GWIA Relay Issue, maybe the SPAMmers authenticated...

So I was greeted with a lovely issue this morning that is really driving me nuts. My mail system was relaying messages from [email protected] using a valid user on my system (MFouch). The IP address that was sending the messages appears to be in Lagos, Nigeria (41.203.64.250). I have been combing my GWIA, MTA, and POA logs and I am not seeing any POP/IMAP/SMTP auth from that IP address. The valid local user that was being abused "C/S dos" login was getting logged but from GWIA's internal IP address. I attached a MIME copy of the message.
My GWIA agent is setup to prevent relaying. I do allow relaying from some specifically defined internal addresses. I do allow POP3 in, but only specific users can use IMAP4 (silly Android issue). I require authentication for both POP3, IMAP4, and SMTP. I ran all of the different open relay tests that I am aware of (abuse.net, mxtoolbox.com) as well as tried to relay something via telnetting to my GWIA. I have attached my current GWIA flags as well. I just added /disallowauthrelay for now as a test/precaution.
I found TID 7008712 that confused, upset, and scared me all at the same time (GroupWise Internet Agents are relaying emails when they're not suppose to be relaying.). If what this TID says is correct, how can I continue to use GroupWise?
It looks like I have stopped the trouble for now. I added /disallowauthrelay as per TID7008712 (which will probably upset a few people). I renamed my gwac.db in case there was some corruption in my SMTP access control list. I changed the abused local user's password. I renamed all of my various GWIA directories (000.PRC, DEFER, GWHOLD, GWPROB, RECEIVE, RESULT, SEND, WPCSIN, and WPCSOUT) just to give me some time to clean out all of the deferrals, send items, and to be sure there is not a message queued somewhere. Members of my team are scanning the two machines this user uses as a precaution. I have also explicitly denied 41.203.64.250 access to my network at my perimeter.
Has any of the great minds out there in the Novell Forum Land seen this before or can point out my buffoonery?
Thanks in advance,
Jeff

Hi.
I'm not quite sure where the uncertainty lies. The user yo uidentified
with the logins from GWIA has been hacked, e.g his password probably was
weak and brute forced, or gained by other means (has this user been in
nigeria recently? ;))
I also don't quite understand the outrage on the TID. It merely explains
what is logical. If someone can authenticate, he can relay. There's
nothing to be overly concerned about, except your password security. You
may want to activate intruder detection... Of course there are other
means to possibly gat to know a users password, but brute force is the
usual way...
On 29.09.2011 18:16, jcrawfor wrote:
>
> So I was greeted with a lovely issue this morning that is really driving
> me nuts. My mail system was relaying messages from [email protected]
> using a valid user on my system (MFouch). The IP address that was
> sending the messages appears to be in Lagos, Nigeria (41.203.64.250). I
> have been combing my GWIA, MTA, and POA logs and I am not seeing any
> POP/IMAP/SMTP auth from that IP address. The valid local user that was
> being abused "C/S dos" login was getting logged but from GWIA's internal
> IP address. I attached a MIME copy of the message.
>
> My GWIA agent is setup to prevent relaying. I do allow relaying from
> some specifically defined internal addresses. I do allow POP3 in, but
> only specific users can use IMAP4 (silly Android issue). I require
> authentication for both POP3, IMAP4, and SMTP. I ran all of the
> different open relay tests that I am aware of (abuse.net, mxtoolbox.com)
> as well as tried to relay something via telnetting to my GWIA. I have
> attached my current GWIA flags as well. I just added /disallowauthrelay
> for now as a test/precaution.
>
> I found TID 7008712 that confused, upset, and scared me all at the same
> time ('GroupWise Internet Agents are relaying emails when they're not
> suppose to be relaying.' (http://tinyurl.com/3ls65sc)). If what this
> TID says is correct, how can I continue to use GroupWise?
>
> It looks like I have stopped the trouble for now. I added
> /disallowauthrelay as per TID7008712 (which will probably upset a few
> people). I renamed my gwac.db in case there was some corruption in my
> SMTP access control list. I changed the abused local user's password.
> I renamed all of my various GWIA directories (000.PRC, DEFER, GWHOLD,
> GWPROB, RECEIVE, RESULT, SEND, WPCSIN, and WPCSOUT) just to give me some
> time to clean out all of the deferrals, send items, and to be sure there
> is not a message queued somewhere. Members of my team are scanning the
> two machines this user uses as a precaution. I have also explicitly
> denied 41.203.64.250 access to my network at my perimeter.
>
> Has any of the great minds out there in the Novell Forum Land seen this
> before or can point out my buffoonery?
>
> Thanks in advance,
> Jeff
>
>
Massimo Rosen
Novell Knowledge Partner
No emails please!
http://www.cfc-it.de

