Re: Lsasrv Event ID 40960

Tech-Archive recommends: Fix windows errors by optimizing your registry



In news:uA%23E6ZKgGHA.5088@xxxxxxxxxxxxxxxxxxxx,
kbergros <kbergros@xxxxxxxxxxx> stated, which I commented on below:
Hi!

Thanxs for your answer.
I have checked my Dns zones (several times) and all my machines has
the correct ptr entry... I have checked with Nslookup both my forward
and recursive zones and get the correct answer every time...
Any other suggestions on how to solve this?

regards

Kbergros

Looking again at your original post, the description part of the error says:

Description:
The Security System detected an authentication error for the server
ldap/gollum.test.timber.se/test.timber.se@xxxxxxxxxxxxxxx The failure
code from authentication protocol Kerberos was "The attempted logon is
invalid. This is either due to a bad username or authentication information.
(0xc000006d)".

This indicates to me that you are possibly pointing to your ISP's DNS in IP
properties. Now if AD is trying to coorespond it's SPNEGO by contacting them
for a PTR for the internal IP range, then I can understand why this is
happening.

The cardinal rule is in any AD infrastructure, no matter how small or large,
NEVER use the ISP's DNS in IP properties of ANY machine that is part of AD
(DCs servers and clients). If not sure what I'm talking about, please post
an unedited ipconfig /all to better assist you and we can point out any
problems in your config.

Ace


.



Relevant Pages

  • Re: Authentication issues with company web
    ... Were both machines joined to the SBS domain with servername/connectcomputer? ... DNS querries to your external DNS host? ... http://companyweb.domain.local or they get a authentication error ...
    (microsoft.public.windows.server.sbs)
  • Re: How to enable communication between Two different lans (subnets)/ domains 2003 server based? Ass
    ... You will also almost certainly have DNS problems running a domain behind ... server domain, with a DHCP server running on one of the 2003 boxes. ... the "inner" subnet can see the original subnet and the Internet, ... The .227 machines can see the machines on the 192.168.1.0 subnet and the ...
    (microsoft.public.windows.server.networking)
  • RE: suspicious firewall rules in WinXP firewall
    ... When that site got taken down, DNS ... suspicious firewall rules in WinXP firewall ... I can ping out of these two machines, ... World renowned security experts reveal tomorrow's threats today. ...
    (Incidents)
  • Re: Removing "permanently offline" DC...
    ... Make sure that at least one of these machines is a Global Catalog ... In the DNS console, use the DNS MMC to delete the cname ... If this was a DNS server before you brought it down, ... Event 13516 OR 13509 which indicate successful replication. ...
    (microsoft.public.windows.server.active_directory)
  • Re: ISA 2006 and Listeners Part 2!
    ... All machines use only the internal AD/DNS ... No machine should ever use any other DNS ... The AD/DNS machine will use the ISP's DNS in the ... Microsoft Internet Security & Acceleration Server: ...
    (microsoft.public.isa.configuration)