Re: Security Log Help

From: Johnse (Johnse_at_discussions.microsoft.com)
Date: 04/27/05


Date: Wed, 27 Apr 2005 12:53:39 -0700

I ran netdiag & dcdiag & no errors reported. IP addresses for DNS are all
correct. Should the pdc point only to itself for DNS? Old server is out of
DNS & new servers are listed. I'll set other DNS servers to point to pdc
first & let you know if it fixes. Any other ideas if this doesn't fix the
problem?

"Steven L Umbach" wrote:

> Try running the support tools netdiag and then dcdiag on your domain
> controller to see if it reports any pertinent problems that may help in a
> solution and verify that your domain controllers have the correct IP
> addresses for preferred dns servers in their tcp/ip properties and that the
> "old" domain controller IP address is not listed. Generally the pdc fsmo
> should point to itself as it's preferred dns server and other domain
> controllers for the domain should point to the pdc fsmo first and then
> themselves. The old domain controller's IP should also be removed from DHCP
> scopes and verified that the correct domain controllers IP addresses are
> listed.--- Steve
>
>
> "Johnse" <Johnse@discussions.microsoft.com> wrote in message
> news:135F66D0-80B0-4070-B564-E2F334716710@microsoft.com...
> > As soon as I retired my previous PDC I started getting errors in my
> > security
> > eventy log & I don't know why. Help!
> > I followed KB255690 for transferring FSMO roles, KB295419 for transferring
> > the Global Catalog. My other event logs are clean. It's just the
> > security
> > log that gets all the errors.
> >
> > Event ID: 537
> > Source: Security
> > Type: Failure
> > User: NT AUTHORITY\SYSTEM
> > Category: Logon/Logoff
> > Reason: An unexpected error occurred during logon
> > Username:
> > Domain:
> > Logon Type: 3
> > Logon Process: Kerbos
> > Authentication Package: Kerbos
> > Workstation Name: -
> >
> > Event ID: 675
> > Source: Security
> > Type: Failure
> > User: NT AUTHORITY\SYSTEM
> > Category: Logon/Logoff
> > Reason: An unexpected error occurred during logon
> > Username:
> > Domain:
> > Logon Type: 3
> > Logon Process: Kerbos
> > Authentication Package: Kerbos
> > Workstation Name: -
> >
> > Event ID: 675
> > Source: Security
> > Type: Failure
> > User: NT AUTHORITY\SYSTEM
> > Category: Account Logon
> > Description: Pre-authentication failed
> > Username: juser
> > User ID: DOMAIN\juser
> > Service Name: krbtgt/DOMAIN
> > Pre-Authentication Type: 0x2
> > Failure Code: 0x18
> > Client address: 10.0.0.127
> >
> >
> > Event ID: 681
> > Source: Security
> > Type: Failure
> > User: NT AUTHORITY\SYSTEM
> > Category: Account Logon
> > Description: The logon to account: supervisor by
> > MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 from workstation: SERVER2 failed.
> > The
> > error code was: 3221225578
> >
> >
> >
> >
>
>
>



Relevant Pages

  • Re: logon
    ... single-domain Forest) that all Domain Controllers are also Global Catalog ... Option 006 where the client is given the DNS Serverinformation. ... Support Tools on all of your Servers (Domain Controllers, Member Servers, ... > server (usually DCs) and that all DCs have correctly registered in DNS. ...
    (microsoft.public.win2000.active_directory)
  • Re: Unable to authenticate users in windows 2003 SP1 secondary DC
    ... is it because my PDC hosts user folders and apps ... long as you have the domain setup to handle in accessible servers. ... domain in your forest) and that both dc's are dns servers for AD (The ... I have a PDC & BDC. ...
    (microsoft.public.windows.server.active_directory)
  • Re: "Windows cannot obtain the domain controller name..."
    ... > That DNS configuration is never going to work. ... > I'm going to make an assumption here that you have two domain controllers. ... > Make your AD domain controllers DNS servers and switch to Active Directory ...
    (microsoft.public.win2000.active_directory)
  • Re: DCs not responding to logon requests
    ... did you disable File and Print on any of the Domain Controllers? ... As PaulB suggested, do all of your clients have all DNS Servers listed (er, ... One of the other DCs hosts AD-Integrated ...
    (microsoft.public.windows.server.active_directory)
  • Re: Going to AD Integrated DNS
    ... contoller servers, named WS1, is the primary DNS server. ... I loaded DNS on our domain controllers, named DC1 and DC2, ... and they are currently set as secondary servers. ...
    (microsoft.public.win2000.dns)