Re: Slow Logon Issue

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Thanks Meinolf ,
Sorted the problem just now... It was not a port issue rather kerberos was
talking in UDP port.I was advised in one of the KB article to use TCP for
kerberos in WAN environments.
Forcing Kerberos to talk in TCP solved the issue.Thanks for your help
anyways for the excellent link you provided.


"Meinolf Weber [MVP-DS]" <meiweb(nospam)@gmx.de> wrote in message
news:ff16fb66122828cb3eee411155a8@xxxxxxxxxxxxxxxxxxxxxxx
Hello Babu,

What ports did you open on the firewall? See here about ports needed to be
open:
http://support.microsoft.com/kb/555381

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and
confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm

Hi,
I have member servers separated from Domain Controllers using
firewall.Now
when I login into the member servers,I get stuck at "Applying computer
settings" for over 15mins and finally allows me in.Below is the msg
which I
gathered from the server,
EventID: 10
"The kerberos subsystem is having problems fetching tickets from your
domain
controller using the UDP network protocol.This is typically due to
network
problems."
EventID:40960
The security system detected an authentication error for the server
cifs/<DC_NAME>.The failure code from authentication protocol Kerberos
was
"There are currently no logon servers available to service the logon
request.(0x000005e)
Can you please help!

cheers
Babu




.



Relevant Pages

  • RE: Setting up IPSEC with servers in and out of a domain
    ... The conditions are that you will have to open the IPSEC ports on FWs on both ... IKE on UDP 500, IP 50 or IP 51 depending on either you are using AH or ESP ... If both servers are behind NAT devices the only ports you'll need will be ...
    (Focus-Microsoft)
  • Re: Use ssh key to acquire TGT?
    ... process that takes a single password and gets multiple tickets from it. ... even if some of the servers don't use kerberos. ... keytab file to obtain AFS tickets automatically at sucessful login. ...
    (comp.protocols.kerberos)
  • Re: Using Kerberos in Windows 2000 Clustering
    ... Windows 2003 servers drop down to using LAN Manger authentication for ... the information about the cluster’s use of Kerberos and LM isn’t ... client can use this authentication method. ... Does the cluster software also drop down to using LM or will ...
    (microsoft.public.windows.server.clustering)
  • Re: openldap client GSSAPI authentication segfaults in fbsd8stable i386
    ... It seems that there are no package for openldap server with GSSAPI/SASL, so I have build and installed cyrus-sasl2, openldap24-server and openldap24-sasl-client from ports. ... that you installed and configured Kerberos from packages. ... Did you by any chance set HEIMDAL_HOME=/usr before building and installing the kerberos port? ...
    (freebsd-stable)
  • Re: HELP, I cannot figure this one out.......
    ... Make sure that w32time is running on all the servers and that one of them ... > Logon Failure: ... > Logon Process: Kerberos ... > Caller User Name: - ...
    (microsoft.public.windows.server.sbs)