Server Health "failed logins per hour"

I'm getting over 100 failures per hour from 3 jet direct cards
The cards are all
Model Number: J6057A
Firmware Version: R.25.57
I've updated the firmware, no help
Is there a default user login that is incorrect?
IPX Name: WAHWAH_PS
IPX Address: 3.0001E697F790
IPX/SPX Frame Type: Auto Select
SAP Interval: 60
Direct Mode
Number of connections supported: 1
Connections Available: 1
Queue Server
Print Server Name: WAHWAH_PS
NDS Tree Name: NP_IC
File Server Name: IBM_XSERIES1
Connection Status: NetWare Password Error
NCP Code: FF
File Server Name: IBM_XSERIES1
Connection Status: Queue Server Connected
NCP Code: D5

Originally Posted by peterkuo
Was the JD configured with a password?
Peter
eDirectory Rules!
No the Jet Direct cards were not setup with a password.
When you login to the printer ... under protocol info ipx/spx
Notice that the printer says there is a password error
IPX Name: WAHWAH_PS
IPX Address: 3.0001E697F790
IPX/SPX Frame Type: Auto Select
SAP Interval: 60
Direct Mode
Number of connections supported: 1
Connections Available: 1
Queue Server
Print Server Name: WAHWAH_PS
NDS Tree Name: NP_IC
File Server Name: IBM_XSERIES1
Connection Status: NetWare Password Error NCP Code: FF
File Server Name: IBM_XSERIES1
Connection Status: Queue Server Connected
NCP Code: D5

Similar Messages

  • Failed Logins Per Hour

    I have a NW 6.5 sp5 server that is showing a very high number of
    'Failed Logins Per Hour'. All the login attempts are as follows:
    Time: Tuesday, 3-20-2007 9:20 am
    Address: IP 192.168.25.43
    User: .CN=MTA.CN=USACSCMAIL01.OU=MAIL.O=USAMAIL.T=USAMAI L.
    The user is the MTA within a GroupWise system. The server showing the
    problem is 1 of 3 POs in a GroupWise system. The other 2 POs do not
    show this problem. The only thing different about this one is that it
    is running iManager. I have seen several mentions of this problem but
    I cannot find any resolutions. I would appreciate any information on
    why this is happen and how to stop it.
    thanks,
    -ch

    [email protected];2661689 Wrote:
    > I have a NW 6.5 sp5 server that is showing a very high number of
    > 'Failed Logins Per Hour'. All the login attempts are as follows:
    >
    > Time: Tuesday, 3-20-2007 9:20 am
    > Address: IP 192.168.25.43
    > User: .CN=MTA.CN=USACSCMAIL01.OU=MAIL.O=USAMAIL.T=USAMAI L.
    >
    > The user is the MTA within a GroupWise system. The server showing the
    > problem is 1 of 3 POs in a GroupWise system. The other 2 POs do not
    > show this problem. The only thing different about this one is that it
    > is running iManager. I have seen several mentions of this problem but
    > I cannot find any resolutions. I would appreciate any information on
    > why this is happen and how to stop it.
    >
    > thanks,
    > -ch
    I guess you may have more success by posting this to the Groupwise
    forums.
    cimetmc
    Marcel Cox
    http://support.novell.com/forums

  • MTA causing Failed Logins

    I tried posting this on novell.support.netware.6x.administration-tools
    and someone referred me here.
    I have a NW 6.5 sp5 server that is showing a very high number of
    'Failed Logins Per Hour' in the Health Monitor. All the login
    attempts are as follows:
    Time: Tuesday, 3-20-2007 9:20 am
    Address: IP 192.168.25.43
    User: .CN=MTA.CN=USACSCMAIL01.OU=MAIL.O=USAMAIL.T=USAMAI L.
    The user is the MTA within my GroupWise 7 system. The server showing
    the problem is 1 of 3 POs. The other 2 POs do not show this problem.
    The only thing different about this one is that it is running
    iManager. I have seen several mentions of this problem but I cannot
    find any resolutions. I would appreciate any information on why this
    is happening and how to stop it.
    thanks,
    -ch

    A couple more ideas, make sure the user and password are in the correct
    format. Another thing to look for is DMS. If DMS was setup at some point
    and the path to the library no longer exists or is no longer accessible, it
    could cause similar problems.
    >>> On 4/5/2007 at 7:31 AM, in message
    <[email protected] .com>,
    <[email protected]> wrote:
    > I had disabled the eDir Synch to see if that would make it stop trying
    > to login and failing. No luck there. I have re-enabled and will wait
    > for the scheduled synch to run to see if the eDir Access will change.
    > I also added an admin level user/pass to the mta config file and
    > restarted the mta. Once again that kicked the failed logins up
    > dramatically.
    >
    > -ch
    >
    > On Apr 3, 2:46 pm, "Marc Porter" <[email protected]> wrote:
    >> >Also, is it a bad thing that the eDir Access will not set to Yes?
    >>
    >> It's been my experience that it won't change to yes until the eDir synch
    > has
    >> executed for the first time. Do you have the edir user synch scheduled?
    > If
    >> so, wait until it runs and see if it changes to yes. Also, do you have
    > a
    >> user/password specified in your MTA startup file?

