Re: DC Apparently lost authentication to domain

Tech-Archive recommends: Fix windows errors by optimizing your registry



We own the connection to the remote site, so there is no firewall between
the home and remote sites. There is just a routing switch which doesn't have
the capability to block ports.

Good thought. I wish it were that easy.

Speaking of routing... Could it be a WINS/NetBIOS thing since we are
routing? We're not using WINS because every MS class I ever went to
suggested not using it with AD integrated DNS but I've recently heard that
some things just won't work right without WINS. Any thoughts?

Ken

"Paul Bergson" <pbergson@xxxxxxxxxxxxxxxxx> wrote in message
news:%23Mve$rM1FHA.3188@xxxxxxxxxxxxxxxxxxxxxxx
> First thought that comes to mind is a firewall issue. Just because the
> servers haven't changed doesn't mean someone didn't block some ports on
> you. Check with your firewall folks and see if they made any changes over
> the weekend.
>
> --
>
>
> Paul Bergson MCT, MCSE, MCSA, CNE, CNA, CCA
>
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>
>
> "Ken Eisman" <ken@xxxxxxxxxxxx> wrote in message
> news:8bt5f.4287$BZ5.411@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx
>> We have a W2K/2K3 domain. It's been working fine up until this weekend.
>> Now one DC (in a remote site) will not authenticate with the other DC's.
>> Consequently, clients that authenticate with the bad DC cannot access
>> network resources in the home site. They seem to be able to access
>> resources in the remote site without problem.
>>
>> Some examples are:
>> If I try to connect to the event viewer of a good DC from the bad DC, I
>> get an 'access denied' error.
>> If I try to connect to any computer in the good site from any computer in
>> the bad site using the computer browser or 'net use ...', I get 'The
>> target account name is incorrect'
>> If I try to connect using 'net view...', I get 'Error 5 Access is
>> denied.'
>> In ADSS, replication appears to work from the good DC to the bad DC but
>> not from the bad DC to the good DC.
>> DNS on the bad DC gives an error 4015 '....critical error from the Active
>> Director' in the event log.
>> Running netdiag on the bad DC yields very few errors except for this:
>> LDAP test. . . . . . . . . . . . . : Passed
>> [WARNING] Failed to query SPN registration on DC
>> 'adserver.co.matagorda.tx.us'.
>> [WARNING] Failed to query SPN registration on DC
>> 'ptr-svr.co.matagorda.tx.us'.
>> [WARNING] Failed to query SPN registration on DC
>> 'ANTIVIRUS.co.matagorda.tx.us'.
>> (These are all the DCs in the home site.)
>>
>> Based on my search of the MS KB, I've tried using netdom to reset the
>> password and I've checked for duplicate account names , but nothing has
>> helped, so far.
>>
>> I'm not sure what kind of information you may need to help me out. Just
>> ask for it and I will do my best to provide it.
>>
>> Thank You
>>
>> Ken
>>
>
>


.



Relevant Pages

  • Re: VPN WinXP Firewall
    ... Networking, Internet, Routing, VPN, Anti-Virus, Tips & Troubleshooting on ... It connects OK but the name mappings (net use x: ... > The remote clients go thru a Linksys BEFSX41 at the remote site. ... The problem seems to have begun when the Win XP firewall update ...
    (microsoft.public.windows.server.networking)
  • RE: 2 router to internal sbs std network
    ... appaers that you have set up a firewall (ISA server) on your internal network. ... > and one ont thing from the remote site i can ping the main office ...
    (microsoft.public.windows.server.sbs)
  • Re: Site-to-Site with ISA 2004
    ... Remote Site Network's firewall so that Web Proxy clients will be able to ... Creating IPSec Tunnel Mode Site to Site VPNs with ISA Server 2004 Firewalls ... The remote office is using a hardware router, ...
    (microsoft.public.windows.server.sbs)
  • Re: Netscreen Remote 7.0.3
    ... >> I have a remote site in Scotland with 2 users. ... >> It seems like the firewall lets them in but doesn't know which of them to ... >> User 1 pings the office and get a response. ... separate policies, but you may have stumbled on to something with the ...
    (comp.security.firewalls)
  • RE: vpn terminating at router
    ... business class router will, but not your standard home based firewalls. ... | allow the vpn from remote site to terminate onto. ... would putting a firewall behind the vpn/firewall ...
    (microsoft.public.windows.server.sbs)