Re: Audit Failures

From: Michiko Short [MSFT] (michikos_at_online.microsoft.com)
Date: 03/31/05


Date: Thu, 31 Mar 2005 09:29:35 -0800

Sorry, not really a VPN expert.

However, a couple of questions. You do recognize the Workstation Names
correct? They should be systems on your remote office. So each of these
events should have a valid combination of Username, Workstation Name, and
Domain. It sounds like even though you have several logon failure events,
you do have successful logons as well.

Your VPN server and DCs are current on patches and service packs?

As far as VPN goes, I would try to repost with a new subject asking for
assistance with VPN configuration. That should attract the attention of the
VPN experts. Good luck.

-- 
Michiko Short [MSFT]
--
This posting is provided "AS IS" with no warranties, and confers no rights.
Please do not send e-mail directly to this alias. This alias is for
newsgroup purposes only.
"EMcGrath@HCA_NOSPAM_Vendor.com" 
<EMcGrathHCANOSPAMVendorcom@discussions.microsoft.com> wrote in message 
news:104267FB-A6D5-47CB-BC39-AEFA30E64224@microsoft.com...
> There are many attempts, even from my account.  I think is may have 
> something
> to do with our VPN.  This is happening with users who are working in
> workgroups in a remote office and who are tunneling into my network via a 
> VPN
> connection.
>
> Does this spark any ideas?
>
> Thanks,
> Erin
>
> "Michiko Short [MSFT]" wrote:
>
>> This event occurs whenever the username & password combination fails.
>> Generally, you will see these in an organization when someone makes a
>> mistake typing their password. (though occasionally people misspell their
>> account). Excessive numbers should be investigated.
>>
>> Since I don't know the details of your environment, it may be caused by
>> other events. Logon type 3 is accessed system via network. There are also
>> several KBs that may apply to your situation.
>>
>> Windows Server 2003 Events and Errors is our web site for more 
>> information.
>> http://www.microsoft.com/technet/support/ee/search.aspx?DisplayName=Windows%20Server%202003&ProdName=Windows%20Operating%20System&MajorMinor=5.2&LCID=1033
>>
>> For more information about that event see:
>> http://www.microsoft.com/technet/support/ee/result.aspx?EvtSrc=Security&EvtID=529&ProdName=Windows+Operating+System&LCID=1033&ProdVer=5.0
>>
>> Michiko Short [MSFT}
>> -- 
>> This posting is provided "AS IS" with no warranties, and confers no 
>> rights.
>> Please do not send e-mail directly to this alias. This alias is for
>> newsgroup purposes only.
>>
>> "EMcGrath@HCA_NOSPAM_Vendor.com"
>> <EMcGrathHCANOSPAMVendorcom@discussions.microsoft.com> wrote in message
>> news:B7A0456C-DDBE-47CB-93F1-687B67CFA814@microsoft.com...
>> > Can anyone tell me if they have seen this type of audit and what does 
>> > it
>> > mean?  We just started auditing, but I am not sure what this is telling
>> > me.
>> > This case seems very ambiguious.  The other day there were the same
>> > entries
>> > but they had user accounts that I know are fine.  One of the accounts 
>> > is
>> > mine
>> > and two others that access our server via a VPN connection.
>> >
>> > Thanks,
>> >
>> >
>> > Event Type: Failure Audit
>> > Event Source: Security
>> > Event Category: Logon/Logoff
>> > Event ID: 529
>> > Date: 3/27/2005
>> > Time: 9:09:35 PM
>> > User: NT AUTHORITY\SYSTEM
>> > Computer: [SERVER_X]
>> > Description:
>> > Logon Failure:
>> >  Reason: Unknown user name or bad password
>> >  User Name: Administrator
>> >  Domain: [SERVER_X]
>> >  Logon Type: 3
>> >  Logon Process: NtLmSsp
>> >  Authentication Package: NTLM
>> >  Workstation Name: [SERVER_X]
>> >
>>
>>
>> 


Relevant Pages

  • Re: VPN logon problem
    ... This account is the same as the one logged on to the system and that this ... There are currently no logon servers available to service the logon request. ... You use a office laptop to connect the office VPN, ... > see a window asking my domain credentials. ...
    (microsoft.public.windows.server.networking)
  • Re: Cached profile problem
    ... The built in vpn client gives the option to specify the domain at logon ... Citrix logon page, which changed her domain account password, but didn't change her ... I know if the laptop had connectivity to the ...
    (microsoft.public.win2000.security)
  • Re: VPN issue
    ... The first thing it tries to do is use the credentials i used to login, ... If I use a different user's account i am able to login, ... I want to be able to logon with the correct account. ... I would like to stress that i am using Symantec VPN client software because ...
    (microsoft.public.windows.server.sbs)
  • RE: Offline files, VPNs (PPTP) and Slow Link Detection
    ... To confirm, if a slow link is detected, then certian GPO policies will not ... at the CRTL+ALTLDEL screen via a dial up VPN? ... with Slow link detection", I can assume that if the folders such as "My ... Logon domain and VPN. ...
    (microsoft.public.windows.server.sbs)
  • Re: cached login storage and changing passwords
    ... The user account status is only checked for status ... at the interactive logon when a domain controller is available. ... Depending on your VPN strategy though you may be able to have a script run ...
    (microsoft.public.win2000.active_directory)

Quantcast