Similar Messages

  • Ram Issues with a Hp Pavilion a6357c or maybe the amd athlon 64 5000+

    I am really not sure if I am in the area-of a post like this. Please excuse my grammar and spelling"will try and use spell check"...
    I got this computer from a friend of mine.Total nightmare. Was told all it needs is a hard drive and maybe a video card..Boy was that not the issue. I first got it and plugged it-make sure it would boot to bios..Nothing computer turned on-fans and all..Nothing on the screen. To make a long story short...I found an old ps2 mouse..The mouse was defective...with that mouse plugged in-computer wouldn't even boot to bios..Fixed that issue. Got into bios and all was good. Next step..Video card-Bought a new pny 9500 GT and a TTGI 550 power supply....swaped it all out and it works great...Than found a hard drive SATA 2...everthing installed and ready to place an operating system on....
     Windows 7 64 bit--Installed great...But when it came up to the start up---Freeze--blue screen...Ok thought maybe it was the ram.....ended up taking all the old ram out and replace it with some DDR2 6300--or what ever the max was...total of 6 gb...still issue...freezing--decided to boot into safe mode---all good and ran great....checked Ram-stress test-checked every little hardware--stress test-no issues...Booted back up out of safe mode... Same issues....ok--lets just try Windows 7 32 bit.....
    Windows 7 32 bit.....Install went great-no issues....updated and all the sp's...but underload----bluescreen....played and played with it...but the blue screen were all over the place...back into safe mode and checked all the drivers--and devices....Ok lets just go back to what the system had----windows Vista....
     Again----everything boot and installed perfect...This time was a liitle more stable...updates--all the sp's all the drivers.....
    Blue screen underload......Ok maybe my ram is at fault.......
    It ended up stable and working perfect---single channel mode-2 gb in the first slot....I tried every way to put the ram in.....
    found out--ok---only stable in single channel mode...anytime I added ram--for dual channel...Fail under load....Put the 2 gb stick or a 1 gb stick any any of the other slots-by itself---perfect stable and running great...I was even able to add another 1 gb stick with the 2 gb stick---but it had to be in single channel....tried to add more in single channel and fail....3 is it and it is not all the way stable--but stable enough to run...2 gb stick by itself---perfect.........
    Did some digging---maybe it is the memory controller...But can not find any post with this issue---I keep finding people asking the quesion--and there storys match...But no answers and it seems that the just get a walk around.....
    I have narrowed it down..It has to me the intergrated memory controller on the chip....so i think...I could just purchase a new one and swap it out........But here is the issue...........
    Safe Mode will take all the ram-dual channel---single channel..anyway.......But so will linix-----Only has this issue with Windows....
    The other werid item too---My had drive say scis drive or something along that lines--Not sata.....and again-I can not find a post to explain why......
    Please understand----Stress test on Ram-cpu-motherboard--videocard----everthing--is perfect no issues...PSU is perfect---checked it out in another sytem---no issues....I am at my witts end with this thing and I have got nowhere......
    It is working great with just a 2 gb stick of ram---very fast and very responsive....But adding extra ram really bothers me...Not because--it make a differance-Just because I don't know...
    Can somebody out there school me.....I have tried everything........

    Sorry all-But i never got a reply to this situation. But I am done. I ended up running threw tons of post and tons of threads. I can tell you that when people ask a question. There is always some smart A--, telling them something that has nothing to do with the current situation. I guess alot of people out there think they know everything- and have nothing to do-but mess with the people like me when they are stumped. Anyways...I ended up running a computer check in or after bios...I think they call it burned in-HP....what ever-the last straw when you can not figure it out..Ran it with one stick---than with all the sticks..Everytime--it claimed that there was nothing wrong..But when I tried to restart it--boom blue screen..with the mulyi sticks of ram. So when I couldn't find an solution online...I stoped using the words HP a6357c.. and just typed the issue..Funny thing the issue kept poping up--and with the same motherboard or processor...and again-nobody ever came up with a solution..Most of the post claimed the issue was the power supply....ot the ram timming..But I know better..Not to mention people kept saying-buy the tool from ebay to check wattage usuage.....Bam----wattage...Did a simple check with harware monitor...my 3.5 or 3.3 rail was running at 1.78....enought to power one stick of ram---not 2...or barley enough to power a 1 gb stick and a 2 gb stick in single channel mode...Again-people were blaming--PSU"not my case".Ram Timming.."not my case".........Then I found a person with the same make and model.....Look for fat or bad capasitors...Never thought of that.....Guess what------That is what I found....No body but a thread-one thread has explained...If you have this same issue-Look at the capasitors...Maybe this is a defective motherboard--you can not find it on the site anyway-no specs nada..like it was a mistake..So if you have one just like this- I have a feeling-you will run into this issue-in one way or another..I just don't understand why both companys have no fix--or no--recall info..No answers to problems on these....now I have a big black paper weight.....sorry for my spelling and grammer-just so mad..the net was no help on this

  • Issue with the Authentication mode:

    Hello Guru's
    I have installed P6 Primavera and when I am trying to login to
    http://localhost:8080/primaveraweb/action/login
    It is giving the below error -
    "Primavera P6 was configured to use a different authentication mode that the database selected"
    I checked the authentication mode in the P6 Administrator scrren where it shows that the
    Authentication
    Mode: NATIVE
    Web Single Sign-On
    User Name Header Key: OAM_REMOTE_USER
    Context Path Override: /primaveraweb
    Server and Port override: http://<hostname>:8080 ----- I can see the correct hostname address.
    Gurus, please help me on this ASAP.
    Thanks
    Venu

