Re: Another Event 529
- From: "Maxibo" <totallyanon@xxxxxxxxx>
- Date: Mon, 1 May 2006 23:50:12 +0100
Hi Terry
Unsure if you know about eventid.net...
http://www.eventid.net/display.asp?eventid=529&eventno=1&source=Security&phase=1
What 'source' is creating the 529 logon type, 3 ?
"Terry M" <terrym@xxxxxxxxxxxxxxxxxx> wrote in message
news:uddWGJtaGHA.4292@xxxxxxxxxxxxxxxxxxxxxxx
I don't seem to get any w32Time errors, I went through
http://support.microsoft.com/kb/816042 "How to configure an authorative
time seerver in Windows 2003"
After restarting the service about 18hr ago I still have almost 600 of
these 529 errors.
Terry Mc
"Maxibo" <totallyanon@xxxxxxxxx> wrote in message
news:erXw5NjaGHA.508@xxxxxxxxxxxxxxxxxxxxxxx
Hi Terry, I can only say that when I had these issues it was related to
time syncing... 2 pcs were not in sysnc with the server...
"Terry M" <terrym@xxxxxxxxxxxxxxxxxx> wrote in message
news:O$$taDiaGHA.1348@xxxxxxxxxxxxxxxxxxxxxxx
I have a fully patched SBS Prem box SP1 without ISA. I use Trend CSM, and
we
using a Symantec Corporate Firewall.
I am loging hundreds of NT AUTHORITY\SYSTEM Logon failures from my
workstations like seen below.
They generally come in groups of four, for the same workstation with
different Source Ports. All workstation seem to be getting triggering
the
same event with different Source Port #'s.
I recently did a hard drive upgrade and restored the Server from backup.
I
did my SBS SP1 at that time.
Everything in the network seems to be working fine, my Trend AV scans
did
not find anything. I have an issue with my XP laptop giving me a
"applnch.exe - Entry Point Not Found" but I did not think this was
related.
Any ideas as to what is going on here?
Thanks
Terry Mc
****
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 4/25/2006
Time: 10:57:38 AM
User: NT AUTHORITY\SYSTEM
Computer: SBSServer
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name:
Domain: ADMIN1
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: ADMIN1
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 192.168.16.38
Source Port: 4668
.
- Prev by Date: Re: Need help setting up a subnet for a test lab.
- Next by Date: Re: Please Help No good backup & Companyweb Down.........
- Previous by thread: Frequent Event 529 Second Post
- Next by thread: Re: Message to Frank McCallister
- Index(es):
Relevant Pages
|
Loading