It used to load a page or two before stopping, now nothing.

But just to reiterate, everything else works fine, I can ping, I can send and receive emails via my Microsoft Outlook Program, Dropbox and OneDrive and working absolutely fine. Just browsers not working.

 

If I open Edge, it gives me the latest news, but when I click on an article, nothing.

IE can't even load a page. This seems to be just browser related.

Firewall is totally disabled.

Posted
Thank you, tried it, it didn't make a difference. I couldn't locate the text file after. It didn't seem to save.

 

The cmd prompt was ran elevated?

 

Just out of interest if you have a fresh build machine off domain does the net work as it should?

  • Thanks 1
Posted
The cmd prompt was ran elevated?

 

Just out of interest if you have a fresh build machine off domain does the net work as it should?

 

Yup, all elevated.

Fresh machines run with no issues at all.

 

The only way I have found I can make it work is to rebook to Safe Mode with Networking. It works like it should then. Not really sure what that means though to be honest.

What could be different to normal operation compared to Safe Mode?

Posted
Can only be driver or service at that point.

 

 

Hmm, as far as I know, drivers have not been updated, I doubt it would be that as OneDrive, Dropbox, Outlook etc are all working perfectly when normal Windows is running, it is just browsers.

I wonder what service it could be. It is driving me bl00dy mad!

Posted (edited)

If things work on a fresh machine then have a look at what services are running and stopped and compare them to a faulty machine.

 

Could it be an update that is causing the issue?

 

Whats starting up when windows starts? Anything out the oridinary there?

 

Might have nothing to do with it, what kind of profiles are you running? Does safe mode use a temporary profile?

Edited by timbo343
  • Thanks 1
Posted
If things work on a fresh machine then have a look at what services are running and stopped and compare them to a faulty machine.

 

Could it be an update that is causing the issue?

 

Whats starting up when windows starts? Anything out the oridinary there?

 

Might have nothing to do with it, what kind of profiles are you running? Does safe mode use a temporary profile?

 

Last updates went on about 1 week ago. Seem to be .Net ones.

Can't see anything on start up that looks suspicious. It has Acronis backup and that is it. I have disabled it, makes no difference.

I have disabled everything in start up, it is still doing it, so makes no difference at all.

 

Profiles are local, these are not domain connected computers.

Never known such aggravation. Contacted Microsoft on Thursday, still nothing from them. It would seem that even they don't know what is wrong with their software.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...