    Hello Guru's,
    I could able to resolve the error by following the Admin Guide.
    This error is because you have migrated the PSUP database which is having the LDAP authentication mode, but the P6 Primavera is in NATIVE authentication mode.
    NOTE: A configuration for P6 Web Access might include database instances that are not set to the same authentication mode as the server of P6 Web Access.
    If a user connects and requests a database that is set to a different authentication mode than the server of P6 Web Access, an error message displays.
    The user must select a database that matches the authentication mode set for the server of P6 Web Access.
    I resolved the issue using the below steps:
    Run the D:\Oracle\installers\Enterprise Project Portfolio Management\P6_70_Client_Applications\install\database\ldap-config\ LDAPCfgWiz.exe
    Login as privuser for PMDB and select the authentication mode as “NATIVE”
    Login as privuser1 for MMDB and select the authentication mode as “NATIVE”
    Bounce the P6 Admin Server.
    Thanks
    Venu

  • Windows 2008 R2 smtp server Relay only selected servers without authentication

    Hello,
    Need help in configuring Windows SMTP server.
    Windows 2008 R2 Server. SMTP service is installed and configured.
    Access TAB -- Authentication TAB -- Anonymous Access is selected..
    Relay TAB -- Only the list below is selected and specfic scanners and application servers IPs are mentioned.
    Issue: Even though we have specified list of IPs to relay from this server, Anybody can send mails using this server ( open Relay )
    -- My requirement is to relay specific IPs of scanners and App servers without any authentication, can anybody help me configure windows smtp server to achieve my requirements.
    Any help will be highly appreciated.
    Regards,
    Ghouse

    Hi,
    I recommend you refer to the following article to configure the smtp server:
    Setup and Configure SMTP Server on Windows Server 2008 R2
    In addition, you should ask this in Windows server forum as this is not an exchange problem:
    http://social.technet.microsoft.com/Forums/en-US/home?forum=windowsserver2008r2webtechnologies
    Thanks.
    Niko Cheng
    TechNet Community Support

  • [Cisco ACS] 11036 The Message-Authenticator RADIUS attribute is invalid

    Hi,
    I got many Cisco AP which are linked to 2 Cisco WLC.
    On each WLC, I configured a primary and a secondary RADIUS Server.
    RADIUS servers are Cisco ACS 5.2.0.26 (patch 10)
    Primary and secondary ACS configurations are synchronized.
    There are no problem between primary WLC and Cisco ACS (primary and secondary).
    When secondary WLC requests primary Cisco ACS, I get this error "11036 The Message-Authenticator RADIUS attribute is invalid"
    Secondary WLC automatically contacts secondary Cisco ACS and it works fine.
    Cisco ACS description for this error: "This maybe because of mismatched Shared Secrets."
    The two Cisco ACS are synchronized so I should have same error on them...
    Why does primary ACS generate this error?
    Thanks for your help,
    Patrick

    Tarik Admani wrote:Amjad,That is a good observation, shouldnt 7.3 (which recently released) help put these types of issues to rest? I hear that the configuration can now be replicated from one controller to the next in a failover setup.Thanks,Tarik Admani
    *Please rate helpful posts*
    Yes. That is a good point.
    With 7.3 you can use high availability (HA) between two WLCs and you can configure only one WLC (the primary) and all the configuraiotn can be replicated and synched to the other WLC (the secondary).
    The two WLCs in the HA must be on same subnet though. Otherwise hot-standby HA between WLCs can't be used.
    Rating useful replies is more useful than saying "Thank you"

  • Exchange 2003: Collab/Notification email relay issues

    We use Exchange 2003 SMTP email server which is open internally and has relaying disabled.
    The portal is installed on internal servers yet is having a problem sending notifications to external email addresses.
    In the notification config file there are settings for email servers that have relaying disabled however this functionality doesn't work and the bug ticket for it has been opened for 4 years I'm told.
    I'm wondering how smaller companies (<2000 employees) handle this issue.
    Do you:
    *enable relaying on your main email servers?
    *setup a notification specific SMTP server?
    *use a 3rd party email company?
    What steps are there to reduce the threat of spammers and blacklists while still allowing email to be relayed?
    I'm trying to work through this with our IT department but the idea of enabling relaying is a very touchy subject here as we have been burned by being blacklisted a few times in the past.
    Thanks for any help!
    Geoff

    After going back and forth with Plumtree support for about 3 weeks we have solved the problem.
    The problem came from a misunderstanding on what needed to be relayed. It turns out that external relaying is not needed, but internal relaying is.
    Explicitly granting trust to the notification server allowed emails to begin flowing.
    Geoff

  • GWIA sending issues!

