Error logon to Windows domain with firewall

From: Toby Loo (neospitz_at_hotmail.com)
Date: 09/05/03


Date: Fri, 5 Sep 2003 13:04:19 +1000


Hi all,

I recently set up a Windows 2000 advanced server on a separated subnet from
the domain controller (Windows Server 2003). I enabled the firewall feature
on the router between the two subnet due to security reason. The Windows
2000 advanced server is on DMZ and Windows 2003 domain controller is on
inside network.

I followed the KB article 179442 to set up the access rule for the firewall,
with clients ports on Windows 2000 advanced server, server ports on domain
controller.

The problem I have is: I can join Win2000 to the domain, after reboot, I
will not be able to logon to the domain. I checked domain controller,
computer account is created, DNS recorded, seems everything is OK on domain
controller. However, every time I log on, I have to wait for 3 minutes, then
I see this error message and I will not be allowed to logon:

"No more endpoints available from endpoint mapper"

I also logon locally to see the event log, and Netlogon ID 5789 is recorded
when logging on to domain. Please advise me any useful information to
resolve this logon problem.

Regards,

Toby



Relevant Pages

  • Re: Huh? "Login failure: the user has not been granted the requested logon type at this compute
    ... I'm a pretty experienced Windows user and programmer, ... the user has not been granted the requested logon type ... on the appropriate OU to see the Group Policy for that OU]. ... > administrators' group to the domain controller. ...
    (microsoft.public.security)
  • Re: Remote User Needs to Change PWD without connecting to domain
    ... On our windows NT machines users receive the no domain controller ... With Windows 2000 User DO NOT receive any notification. ... >> When they would take the laptop in the field they were unable to logon ...
    (microsoft.public.win2000.security)
  • Re: Domain authenticating non-domain accounts
    ... I limited the tests to Windows ... a machine running Windows 98 can still access file shares ... for a logon but were able to authenticate me as long as I entered the same ... it does not explain why this domain controller was LESS strict about ...
    (microsoft.public.platformsdk.security)
  • Re: cached logons
    ... Microsoft Windows 2000 Security Hardening Guide ... Disable Caching of Logon Information ... If the Domain Controller cannot be found during logon ... how many user account entries Windows 2000 saves in the logon cache ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Windows 2003 member server with Windows 2000 Domain Controller
    ... If anyone is having a Windows 2003 member server with a Windows 2000 ... Windows cannot obtain the domain controller name for your computer ... There are currently no logon servers available to service the logon ...
    (microsoft.public.win2000.security)