Repeated Error Log HELP

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Help am going round in circles here with 2, which i think are related error
messages in the system and security
event logs

The first pair occur in the system log every 20 mins 2gether... here they are

Event Type: Warning
Event Source: LSASRV
Event Category: SPNEGO (Negotiator)
Event ID: 40961
Date: 05/12/2005
Time: 12:26:05
User: N/A
Computer: SERVER1
Description:
The Security System could not establish a secured connection with the server
DNS/server1.mydomain.local. No authentication protocol was available.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 6d 00 00 c0 m..À
**********************************************************
Event Type: Warning
Event Source: LSASRV
Event Category: SPNEGO (Negotiator)
Event ID: 40960
Date: 05/12/2005
Time: 12:26:05
User: N/A
Computer: SERVER1
Description:
The Security System detected an authentication error for the server
DNS/server1.mydomain.local. The failure code from authentication protocol
Kerberos was "The attempted logon is invalid. This is either due to a bad
username or authentication information.
(0xc000006d)".

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 6d 00 00 c0 m..À
*************************************************

Then at regular intervals this failure audit appears in the security logs

Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 05/12/2005
Time: 12:42:16
User: NT AUTHORITY\SYSTEM
Computer: SERVER1
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: SERVER1$
Domain: mydomain.local
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: SERVER1
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: -
Source Port: -


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

*******************************************88

i cannot seem 2 find why my own SBS server ( server1) has this problem any
help would be fantastic....

DNS is fine all users can log on etc.... I do seem to ba having a few time
out error on the server when i access new pages.... this is since i added a
second network card a ran the internret connection wizard to put the lan and
wan on 2 different cards?

Iain
.



Relevant Pages

  • Error messages relating to domain server authorisation
    ... The Security System could not establish a secured connection with the server ... No authentication protocol was available. ... Then at regular intervals this failure audit appears in the security logs ...
    (microsoft.public.windows.server.sbs)
  • Re: SharePoint failure audit
    ... It may not be the most perfect solution, but your server's security ... logs should show all authentication attempts into MOSS by default. ... rule that will generate an alert in the case of a failure attempt ...
    (microsoft.public.sharepoint.portalserver)
  • Re: SharePoint failure audit
    ... It may not be the most perfect solution, but your server's security ... logs should show all authentication attempts into MOSS by default. ... rule that will generate an alert in the case of a failure attempt ...
    (microsoft.public.sharepoint.portalserver)
  • [NEWS] Nokia IPSO Script Injection Vulnerability
    ... Get your security news from a reliable source. ... Nokia Network Voyager is "an SSL-secured, ... After the malicious code is successfully injected into the logs, ...
    (Securiteam)
  • Re: Changes to folder permissions not taking effect on Server 2008
    ... When a user logs on, Windows creates a SID (security identifier) that contains a list of the security groups the user belongs to at that particular moment. ... are only 2 special access folders, on which I turned off 'Include Inherited ... I tried gpupdate on client and server to no avail. ...
    (microsoft.public.security)