    Hi,
    Not sure if anyone will be able to assist with the information I supply!
    We have 2 x GWIA's in 2 different physical locations in London each servicing 1 x domain and 3 x PO's each. For some weird reason one the of the GWIA's suddenly stopped sending outbound external mailo, inbound external mail seems to be working ok.
    The GWIA's run on Netware 6.5 SP6 and we run Groupwise 7.0.4 - nothing has changed on our network, our internet links are fine, no firewall changes etc. Our outbound/inbound external mail routes via Postini but their tech support can see both GWIA's communicating with their servers.
    I have checked the SEND folder on the problem GWIA and there are a few messages in there of 0KB but not a massive backlog of e-mails.
    I don't see anything screaming out "problem" in the log file.
    Temporarily I have routed e-mails for the three PO's that cannot send, out via the other GWIA to enable them to send out external e-mail.
    Any advice welcome.
    Thank you
    Mike

    Glad that all is working
    Maybe see you soon
    T
    On Tue, 10 Jan 2012 11:21:11 GMT, "Mike Goodson"
    <[email protected]> wrote:
    >Hi Tim,
    >
    >Thanks for your message. I carried on looking into the problem and "resolved" it although I assume the thing I did actually resolved the issue rather than it resolving itself!
    >
    >I noticed hundreds of IMAP requests hitting the GWIA - then realized we had a DNS entry assigned to the external IP on the DMZ, so I disabled IMAP on the GWIA. Pretty much as soon as I did this I was able to send external outbound e-mail - coincidence? I assumed that all the IMAP requests from devices may have caused the problem?
    >
    >Anyway, I did follow your recommendations below just out of interest but found that MTP on GWIA was set to port 0 so obviously we don't use that.
    >
    >Kind regards
    >Mike
    >
    >"Tim Heywood (NKP)" <[email protected]> wrote in message news:[email protected]...
    >> Morning Mike,
    >>
    >> Something has to have changed - not nessisarily of your doing.
    >>
    >>
    >> First are you using MTP? If you look at the domain that hosts the
    >> broken GWIA look at the mslocal\mshold directory you will find a
    >> directory that corespons to the GWIA (in each of the folders there you
    >> will see a file name "mtaname" find the one that coresponds to the
    >> GWIA and then see how big it is - if very large. Simple resolutoin of
    >> that would be to stop and then start both the Domain and the GWIA. To
    >> check the MTP usage, look in ConsoleOne, GWIA, GroupWise tab, Network
    >> Address - does the top box (message transfer protocol) have a number
    >> in there? 0 would be unot used, 7102 would indicate that it is and
    >> the port uses is indeed 7102.
    >>
    >> Have a look and if that isn't it we can move down the queue
    >>
    >> T (up north)
    >>
    >>
    >> On Sat, 07 Jan 2012 14:17:45 GMT, "Mike Goodson"
    >> <[email protected]> wrote:
    >>
    >>>Hi,
    >>>
    >>>Not sure if anyone will be able to assist with the information I supply!
    >>>
    >>>We have 2 x GWIA's in 2 different physical locations in London each servicing 1 x domain and 3 x PO's each. For some weird reason one the of the GWIA's suddenly stopped sending outbound external mailo, inbound external mail seems to be working ok.
    >>>
    >>>The GWIA's run on Netware 6.5 SP6 and we run Groupwise 7.0.4 - nothing has changed on our network, our internet links are fine, no firewall changes etc. Our outbound/inbound external mail routes via Postini but their tech support can see both GWIA's communicating with their servers.
    >>>
    >>>I have checked the SEND folder on the problem GWIA and there are a few messages in there of 0KB but not a massive backlog of e-mails.
    >>>
    >>>I don't see anything screaming out "problem" in the log file.
    >>>
    >>>Temporarily I have routed e-mails for the three PO's that cannot send, out via the other GWIA to enable them to send out external e-mail.
    >>>
    >>>Any advice welcome.
    >>>
    >>>Thank you
    >>>Mike

