Re: Failure Audit - Logon/Logoff - Event ID 529



Sam,
0) Type 3 is a network or IIS logon. This one is over NTLM
1) It means the client is in a workgroup
2) The client name
3) No user name supplied.

I think the question you should be asking is how a client on a 321.32.xxx.xxx network gets to have access to your intranet IIS,

Anthony,
http://www.airdesk.com



"SamD" <SamdWithNoEmail.com> wrote in message news:ekFaiw5dJHA.4180@xxxxxxxxxxxxxxxxxxxxxxx
Hi all,

My Windows Server 2003 which works as a Web Server inside an intranet shows a growing number of the following Failure Audits.
------------------------------------------------------------------------------
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 1/14/2009
Time: 9:32:44 AM
User: NT AUTHORITY\SYSTEM
Computer: MYSERVER
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name:
Domain: WORKGROUP
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: lQPxd6fSQgERESGK
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 321.32.321.32
Source Port: 0
------------------------------------------------------------------------------

Source Network Addresses are not from our authorized users.

My Questions:

1) What does "Domain: WORKGROUP" refer to? (this server is in another domain) ("WORKGROUP" is not a usual name in this intranet)

2) What does this meaningless " Workstation Name: lQPxd6fSQgERESGK" refer to? (our computer names has a different name format)

3) Why User Name is blank?

Any comment and help would be appreciated.

Cheers
Sam


.



Relevant Pages

  • Re: Cant join Win 2000 Pro Client to Win 2000 Adv Server Domain...
    ... > Win 2000 Pro client. ... > like may be the userame/password or both is incorrect. ... > If I provide the network username correct & password incorrect, ... at next logon" and then never logon to update the password? ...
    (microsoft.public.win2000.active_directory)
  • Re: Network Connection
    ... For the clients make sure that you use following policy to prevent logon with cached credentials: ... Additional post an unedited ipconfig /all from the DC/DNS server and a problem machine so we can exclude DNS configuration problems. ... From last December I have been experiencing network connection problem ... out client pc some with Vista and the rest with XP. ...
    (microsoft.public.windows.server.networking)
  • Re: change from workgroup to domain
    ... This computer with W2K server OS was a client of our ... a member of the class workgroup. ... I can change the network settings. ...
    (microsoft.public.win2000.networking)
  • Re: sharing encrypted files in a XP workgroup environment
    ... It should work if users all logon locally to the computer where the EFS ... One reason probably is because in a workgroup ... name is the same thus the network user is not able to retrieve the EFS ... certificate/private key from the user profile on the computer with the ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Error ID 5719. Source Netlogon
    ... not the client. ... There are currently no logon servers available ... >> Make sure that the computer is connected to the network and try again. ... >> the problem persists, ...
    (microsoft.public.windows.server.networking)

Loading