Re: Failed Security Audit

From: Steven L Umbach (n9rou_at_n0-spam-for-me-comcast.net)
Date: 10/07/04

  • Next message: Steven L Umbach: "Re: Disabled registry editing"
    Date: Wed, 06 Oct 2004 22:15:31 GMT
    
    

    If the computers generating these events are downlevel operating systems
    such as NT4.0 these errors are normal as they can not use Kerberos. From
    your description though I would first check your dns configuration for the
    domain in that the domain controllers must be pointing to only themselves or
    other W2K domain controllers for their preferred dns server and the domain
    computers must be pointing ONLY [never an ISP dns server] to a domain
    controller running AD dns for the domain as their preferred dns server. The
    link below explains this more.

    http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3B291382 --
    Active Directory dns FAQ.

    Also look in Event Viewer on your domain controllers and on the domain
    computer that caused this event to see if any pertinent errors are recorded.
    If you have an ipsec policy in the domain, domain controllers must be exempt
    by their IP addresses with a permit filter action. There are a couple
    support tools that can help. Run netdiag on at least the pdc fsmo domain
    controller and then dcdiag on it to see if any pertinent failed
    tests/errors/warnings show up. Also run netdiag on the domain computer that
    caused this failure audit. Many or most errors found are due to dns or
    networking misconfiguration. --- Steve

    http://support.microsoft.com/default.aspx?scid=kb;en-us;321708 -- netdiag
    and how to install support tools.
    http://www.eventid.net/display.asp?eventid=677&eventno=4&source=Security&phase=1
     -- results from EventId.net for Event ID 677

    "Scarebus" <scarebus@hotmail.com> wrote in message
    news:eQ$ByT%23qEHA.3976@TK2MSFTNGP10.phx.gbl...
    > The Domain Controller's (Win 2k) Security Event log is constantly giving
    > the following Failure warning for each Workstation that is in the network:
    >
    > Event Type: Failure Audit
    > Event Source: Security
    > Event Category: Account Logon
    > Event ID: 677
    > Date: 06/10/2004
    > Time: 17:23:28
    > User: NT AUTHORITY\SYSTEM
    > Computer: SERVER
    > Description:
    > Service Ticket Request Failed:
    > User Name: STATION1$
    > User Domain: FR.COM
    > Service Name: krbtgt/FR.COM
    > Ticket Options: 0x2
    > Failure Code: 0x20
    > Client Address: 192.168.2.8
    >
    > I've tried removing each Workstation from the Domain and rejoining - it
    > initially works but after a short while the Failure messages start again.
    >
    > Where do I start to look?
    >
    > Gerry
    >


  • Next message: Steven L Umbach: "Re: Disabled registry editing"

    Relevant Pages

    • Re: WINDOWS RAPLICATION ISSUE
      ... My head of dns server _msdcs.x.x.x it shwing CNAME recored for my doha DC ... But still I AM NOT ABLE TO RESOLVE THE NAME FROM MY HEAD OFFICE to my DOHA ... to configure all domain controllers to point to Dubai DNS and did you restart ... DNS server that is authoritative for that zone. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Domain workstation cannot see the domain for adding user permi
      ... use only domain controllers as their preferred DNS servers because in an AD ... access to also obtain their DNS server automatically as the rest of the ... The network has a dsl router which only some machines are allowed to use ...
      (microsoft.public.windowsxp.security_admin)
    • Re: DNS dfs issue
      ... You say that some clients are OK. ... The domain controllers for SiteA are named: ... No matter which dns server I use on clientB1 its %logonserver% is always ...
      (microsoft.public.windows.server.dns)
    • Re: Windows 2000 logon process
      ... out-of-the-box when you have two Domain Controllers (and 33/33/33 when you ... there is a priority entry. ... I also assume that if you were to look at your DNS MMC in the Forward Lookup ... Secondary DNS server. ...
      (microsoft.public.win2000.active_directory)
    • RE: NTFRS PROBLEM
      ... > I am having a problem with FRS on one of our domain controllers. ... > DNS is working fine and so is ping. ... When the DC starts up it tries to start the services (NTFRS and DNS Server) ...
      (microsoft.public.win2000.general)