  • DHCP relay issues - WLC4400 series

    Hi all,
    I'm experiencing some strange problems with my WLC 4400 – and hope you guys can give me a hand.
    There is an issue while connecting a WLAN Client to the WLC for the first time. I pinpointed the source of the problem to the dhcp, but I wondering why this happens…
    As stated above – the issue occurs only during the first time registration of a WLAN client with the WLC. If I do another registration right after the failed connection attempt, the session is established and I can start working in my network environment.
    Because we use 802.1x authentication, my first idea was that there is an issue – but the authentication process completes successfully.
    Another debug for the dhcp process showed an issue during the initial registration process. I'll paste an extract of the NOT working connection attempt below (DHCP DISCOVER msg and DHCP OFFER msg passed successfully – I'll focus on the DHCP REQUEST msg):
    ###### Extract one ######
    Tue Mar  9 09:51:31 2010: 00:21:6a:00:35:9c dhcpProxy: Received packet: Client 00:21:6a:00:35:9c
                            DHCP Op: BOOTREQUEST(1), IP len: 303, switchport: 29, encap: 0xec03
    Tue Mar  9 09:51:31 2010: 00:21:6a:00:35:9c dhcp option len, including the magic cookie = 67
    Tue Mar  9 09:51:31 2010: 00:21:6a:00:35:9c dhcp option: received DHCP REQUEST msg
    Tue Mar  9 09:51:31 2010: 00:21:6a:00:35:9c dhcp option: skipping option 61, len 7
    Tue Mar  9 09:51:31 2010: 00:21:6a:00:35:9c dhcp option: requested ip = 10.64.153.66
    Tue Mar  9 09:51:31 2010: 00:21:6a:00:35:9c dhcp option: server id = 1.1.1.1
    Tue Mar  9 09:51:31 2010: 00:21:6a:00:35:9c dhcp option: skipping option 12, len 12
    Tue Mar  9 09:51:31 2010: 00:21:6a:00:35:9c dhcp option: vendor class id = MSFT 5.0 (len 8)
    Tue Mar  9 09:51:31 2010: 00:21:6a:00:35:9c dhcp option: skipping option 55, len 12
    Tue Mar  9 09:51:31 2010: 00:21:6a:00:35:9c dhcpParseOptions: options end, len 67, actual 67
    Tue Mar  9 09:51:31 2010: 00:21:6a:00:35:9c dhcpProxy: dhcp request, client: 00:21:6a:00:35:9c:
                            dhcp op: 1, port: 29, encap 0xec03, old mscb port number: 29
    Tue Mar  9 09:51:31 2010: 00:21:6a:00:35:9c Determing relay for 00:21:6a:00:35:9c
                                                                                                            dhcpServer: 10.49.143.8, dhcpNetmask: 0.0.0.0,
                            dhcpGateway: 0.0.0.0, dhcpRelay: 0.0.0.0  VLAN: 0
    Tue Mar  9 09:51:31 2010: 00:21:6a:00:35:9c Relay settings for 00:21:6a:00:35:9c
                                                                                                            Local Address: 0.0.0.0, DHCP Server: 10.49.143.8,
                            Gateway Addr: 10.64.153.1, VLAN: 0, port: 29
    Tue Mar  9 09:51:31 2010: 00:21:6a:00:35:9c dhcpProcessPacket return an error,chaddr: 00:21:6a:00:35:9c
    The process stops working after the last line above. The client reports connection successfully, but no IP address was assigned to the client. A second connection attempt was successful (again – I'll focus on the dhcp REQUEST msg – ignoring DISCOVER, OFFER and ACK msg):
                            DHCP Op: BOOTREQUEST(1), IP len: 303, switchport: 29, encap: 0xec03
    Tue Mar  9 09:53:02 2010: 00:21:6a:00:35:9c dhcp option len, including the magic cookie = 67
    Tue Mar  9 09:53:02 2010: 00:21:6a:00:35:9c dhcp option: received DHCP REQUEST msg
    Tue Mar  9 09:53:02 2010: 00:21:6a:00:35:9c dhcp option: skipping option 61, len 7
    Tue Mar  9 09:53:02 2010: 00:21:6a:00:35:9c dhcp option: requested ip = 10.64.153.66
    Tue Mar  9 09:53:02 2010: 00:21:6a:00:35:9c dhcp option: server id = 1.1.1.1
    Tue Mar  9 09:53:02 2010: 00:21:6a:00:35:9c dhcp option: skipping option 12, len 12
    Tue Mar  9 09:53:02 2010: 00:21:6a:00:35:9c dhcp option: vendor class id = MSFT 5.0 (len 8)
    Tue Mar  9 09:53:02 2010: 00:21:6a:00:35:9c dhcp option: skipping option 55, len 12
    Tue Mar  9 09:53:02 2010: 00:21:6a:00:35:9c dhcpParseOptions: options end, len 67, actual 67
    Tue Mar  9 09:53:02 2010: 00:21:6a:00:35:9c dhcpProxy: dhcp request, client: 00:21:6a:00:35:9c:
                            dhcp op: 1, port: 29, encap 0xec03, old mscb port number: 29
    Tue Mar  9 09:53:02 2010: 00:21:6a:00:35:9c Determing relay for 00:21:6a:00:35:9c
                                                                                                            dhcpServer: 10.49.143.8, dhcpNetmask: 0.0.0.0,
                            dhcpGateway: 0.0.0.0, dhcpRelay: 10.64.153.6  VLAN: 300
    Tue Mar  9 09:53:02 2010: 00:21:6a:00:35:9c Relay settings for 00:21:6a:00:35:9c
                                                                                                            Local Address: 10.64.153.6, DHCP Server: 10.49.143.8,
    The major difference seems to be in line 16:
    Not Working:
                            dhcpGateway: 0.0.0.0, dhcpRelay: 0.0.0.0  VLAN: 0
    Working:
                            dhcpGateway: 0.0.0.0, dhcpRelay: 10.64.153.6  VLAN: 300
    For me it seems that the WLC is not able to forward this request to the appropriate dhcp server.
    Does anyone of you have an idea, why this happens? And why does this happen only during the first time login of every client? Or am I misinterpreting the debug output?!
    Thx a lot in advance!
    Cheers
    Martin