  • Problem with failed logins for "Workstation" objects

    All
    I am currently seeing an issue in my environment since an upgrade of the
    workstation ZENworks client to 6.5.
    Basically our environment was all ZEN 3.2, over the last month we have
    been force upgrading each site to ZENworks 6.5 for clients through the
    login script. Since then we have had failed logins from various
    workstations and the only way to resolve the issue, currently, is to
    delete the workstation object and let it re-create itself which does
    resolve the issue.
    From a site perspective I am not in a position to delete 2000 workstaion
    objects so they can re-register into the tree so I was wondering if
    anyone had seen anything like this and knew how to resolve it?
    Current count on Health Monitor:
    Failed Logins Per Hour 3038 6096 N/A
    Example Error:
    Time: Monday, 27-11-2006 9:18 am
    Address: IP 165.198.211.58
    User: .CN=PUKWUL01523.OU=WKSTS.OU=THEALE.OU=UK.O=FLE.T=F LE-NDS.
    I was thinking it may be a rights issues of some sort but any help
    greatly received!!!!!
    Paul

    > OK, we have tried that and it didnt work unfortunatly, we have also added
    > public rights to the workstation container to see if it was a rights
    > issue of some sort but again this didnt work.
    >
    > Paul
    I did see this issue a while ago when moving from 3.2 to 6.5
    What I might suggest is trying to force the upgraded PCs to create "new"
    workstation objects.
    As part of the upgrade process, unregister the Workstation Objects 1st,
    then run the agent install. Have the ZFD7 Import policy create the
    workstation Objects with a slight different name or in a slightly different
    location.
    I dont recall the details exactly so I wont say too much since I will not
    have the facts 100% correctly, but it was an issue in which the old
    workstation objects would lose the ability to authenticate after a few days
    because of a switch in the WS Manager.
    By having new objects made, the issue would be avoided.
    The old ones should go aways shortly due to automatic workstation cleanup.

  • Inventory service does not start 610 failed login

    L.S.
    Netware 6.5, SP6
    ZEN 7.01SP1IR1
    Sybase database
    Standalone server
    My inventory service does not start. I've looked around but did not yet find the solution. I did have an error I've read nothing about:
    logger screen: java:Class com.novell.....ZENWorksInventoryservicemanager exited with status -1
    C1, Inventory service object shows 610: database location policy is not configured (but it is)
    NRM: health, failed login: user: .CN=Server package_ZENSERVER:Netware:ZENDateBase.O=context.T= tree
    Any suggestions
    Thomas Roes

    Thomasroes,
    either of these help?
    http://www.novell.com/support/php/se...1%200%20506894
    http://www.novell.com/support/php/se...1%200%20506894
    Shaun Pond

  • Every now and then (every 15 minutes-half an hour or so), my internet fails. It says in the Diagnostics that the internet and server have failed. Happens on my sister's mac as well. Is this our modem?

    Every now and then (every 15 minutes-half an hour or so), my internet fails. It says in the Diagnostics that the internet and server have failed. Happens on my sister's mac as well. Is this our modem? Our PCs don't do this so it has something to do with the macs.

    Hi Patrick,
    I'm starting to think it's either an AirPort card issue or something to do with the Mac OS. I have stopped using wireless as much as possible in my home (have wired up several new Ethernet outlets), and it sure is nice having Internet run at the speed it's supposed to all the time, and with no drops. Might be something to consider.
    In the meantime:
    Open System Preferences > Network > select AirPort > click on Advanced > TCP/IP > Configure IPv6 > Off > OK > Apply > Turn AirPort Off > Turn AirPort On
    Open System Preferences > Network > select Ethernet > click on Advanced > TCP/IP > Configure IPv6 > Off > OK > Apply
    (FOR LION: If you can’t see an option to turn ipv6 off, set it to link-local only.)
    IPv6 troubleshooting http://support.apple.com/kb/TS3802
    And here are some internet troubleshooting ideas:
    http://docs.info.apple.com/article.html?path=Mac/10.6/en/11395.html
    http://support.apple.com/kb/HT1714

