The response comes back with one of the following server names: prisoner.iana.org blackhole-1.iana.org blackhole-2.iana.org These servers own the public PTR records for the 192.168.x.x zones. Also let me know if there are any references/known issues in regards to above scenario. - Charles Derber Moved by Carey FrischMVP Monday, September 17, 2012 7:10 AM Moved to more The 1006 and 1030 events showed me a disconnected user still logged onto this server, through his terminal server session. x 100 Jens Tolkmitt This event may be recorded if the SID of a domain client is not valid. http://www.eventid.net/display-eventid-40960-source-LSASRV-eventno-8508-phase-1.htm

You only confirmed that issue has been resolved just by rebooting the servers. To fix this issue, you need to remove the client from domain. x 9 EventID.Net This event might occur if a scheduled task cannot access a shared network resource. Restart the server (this forces the DC to get a Kerberos ticket from one of the other DCs). 4.

x 11 Dale Smith In my case, a WinXP workstation logged events 40960 and 40961 from source LsaSrv as well as event 1053 from source UserEnv. The solution seems to be adding DNS as a dependency to these services. After a support call with Microsoft, it was determined that somewhere between his home machine and our RRAS server, the Kerberos UDP packets were being fragmented, hence any authentication was failing https://social.technet.microsoft.com/Forums/windows/en-US/d977ad57-5178-4c7c-acf5-2542970ec238/all-windows-xp-issue-with-windows-2008-r2-domain-controller?forum=winservergen x 14 Anonymous If you are getting this combined with event id 40961 from source LsaSrv, check for a missing Client for Microsoft Networks in your network components.

In this scenario, the Windows Time service (W32Time) tries to authenticate before Directory Services has started. What Is Lsasrv This is either due to a bad username or authentication information (0xc000006d)" - From a newsgroup post: "I've had the same problem, and I am almost positive I found a working This solved our issue. x 53 Anonymous It might be necessary to adjust the MTU on the router interface or on the server itself.

Thank you! http://3ecommunications.net/event-id/lsasrv-40960-automatically-locked.html machine are not facing any issues and working fine.Authentication related(Kerbores) issues with different machines(DC/ISA/Application Srv) logged in event id 49060.Checked if the users account were locked out but wasn't. Our solution was to change kerberos auth to use TCP packets instead of UDP and also to lower the MTU of the interface. TIMMCMIC Reply Skip to main content Follow UsArchives May 2016(1) All of 2016(1) All of 2015(13) All of 2014(14) All of 2013(16) All of 2012(14) All of 2011(28) All of 2010(28) Event Id 40960 Lsasrv Windows 7

This allows the customer to open one package for a surgical procedure instead of many individual packages. Set the KDC service to “Automatic”. 6. About 15 computers (Windows XP Pro, dual core, 4 gb ram). this contact form I can connect with my Cisco VPN client just fine, but both Outlook and SQL Server fail with this error when I try to connect to either at the problem hot-spots.

The computer then started normally. Lsasrv 40961 What is an authentication protocol? English: This information is only available to subscribers.

Removing Kerberos (TCP 88) port from http inspection resolved problem.

All rights reserved Use of this Site constitutes acceptance of our User Agreement (effective 3/21/12) and Privacy Policy (effective 3/21/12), and Ars Technica Addendum (effective 5/17/2012) Your California Privacy Rights The It should be noted that the default for Windows 2003 is a LMCompatabilityLevel of 2. x 11 Moki I experienced this problem over VPN from some hot-spot locations and not others. The Security System Detected An Authentication Error For The Server Cifs This is either due to a bad username or authentication information. (0xc000006d)".

I found that the credentials used to access that server from the XP computer were not the ones of the user logged in but belonged to a long gone employee. The Application log contains EventID 1219 from source Winlogon, message “Logon rejected for . What is Kerberos? navigate here What is the role of LsaSrv?

x 9 PK We were also getting this error on a Windows 2003 Member Server (in a Windows 2003 AD) which had its own DNS Server Service Running. x 109 Anonymous We had this problem with two domain controllers (two separate domains with trust relationship) in two cities connected through Internet using OpenVPN. We can reference the following Knowledge Base Articles - ME291382 Frequently Asked Questions About Windows 2000 DNS. In the case where the DNS Server used does not have the Reverse Lookup Zone and/or no PTR Record for their DNS Server, the request gets forwarded out to the Internet.

x 9 PK We were also getting this error on a Windows 2003 Member Server (in a Windows 2003 AD) which had its own DNS Server Service Running. x 109 Anonymous We had this problem with two domain controllers (two separate domains with trust relationship) in two cities connected through Internet using OpenVPN. We can reference the following Knowledge Base Articles - ME291382 Frequently Asked Questions About Windows 2000 DNS. In the case where the DNS Server used does not have the Reverse Lookup Zone and/or no PTR Record for their DNS Server, the request gets forwarded out to the Internet.

Using the procedure in ME325850 reset the machine account password. 5. We found that we were having issues where users had slow logins when connected to a network drive and operated normally when not connected to a network drive. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LsaKerberos\Parameters\MaxPacketSize=1 Note: On his XP Professional w/SP1 client, I had to create the Parameters subkey and MaxPacketSize DWORD value manually. The PC would attempt normal Kerberos interactions with the server and the server would log this event.

I had this fixed as follows: 1. Even with 5 minutes per server (to check the logs and other parameters), it may take an hour to make sure that everything is ok and no "red lights" are blinking It was randomly losing connection with DC and only re-joining in domain solved this issue. Each have their own username/password to sign on.All map to a single network drive (called the P or Public drive)2 computers will randomly lose connection to the P drive throughout the