    Hi,
    thx for your comment so far.
    I did some additional troubleshooting yesterday and I guess I fixed the problem. The management interface was configured with two dhcp server IPs (0.0.0.0 and 1.1.1.1).
    Within the Cisco documentation it is stated that the dhcp relay proxy feature uses a virtual IP 1.1.1.1.
    0.0.0.0    seems to be used for the internal communication.
    When I changed the dhcp address (primary & secondary) to IP 1.1.1.1 the problem was solved. We tested it yesterday evening and this morning.
    My assumption is that the virtual 1.1.1.1 IP is mandatory to match the dhcp responses to the proxy relaying feature. Or the WLC uses the DHCP addresses on the management interface to forward the traffic to the appropriate feature (where 1.1.1.1 triggers the proxy feature and 0.0.0.0 is used to forward the traffic to the internal dhcp service). But this is just a guesswork – I do not know the Cisco WLAN good enough to provide a valuable explanation.
    Cheers
    Martin

  • I changed nothing in my email account but can no longer send emails on my talktalk account and get the message, "authentication required." I am running Mavericks on my MacBook Pro. I can receive messages on talktalk. Can send

    I changed nothing in my email account, talktalk.net, but can no longer send (server's response, "authentication required) No problem receiving, I am using Mavericks on my MacBookPro. No problem using Cloud, but I want to use my talktalk account as before the problem
    I can send and receive using talktalk without any problems using my iPod and iPad.
    I would be most grateful for help - in simple form, please, I am an 80 plus female Mac lover!

    Hello Hazel139,
    I found this in one of the similar post hope it helps you.
           Level 6 (14,190 points)             
    X423424X 
    This helped meRe: Problem SENDING email     Jun 17, 2012 1:40 PM    (in response to Casanewton) 
    The error I see is you did not specify the proper authentication for the smtp server.
    In the Mail preferences for the account, smtp popup, select Edit SMTP Server List.  A sheet will drop down.  Select Advanced tab on that sheet.  You should, I assume, set the Authentication to password, and set the proper username and password.  That's where the poper would be set if 587 is not the one you should be using.  Maybe it is.  I only bring it up since I see it trying to use port 587.
    If you got this stuff already set correctly then I don't know.  Mail has a problem in your setup.  Maybe delete the account and recreate it from scratch.
    https://discussions.apple.com/message/18670442#18670442

  • Issue with form based Authentication in three tier sharepoint 2013 environment.

    Hi,
    We are facing issue with form based Authentication in three tier environment.
    We are able to add users to the database and in SharePoint.
    But we are not able to login with created users.
    In single tier everything working fine
    Please help , Its urgent ... Thanks in advance.
    Regards,
    Hari
    Regards, Hari

    if the environments match, then it sounds like a kerberos double-hop issue
    Scott Brickey
    MCTS, MCPD, MCITP
    www.sbrickey.com
    Strategic Data Systems - for all your SharePoint needs

  • I have a mid 2010 macbook pro 15" and recently it started crashing so I took it to my local Apple store to have it looked into and they told me its a graphics card issue requiring the replacement of the logic board at a cost to me of $340.

    I took my laptop to my local Apple store to have the problem diagnosed and they told me the problem lies in the grpahics card which will require the replacement of the entire logic board at a cost to me of $340.
    after that I did some research on the topic and found that this was a massive problem on this model of macbook pro and Apple never issued a recall to fix the issue, are there any class action suits in this category currently underway? if so how can I join?

