Event Type: Error Event Source: Userenv Event Category: None Event ID: 1030 Date: 6/11/2006 Time: 3:10:50 p.m. User: NT AUTHORITY\SYSTEM Computer: PRODISA03 Description: Windows cannot query for the list of Group Policy objects. Check the event log for possible messages previously logged by the policy engine that describes the reason for this.
Event Type: Error Event Source: NETLOGON Event Category: None Event ID: 5783 Date: 6/11/2006 Time: 3:10:49 p.m. User: N/A Computer: PRODISA03 Description: The session setup to the Windows NT or Windows 2000 Domain Controller \\PRODDC01.prod.local for the domain PROD is not responsive. The current RPC call from Netlogon on \\PRODISA03 to \\PRODDC01.prod.local has been cancelled.
Event Type: Error Event Source: NETLOGON Event Category: None Event ID: 5719 Date: 6/11/2006 Time: 3:10:50 p.m. User: N/A Computer: PRODISA03 Description: This computer was not able to set up a secure session with a domain controller in domain PROD due to the following: The remote procedure call was cancelled. This may lead to authentication problems. Make sure that this computer is connected to the network. If the problem persists, please contact your domain administrator.
ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain.
Event Type: Error Event Source: Kerberos Event Category: None Event ID: 7 Date: 6/11/2006 Time: 3:10:50 p.m. User: N/A Computer: PRODISA03 Description: The kerberos subsystem encountered a PAC verification failure. This indicates that the PAC from the client PRODISA03$ in realm PROD.LOCAL had a PAC which failed to verify or was modified. Contact your system administrator.
Have you setup your ISA for Domain communications (LDAP/Kerberos...) ? Does not looks like.
Once ISA is installed everything is locked down, no traffic at all.
The normal Windows communications are already defined in the firewall settings, they are hidden per default, you can access them by using Firewall Policy > Quick panel, Task tab then Edit system policy rules. Make sure you ISA server is set up properly in the network settings.
< Message edited by Boedus -- 7.Nov.2006 3:38:00 PM >
Posts: 12
Joined: 3.May2006
From: New Zealand
Status: offline
Hi,
just double checked it - the system policy allows access to the internal network for all domain related stuff. The strange thing is that dcdiag and netdiag are working without reporting any errors....