  • There have been 7,039 failed login attempts in the last 30 minutes

    Hi,
    I am trying to find out the cause for an OEM alert we received:
    There have been 7,039 failed login attempts in the last 30 minutesThe cause is ofcourse known, but I can't find out why the application anyway was able to do 7000+ login attempts within half an hour. The account should have locked after 10 attempts
    The perticular account has a DEFAULT profile.
    Auditing is on, so if we look into DBA_AUDIT_SESSION it is clearly seen that within 1 minute approx 1200 failed login attempts occured without the account being locked.
    USERNAME USERHOST     RETURCODE      TIME              COUNT
    KRAMPV      DDE18LNB       1017     27-01-2012 13:54     235
    KRAMPV      VSV2SH221     1017     27-01-2012 13:54     271
    KRAMPV      VSV2SH222     1017     27-01-2012 13:54     258
    KRAMPV      VSV2SH223     1017     27-01-2012 13:54     263
    KRAMPV      VSV2SH224     1017     27-01-2012 13:54     266If we retry the login with a incorrect password manually from SQLplus, after 10 login attempts the account gets locked as expected.
    The above login attempts come from three application server of which I don't know how they handle failed logins.
    Can anyone point me into a search direction as to why the account didn't lock. Just for completeness some extra info about the account and the DEFAULT profile:
    User is created with:
    CREATE USER KRAMPV
    IDENTIFIED BY VALUES 'S:123456890'
    DEFAULT TABLESPACE KRAMPVDATA
    TEMPORARY TABLESPACE TEMP
    PROFILE DEFAULT
    ACCOUNT UNLOCK;
    GRANT RESOURCE TO KRAMPV;
    GRANT CONNECT TO KRAMPV;
    ALTER USER KRAMPV DEFAULT ROLE ALL;
    GRANT CREATE MATERIALIZED VIEW TO KRAMPV;
    GRANT CREATE VIEW TO KRAMPV;
    GRANT CREATE TABLE TO KRAMPV;
    GRANT ALTER ANY MATERIALIZED VIEW TO KRAMPV;
    ALTER USER KRAMPV QUOTA UNLIMITED ON KRAMPVDATA;
    ALTER USER KRAMPV QUOTA UNLIMITED ON KRAMPVARCH;The DEFAULT profile has the following settings:
    DEFAULT     COMPOSITE_LIMIT               UNLIMITED
    DEFAULT     PASSWORD_LOCK_TIME          UNLIMITED
    DEFAULT     PASSWORD_VERIFY_FUNCTION     NULL
    DEFAULT     PASSWORD_REUSE_MAX          UNLIMITED
    DEFAULT     PASSWORD_REUSE_TIME          UNLIMITED
    DEFAULT     PASSWORD_LIFE_TIME          180
    DEFAULT     FAILED_LOGIN_ATTEMPTS          10
    DEFAULT     PRIVATE_SGA               UNLIMITED
    DEFAULT     CONNECT_TIME               UNLIMITED
    DEFAULT     IDLE_TIME               UNLIMITED
    DEFAULT     LOGICAL_READS_PER_CALL          UNLIMITED
    DEFAULT     LOGICAL_READS_PER_SESSION     UNLIMITED
    DEFAULT     CPU_PER_CALL               UNLIMITED
    DEFAULT     CPU_PER_SESSION               UNLIMITED
    DEFAULT     SESSIONS_PER_USER          UNLIMITED
    DEFAULT     PASSWORD_GRACE_TIME          7The Oracle database version is 11.2.0.3
    The OS is AIX7.1
    I've been looking on MOS, but was unable to find a clue yets
    Thanks
    FJFranken
    Edit: For the record, after I discovered the above I changed the DEFAULT profile, so the account would not unlock itself anymore. If this problem will occur in the future, maybe we can get more info as the account - if it gets locked- should stay locked now:
    alter profile default limit PASSWORD_LOCK_TIME unlimited;Edited by: fjfranken on 3-feb-2012 2:56

