Repeating eventid 538 and lots of "chatter" on ports 389/445

From: Rolf Barbakken (rolf@questus.no)
Date: 12/04/02


From: "Rolf Barbakken" <rolf@questus.no>
Date: Wed, 4 Dec 2002 01:54:31 +0100

We have a network of two DCs and about 15 XP clients.

Recently the XP users have complained about hangs when working on the
network and slow computers in general. Checking around a bit we found that
the XP computers are generating the eventid 538 in the security log -
typically:

User Logoff:

User Name: klientcomp2$

Domain: ourdomainx

Logon ID: (0x0,0x1985CA)

Logon Type: 3

Sniffing packets on the network shows a lot of chatter between the two DCs
on ports 389 (LDAP) and 445 (Microsoft-ds).

Every 12 seconds the mentioned event is generated and at the same time the
CPU usage is 99% for svchost.exe (system) for a couple of seconds. We can
actually hear the computer is working harder because the fan spins up!

What is happening here?

-- 
__________________________________________
Rolf-Arne Barbakken
Teknisk ansvarlig for Questus ans
Web: www.questus.no
* "The most exciting phrase to hear in science, the one that heralds new
discoveries, is not 'Eureka!' (I found it!) but 'That's funny ...'" Isaac
Asimov *


Relevant Pages

  • Re: Two domains, One Forest....
    ... problem is that everything Microsoft insists on doing multiple network ... Placing DCs of both domain is both locations ... those machines now when there is heavy VPN traffic). ... > Correct - no leased lines T1 to internet VPN tunnel via internet. ...
    (microsoft.public.win2000.security)
  • Re: Server 2003 sp3 error - Domain controller cannot be found ?
    ... Starting test: NetLogons ... Network Logons Privileges Check ... Can you do us a favor and post an unedited ipconfig /all from both DCs? ... I saw your other post too about trusts. ...
    (microsoft.public.windows.server.active_directory)
  • Re: LAN Logons
    ... Open the RUN dialog and type "services.msc" all your computers services will ... When I first set my network up I was having the same problem, ... > how to change a logon type to avert this message. ...
    (microsoft.public.windowsxp.basics)
  • Re: Group policy and File Replication Service
    ... > I was referring to the instance when it is on the network, but its SYSVOL ... >>> DCs from a GP perspective is to run GPOTool.exe against all your DCs. ... the Windows Group Policy Guide is out from Microsoft Press!!! ...
    (microsoft.public.windows.group_policy)
  • Re: Confuguring DNS infrastructure of multisite multidomain network
    ... Microsoft MVP - Directory Services ... Two DCs of root domain are located in the company headquarteers. ... > I can sucessfully ping every server or worksstation in my network using ...
    (microsoft.public.win2000.active_directory)