Windows Firewall blocking LSASS, causing DCOM launch error



I am having a problem with several Windows Server 2003 SP1 servers on our
domain that have the Windows Firewall service running, but Windows Firewall
configured "off" (by domain policy). I turned on ALL auditing (since I don't
know what I am looking for!) and see that Windows Firewall is blocking LSASS
listening on a UDP port soon after a reboot. Oddly, nothing is logged in
C:\Windows\pfirewall.log. It seems to be a random port number. Below are
three example Event Log entries.

When I try to create a remote out of process DCOM object and the server is
one of the affected servers, it fails to launch the process (DCOM Server
Process Launcher cannot communicate with LSASS?) and I immediately get an
E_ACCESSDENIED error returned. If I disable the Windows Firewall service and
reboot, the problem does not occur. What is going on here? Thanks,

Paul

Event Type: Failure Audit
Event Source: Security
Event Category: Detailed Tracking
Event ID: 861
Date: 5/1/2008
Time: 11:55:53 AM
User: NT AUTHORITY\SYSTEM
Computer: NCOALINK2
Description:
The Windows Firewall has detected an application listening for incoming
traffic.

Name: -
Path: C:\WINDOWS\system32\lsass.exe
Process identifier: 716
User account: SYSTEM
User domain: NT AUTHORITY
Service: Yes
RPC server: No
IP version: IPv4
IP protocol: UDP
Port number: 1100
Allowed: No
User notified: No

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Failure Audit
Event Source: Security
Event Category: Detailed Tracking
Event ID: 861
Date: 5/1/2008
Time: 11:52:08 AM
User: NT AUTHORITY\SYSTEM
Computer: NCOALINK2
Description:
The Windows Firewall has detected an application listening for incoming
traffic.

Name: -
Path: C:\WINDOWS\system32\lsass.exe
Process identifier: 716
User account: SYSTEM
User domain: NT AUTHORITY
Service: Yes
RPC server: No
IP version: IPv4
IP protocol: UDP
Port number: 1092
Allowed: No
User notified: No

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Event Type: Failure Audit
Event Source: Security
Event Category: Detailed Tracking
Event ID: 861
Date: 5/1/2008
Time: 11:52:08 AM
User: NT AUTHORITY\SYSTEM
Computer: NCOALINK2
Description:
The Windows Firewall has detected an application listening for incoming
traffic.

Name: -
Path: C:\WINDOWS\system32\lsass.exe
Process identifier: 716
User account: SYSTEM
User domain: NT AUTHORITY
Service: Yes
RPC server: No
IP version: IPv4
IP protocol: UDP
Port number: 1088
Allowed: No
User notified: No

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


.



Relevant Pages

  • RE: SBS2003 Firewall disconnecting workstations
    ... Generally, the option in Windows Firewall on the computer is grayed out, ... On SBS 2003 server, ... on a Windows XP Service Pack 2-based client computer that is in a Windows ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • RE: Windows Firewall not working
    ... Microsoft Certified System Engineer ... I did as indicated and deleted what was below Server Status but the problem ... This is what I have in the RRAS console: ... I searched for the other errors such as " Windows Firewall cannot run because ...
    (microsoft.public.windows.server.networking)
  • Re: can not start Windows Firewall
    ... Unfortunately, DCOM Server Process Launcher service, Network Connections ... "Coraleigh Miller" wrote: ... Connection Sharingservice are started. ... Yesterday I happened to notice I can't open Windows Firewall ...
    (microsoft.public.windows.server.general)
  • RE: SBS SP1 Manage Computer
    ... Thank you for posting in SBS newsgroup. ... The RPC server is unavailable" when you click Clients Computers on Server ... In Windows XP Service Pack 2, Windows Firewall is enabled by default. ...
    (microsoft.public.windows.server.sbs)
  • Re: RDP not working
    ... Then do you have the Windows firewall enabled on the server? ... RD isn't running or the port has been changed. ... No....but you didn't mention that (you said remote administration). ...
    (microsoft.public.windows.server.sbs)