    Girish Sharma wrote:
    I cann't say that resource_limit is not TRUE, because you are saying "If we retry the login with a incorrect password manually from SQLplus, after 10 login attempts the account gets locked as expected.", so it means profile is working for the "KRAMPV" user.
    The interesting thing is USERHOST is changing, so another option is the listener log should also have information about the failed connection attempts.
    My another guess is duplicate user in the database i.e. one is KRAMPV and another is "krampv" (with quotation mark). Just check in dba_users that is there something like exists or not.....
    select upper(username),count(*) from dba_users group by upper(username) having count(*) > 1;
    Regards
    Girish SharmaHi Girish,
    resource_limit is set to FALSE.
    And we've tested the locking with another user, because KRAMPV is used by the application that is running and we didn't want to risk that it got locked
    USERHOST is not changing, there are 4 hosts ( application servers ) doing the same thing, so connection requests are coming from 4 hosts concurrently.
    There is luckily no duplicate user.
    Thanks anyway, we will keep investigating. I also sent the information to the application provider.
    Bye
    FJFranken

  • Please help, how to send mails faster / send more mails per hour

    hello,
    in my application i am using mail sender class i have created to send mail to the users to participate in a survey. following is the code for it. i would like to know if there is anything wrong in it coz it takes to much time to send the mails it is taking 2 minustes to send 6 mails i.e 360 mails per hour only.
    following is how i instantiate the mail sender class and then generate a http link string dynamically as it is different for all the user.
    //////////class where mail sender is instantiated////////////////////
    try
    setConnection();
    st=con.createStatement();
    rs=st.executeQuery("select * from "+CNAME+"_campaign");                         
    String SurveyT = new String();
    while(rs.next())
         SurveyT = rs.getString(2);
    rs.close();
    rs=st.executeQuery("select * from "+CNAME+"_user");     
    ss = new MailSender();
    while(rs.next())
         String userid = rs.getString("userid");
         String password = rs.getString("password");
    StringBuffer message = new StringBuffer(BodyText.getText().trim());
    if(SurveyT.equals("invitational") || SurveyT.equals("single"))
                                            message.append( "\n" + "http://"+IPadd.getText().trim()+"/"+CNAME+"/servlet/login?username="+userid+"&passw="+password);
                                            ss.send(FromField.getText().trim(),userid,SmtpServerID.getText().trim(),MailSub.getText().trim(),message.toString());
    else if(SurveyT.equals("general"))
    message.append( "\n" + "http://"+IPadd.getText().trim()+"/"+CNAME+"/Index.html");
    ss.send(FromField.getText().trim(),userid,SmtpServerID.getText().trim(),MailSub.getText().trim(),message.toString());
    st.close();
    this.dispose();
    catch(SQLException sqlex)
    JOptionPane.showMessageDialog(null,sqlex.getMessage());
    //Mail Sender class/////////////////
    import javax.mail.*;
    import javax.mail.internet.*;
    import java.util.*;
    import javax.swing.*;
    public class MailSender
         String sentAddr,fromAddr,smtpServer,body,subject;
         public MailSender()
         //function send to send the mail
    public void send(String from,String to,String smtps,String subj,String messagetext)
              fromAddr=new String(from);
              sentAddr=new String(to);
              smtpServer=new String(smtps);
              body=new String(messagetext);
              subject=new String(subj);
              try
                   Properties props = System.getProperties();
                   props.put("mail.smtp.host",smtpServer);
         Session session = Session.getDefaultInstance(props,null);
    Message msg = new MimeMessage(session);
                   msg.setFrom(new InternetAddress(fromAddr));
    msg.setRecipients(Message.RecipientType.TO,InternetAddress.parse(sentAddr,false));
         msg.setSubject(subject);
         msg.setText(body);
    msg.setHeader("Survey","MailCheck");
    msg.setSentDate(new Date());
         Transport.send(msg);
         catch(MessagingException mex)
              JOptionPane.showMessageDialog(null,mex.getMessage());
    }

    Lots of variables here....Also my maths says only 180 per hour.... i.e. three a minute.
    1) you are using a database to get info from. What is the average response time of the DB server? Looks like you are doing one SQL then reading the result table but does the initial SQL take a while?
    2) how much data are you passing on to the SMTP server and how fast/slow is the link to that SMTP server? Work out the absolute max amount of data you can transfer over the link then get your average message size and work out a VERY theoretical Max number of messages a minute. Note that real life might approach 80% of this taking TCP/IP and SMTP overheads into account.
    3) What sort of load is the SMTP server under? If it's busy you will be only getting a fraction of whatever bandwidth is available. Depending on its design it may be trying to deliver the first message you sent it while you are still pumping more messages down to it. SMTP servers may limit the number of connections per minute from another machine in order to defeat a denial of service attack. Your code makes a connection per email so this may have relevence here.
    4) Raw horsepower always helps. When I write stuff to do things like this there is no nice GUI screen etc. Just basic Java that if it has to will write a log if something goes wrong. Maybe just maybe a counter on STD out to show it is still actually doing something. Keep the number of classes used down to the bare minimum. In the old days we used to spend days paring code to the bone - a skill somewhat lost these days.
    Hope this gives you some help in finding the bottleneck.
    Cheers,
    SH