    I also have a mid-2010 Macbook Pro 15". Also, I had paid $100 for Apple Developer account and I can't even use Xcode or Unity3D to work on my game because the moment I write a line of code, my computer crashes. Scratch that, I used to have an Apple Developer account (I let it expire a couple of weeks ago). It hasn't been of much use since my Macbook Pro crashes 15 times a day.\
    A month after buying a mid-2010 Macbook Pro 15" directly from Apple, it began to crash. At first, I assumed it was my fault as I had been messing around with Bootcamp and doing other heavy stuff, but I quickly learned it would randomly decide to shutdown regardless of the task at hand. I was very busy at the time. I was a fledgling teacher in France, and I hardly had any time, or money, to put toward a 84 euro train ticket to Paris. Also, OS X updates were around the corner (Lion, Mountain Lion), so I held out, hoping the issue would be resolved with the updates.
    During my investigation of the issue, I did find the TS4088 article. It recommended I install some updates, and then it described a problem that seemed similar to my own, but the order in which the problems occured, as described in the TS4088 article, did not follow the same pattern that my computer had been experiencing–there was no gray or black screen after the restart warning message when my mac crashed. The first time I found TS4088 on Apple's Support page (at a time when their product recalls were easier to locate before they redesigned their website), it was a couple of months after I had bought the computer. I reasoned that my Macbook Pro must not be suffering from the same issues as I had never seen the video freeze or go black before seeing a restart message. The restart warning message is the last thing I saw, no loss of video or black(or gray) screen afterwards. My computer would simply start to boot up again.
    About two years after buying the computer, and suffering from about 3 GPU panics a day, I searched for the TS4088 article again, wondering if I had misread it, and that maybe the issues described in the article were the same issues I was experiencing. This time I could not find the TS4088 article on Apple's Website. I searched over and over again, but it was nowhere to be found. I assumed that issue had been resolved and the article removed. Now after three years of using a faulty, unreliable computer, I was feeling like a schmuck. I searched again on Apple's website to find the TS4088 article, or any new ones that outlined my very apparent GPU issues, but I had no luck. I circled Apple's website over and over and could not find that article. It was only through a link other frustrated mid-2010 Macbook Pro owners had posted on some other website that I found the link to TS4088, also learning that the forum's users were experiencing my same problems.
    Based on the language Apple used to describe the problem, I did not reason that I was suffering the same issue. Here's what happens when my computer crashes:
         • The computer seems to shut down. The display turns off, the fans stop spinning
         • The message "Your computer was restarted because of a problem . . . Press any key to restart" is displayed.
         • I press any key, the computer restarts, I wait for next crash to interrupt my work
    Excerpt from TS4088
    "Symptoms
    Apple has determined that a small number of MacBook Pro (15-inch, Mid 2010) computers may intermittently freeze or stop displaying video on the built-in display or on an external display connected to the MacBook Pro. In this situation, you may also see a restart warning message before the video is lost or the display turns black or gray."
    My computer never displays a restart message before the video is lost or display turns black. My Macbook Pro mid 2010 loses the picture on the display, and less than a second after that is the restart warning displayed. The video would never freeze or stop playing, rather the whole computer just dumped all of its processes and displayed a warning message asking me to press any key to restart.
    My issues with this problem are the following:
    •The problems described in TS4088 do not accurately reflect what users are experiencing. TS4088 is misleading in this respect.
    •The article TS4088 was not easy to find on Apple's website. It seemed to have moved to an obscure, impossible-to-find location that could only be found thanks to the great number of other Mac users who are experiencing the same problem.
    This issue hasn't been managed dutifully. I'm annoyed to have sunk money into a developer account. I'm annoyed that I sunk money into an expensive product that does not work. I'm annoyed that the description of the issue afflicting mid 2010 Macbook Pros was inaccurately and misleadingly described and that links to the TS4088 article disappeared from Apple's website when I could have truly benefitted from them. I am especially annoyed that my life in graphic design, web development, and iOS development has stagnated for several months as my computer crashes some 15 times a day. I am, however, pleased with the speed at which a Mac can boot up.

  • Q: How can ISE 1.2 be configured to display "IP Address" in the Operations-Authentication view ?

    Hi Forum !
    I have several ISE installations running, and I have come across an Issue, that may or may not be a real issue.
    How can ISE 1.2 and/or the WLC be configured to display "IP Address" in the Operations-Authentication view ?
    I simply can not see any IP address in this field, when the dot1x Authentication is done on a WLC.
    This may be "works as designed" due to the fact that dot1x runs before the IP is assigned, but then again I do get profiler date etc, and hence I would expect the IP to be displayed.
    Please see attachment for clarification of the field in the ISE dashboard.
    FYI
    I do see IP in WIRED dot1x senarios, but then again I run LowImpact modes, as opposed to CloseMode in the WiFi senarios
    I have the same ono WLC OS 7.0, aswell as on 7.5 & 7.6 (i.e. no IP address shown in dashboard)
    Have Fun !
    Regards
    Martin

    I have seen this before but never really bothered to look more into it. It has always showed for wired but not wireless. I did some digging and it appears that the "framed-ip-address" is being sent/honored by the NAS in the "access-accept" packet.
    http://www.cisco.com/c/en/us/td/docs/wireless/controller/7-6/configuration-guide/b_cg76/b_cg76_chapter_0101001.html#ID676
    Why is it not showing in ISE's screen is now another quesiton. I would say a bug but I recall this since the 1.0 days and I have done several deployments. Perhaps Cisco can chime in here or if you can open a TAC case and report back your findings :)
    Thank you for rating helpful posts!

  • MacBook Pro 2008 display issue (see the photo)

    As you can see in the picture below, my 15" MBP Early 2008 started to experience this kind of issue. Sometimes it goes away if I close the lid or with a restart. I've already tried the PRAM reset with no long-term results.
    My Mac had the nvidia 8600M GT issue so I got the logic board replaced. At the Apple Store the technician said this problem has nothing to do with the video card... maybe the display? Anyway, I'd like to have your opinion about this and some possible solutions.
    Thank you!

    What you've pictured is a disaply backlight LED problem — it looks as though half of yours aren't lit. They're integrated into the LCD panel, and this issue is not related in any way to the replacement of your logic board. You may want to reset your computer's SMC and see whether that resolves the problem:
    http://support.apple.com/kb/HT3964
    If it doesn't, I'm afraid you're in for another repair, and this one will be on your dime unless you still have a little AppleCare coverage left.

