Re: NTLM Proxy locking user account

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



I don't have one of those type of networks, but it *sounds* like the
following may be occurring:
You may not have failure auditing turned on for the domain controllers.
You may have a problem with the agent where it causes the failures and you
may just be missing them in the dc logs (see above).

You might want to check with Bluecoat and see if they have any updates and
you may want to verify that you're getting failure audit logs for various
types of audit events and verify that they are working (try logging in
incorrectly to the domain once and see it in the logs.)

Check the server with the agent and verify there are not secondary issues
with that machine.

Al



"Pete" <Pete@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:C5EC55E2-D53C-43A2-BF0C-44110278AC91@xxxxxxxxxxxxxxxx
Proxy is made by Bluecoat, & you load proxy agent on the server that will
autenticate user via ntlm against the AD domain when they try to access
web.

Thanks again

"Al Mulnick" wrote:

Just to be sure we're talking the same language, your NTLM proxy - what
is
the exact name of it and version?

Al


"Pete" <Pete@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:42FC4E2E-420D-4EAC-B2A5-3CA36AB57C3A@xxxxxxxxxxxxxxxx
AL,
Thanks for your response....

Sorry just found the logs on server that is running the agent for NTLM
proxy. I was getting successful autentication event id: 680 on the DC &
failure were not showing up there. My question would why the failures
are
only showing up on the Server that is running the agent & not on DC.


Have both Default Domain & Default Domain controller policy turned on
for
audit logs.


Thank You,

"Al Mulnick" wrote:

You turned on the auditing where? On the domain controllers?




"Pete" <Pete@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:4AF9B05A-E2C9-4C62-AD0D-A4DC71C74A05@xxxxxxxxxxxxxxxx
Hello All,

Hoping to find some answers to this problem. We have NTLM proxy in
our
network, every so often users get prompted to login into NTLM proxy
in
order
for them to access particular site (ex: windows update). If a user
happens
to
just put their userid without domain & pwd, their account gets
locked.
We
are
not seeing any logs under security event viewer on the domain.

We have turned on success, failure policy settings for all audit
item
except audit directory service access-- which is set to no auditing.

How is it possible that this ntlm proxy is able to lock out user
account
without generating a log?


Thanks in advance for your insight & help.....
Pete









.



Relevant Pages

  • Re: NTLM Proxy locking user account
    ... Just to be sure we're talking the same language, your NTLM proxy - what is ... Sorry just found the logs on server that is running the agent for NTLM ... failure policy settings for all audit item ...
    (microsoft.public.windows.server.active_directory)
  • Re: disaster recovery log file question
    ... We recently had an exchange failure here due to faulty drives. ... backup and server is running fine now. ... Transaction logs are not committed during a backup, ...
    (microsoft.public.exchange.admin)
  • Re: Sudden shutdown
    ... Same type failure also does not display any useful BSOD ... failure long ago that would eventually start causing shutdowns today. ... around' long ago while also stored in the system logs. ... Dust causing a crash in a one year old computer in a 70 degree room ...
    (microsoft.public.windows.vista.general)
  • Re: LDAP Lookup failure
    ... I thought that was incorrect as well, I think this must be incorrect logging ... I have failure auditing on on the DC policy, but no entries appear from the ... > Did you enable failure audits on the DC and check the logs? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Web site cant be browsed when logging out from IISv6.0 Server
    ... Your logs show that there is a failure to instance some object ... but that it lack sufficient permissions to instance whatever ... browse the website. ...
    (microsoft.public.inetserver.iis.security)