Re: Kerberos / IP address / event log

From: Steve (me@here.ca)
Date: 04/01/03

  • Next message: utkanbir: "ipc$ password problem"
    From: Steve <me@here.ca>
    Date: 1 Apr 2003 13:43:22 GMT
    
    

    Hi Stuart,

    To the best of my knowledge, W2K has no native way of capturing the
    IP address when a client connects. When connections are made by a
    client inside of your domain who is registered in DNS, you can quite
    easily resolve their machine name to an IP. However, if the server
    is connected to or attacked by a system outside of your domain or not
    registered in DNS, the machine name will do no good whatsoever as it
    cannot be resolved.

    At my office we have managed fix this by putting a software firewall
    on the server and set it to log all of the traffic we are interested
    in. The firewall we use is Kerio Personal Firewall and it works
    like a charm, plus is very inexpensive.

    Cheers,

    Steve

    skendric@fhcrc.org (Stuart Kendrick) wrote in
    news:62dbf7f1.0303301845.1829c142@posting.google.com:

    > Hi,
    >
    > I want to log the IP addresses of W2K clients requesting tickets from
    > domain controllers (Kerberos KDCs). I don't see a way to do this.
    >
    > Is this possible? In the Event Log, I can see the NetBIOS names of
    > machines whose users have mistyped their passwords (authentication
    > failures) ... I don't care about that ... I want the IP addresses of
    > machines which are authenticating (or, even, the IP address of the
    > machine from which a user is requesting a Kerberos ticket, i.e. making
    > an authentication request).
    >
    > --sk
    >
    > Stuart Kendrick
    > FHCRC
    >


  • Next message: utkanbir: "ipc$ password problem"

    Relevant Pages

    • Re: Max connections per client?
      ... connections per client, max failed authentication attempts per client, ... and/or max authentication attempts per client. ... Once the number of failures reaches half this ...
      (SSH)
    • vpn clients cannot access internet
      ... Here are the commands I used to set up the pix for vpn connections: ... vpdn group 1 ppp authentication pap ... vpdn group 1 ppp authentication chap ... vpdn group 1 client configuration address local vpnpool ...
      (comp.dcom.sys.cisco)
    • Re: Max connections per client?
      ... blocking max connections per client, ... authentication attempts per client, and/or max ... (Keep counter of connections, attempts, failures ...
      (SSH)
    • Re: Windows Authentication, Single sign on and Active Directory
      ... service proxy client fails to connect due to authentication failure and then ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... The server is always in the domain. ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: BASIC authentication Issues with IE - Part II - Solved but WHY?
      ... it does not know the difference between a request from IE or from ... some other HTTP client. ... Some other authentication schemes are more ... IIS can sometimes remember the token for a particular set of credentials so ...
      (microsoft.public.inetserver.iis.security)