  • K8N Neo3 Issues (At the end of my rope)

    The parts I have are as follows:
    1x K8N Neo3 MOBO
    1x Sapphire x1600 Radeon Video Card 512MB PCIE
    1x AMD64 Sempron +3000 (Socket 754)
    1x WD 100GB HDD
    1x WD 250GB HDD
    2x DRAM Master PC3200 DDR400 Memory Modules
    1x DWL D-Link 11.0Mbps Wireless USB Adapter
    1x LiteOn 16X DVD Dual Drive (ATAPI/E-IDE)
    Some things to note:
    All of the parts have been tested in other machines and work perfectly. I'm currently running XP Pro on a 15gig partition on the 100GB HDD. All of the drivers are installed on this partition as well as firefox. On the other partition on that drive, I have 3DMark05 and windows media player classic installed. Both partitioned were made after formatting the entire drive. On the 250GB HDD, I have some anime and various wallpapers. Hardware acceleration currently set to two notches left of full. All of the drivers are up to date, and I have flashed the BIOS.
    The problems:
    First off, my CD driver could not read CDs all too well. In the middle of installation I'd get tons of errors which was odd considering the fact that the CD (XP Pro) worked in other comps. After I flashed the BIOS however, this problem was removed, or rather, it pops up less frequently.
    Another issue I'm having is with the memory. Both memory modules work well, and were memtested with no errors, however, unless I go to Advanced Chipset Features in the BIOS and enter into DRAM Configuration and change the timing mode to manual, set the Memclock Index Value to 250MHZ and the CAS# Latency to 3, I can't boot into XP. Instead, it'll clear POST, and then pretend like it's going to take me to XP, and then reboot. On the issue with memory, it's interesting to note that with my old sempron processor (AMD 3200+), I don't have to change any BIOS settings to get the RAM to work.
    The next problem on the list is with my video card. As mentioned previously, it's a Sapphire x1600 Radeon 512MB PCIE and I can't get it to work on this system for the life of me. I tested the card in a friend's computer (uninstalled his drivers and installed mine before attempting) and it worked like a dream. In mine however, whenever I go to run a graphic intensive program such as 3DMark05, it locks up after about 10 seconds, some times sooner. Occaisonaly VPU will kick in, but usually I have to perform a reboot. Even the little car animation in catalyst control center locks up my computer. It's interesting to note however that when watching anime, that I can usually go about 2 or 3 episodes before my computer freezes up on me, or just reboots.
    It's interesting to note that my computer has not rebooted on me while surfing the net, or typing stuff up.
    Another issue is that it seems like I can't go 10 or 15 minutes without something shutting down, such as firefox, or msn messenger due to errors. I've reinstalled windows and formatted twice now, and I'm still continually getting conflicts. I'm not sure if this issue might be tied into the ones I'm having with the motherboard, or if that even makes sense, but considering the fact I wasn't having these issues till I switched to this one, I'm ready to put the blame on it.
    My theories:
    My current theory is that there is a device driver conflict somewhere. After much searching, reinstalling, and a lot of crying, I've not been able to figure out what the video card is conflicting with. While this issue might be better dealt with on some ATI fourm, ATI has not such fourm I could find, and since I'm having issues with the board overall, I figured I'd post it here.
    I have no theory as to why one processor would have me to change bios setting to get the RAM to work, and why another wouldn't.
    I have no theory as to why I can watch anime, but not play games.
    What I'm hoping for:
    I'm open to any possible solutions to the problems I'm currently experiencing, and would even be grateful for possible causes if no solution can be met. If all else fails, and I can't get anything to work, (even though all the other parts work on other boards), I'll assume the board is faulty and just RMA it considering the fact that the people I bought it from don't accept returns.

    Quote from: Xfraze on 03-February-06, 19:26:38
    I plan to get a 450W PSU today and see if that helps, I have my fingers crossed though. Last time I though my computer had a power issue, it turned out the problem was somthing else and I forkedout some cash for nothing.
    Yep, that happens ... that is why I always recommend to try it out with a borrowed PSU first. Still, I have the feeling that things are moving in the right direction Maybe it is time to take a closer look at the videocard - you have any idea of the temperature of the card under stress - or about the temperatures in the computer in general? CPU temp, case temp, etc?

  • Are there any known issues with the latest update to iTunes on Windows 7 maxing out the processor and nearly bringing the system to a hault.

    Has anyone experienced an issue with the latest update to iTunes (11.2.0.115) for Windows where iTunes pegs out the processor at 97%, 98%, and holds there for maybe 15 minutes before dropping to 50%. During that time, the system is basically useless. You just have to ride it out. I'm running Windows 7 Home Premium.

    Hi OnceBeforeIDie,
    Welcome to Apple Support Communities!
    Take a look at the article below, it has some some tips that will resolve a performance issues like the one you described.
    Apple software on Windows: May see performance issues and blank iTunes Store
    http://support.apple.com/kb/ts4123
    -Jason

Maybe you are looking for