  • Thousands of failed login 4625 events, corresponding with 1003 events form Security-SSP

    I've got a server running Server 2012 R2, it's got a few services and such, but lately there have been thousand of failed logins, they seem to happen every 30 minutes and there is about 10 or so at a time. I checked the application logs and there seem to
    be corresponding events from Security-SSP at the same times, event ID 1003,a s well as a few different ones at random times. These are the details for the 4625 events:
    An account failed to log on.
    Subject:
        Security ID:        SYSTEM
        Account Name:        SERVER$
        Account Domain:        MYSERVER
        Logon ID:        0x3E7
    Logon Type:            3
    Account For Which Logon Failed:
        Security ID:        NULL SID
        Account Name:        
        Account Domain:        
    Failure Information:
        Failure Reason:        Unknown user name or bad password.
        Status:            0xC000006D
        Sub Status:        0xC0000064
    Process Information:
        Caller Process ID:    0x2c4
        Caller Process Name:    C:\Windows\System32\lsass.exe
    Network Information:
        Workstation Name:    SERVER
        Source Network Address:    -
        Source Port:        -
    Detailed Authentication Information:
        Logon Process:        Schannel
        Authentication Package:    Kerberos
        Transited Services:    -
        Package Name (NTLM only):    -
        Key Length:        0
    System
    Provider
    [ Name]
    Microsoft-Windows-Security-Auditing
    [ Guid]
    {54849625-5478-4994-A5BA-3E3B0328C30D}
    EventID
    4625
    Version
    0
    Level
    0
    Task
    12544
    Opcode
    0
    Keywords
    0x8010000000000000
    TimeCreated
    [ SystemTime]
    2014-10-08T15:39:27.023566500Z
    EventRecordID
    555922
    Correlation
    Execution
    [ ProcessID]
    708
    [ ThreadID]
    11356
    Channel
    Security
    Computer
    Server.MYSERVER.local
    Security
    EventData
    SubjectUserSid
    S-1-5-18
    SubjectUserName
    SERVER$
    SubjectDomainName
    MYSERVER
    SubjectLogonId
    0x3e7
    TargetUserSid
    S-1-0-0
    TargetUserName
    TargetDomainName
    Status
    0xc000006d
    FailureReason
    %%2313
    SubStatus
    0xc0000064
    LogonType
    3
    LogonProcessName
    Schannel
    AuthenticationPackageName
    Kerberos
    WorkstationName
    SERVER
    TransmittedServices
    LmPackageName
    KeyLength
    0
    ProcessId
    0x2c4
    ProcessName
    C:\Windows\System32\lsass.exe
    IpAddress
    IpPort
    And the 1003 events:
    System
    Provider
    [ Name]
    Microsoft-Windows-Security-SPP
    [ Guid]
    {E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}
    [ EventSourceName]
    Software Protection Platform Service
    EventID
    1003
    [ Qualifiers]
    16384
    Version
    0
    Level
    4
    Task
    0
    Opcode
    0
    Keywords
    0x80000000000000
    TimeCreated
    [ SystemTime]
    2014-10-08T11:09:21.000000000Z
    EventRecordID
    7230
    Correlation
    Execution
    [ ProcessID]
    0
    [ ThreadID]
    0
    Channel
    Application
    Computer
    Server.MYSERVER.local
    Security
    EventData
    55c92734-d682-4d71-983e-d6ec3f16059f
    1: e96022a1-3247-4125-9ddc-4c6068ab3bfc, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
    There are also a few 900, 902, 903 events. Any ideas what is happening? Everything seems to be running fine.

    Hi,
    The event 4625 indicates a computer account failed to logon. You could run NLTEST /SC_RESET:domain-name command with administrative credentials to check domain’s health.
    For more detailed information, please see:
    Audit Failure event ID 4625
    https://social.technet.microsoft.com/Forums/windowsserver/en-US/ae9da10a-b4d2-4eda-ae6d-ad61b7b6ab79/audit-failure-event-id-4625?forum=winserversecurity
    You could also refer to the similar threads to troubleshoot the issue:
    numerous 4625 errors in the event log
    https://social.technet.microsoft.com/Forums/windowsserver/en-US/c6b0d058-98d0-4572-8a72-e18e353b04fd/numerous-4625-errors-in-the-event-log?forum=winserversecurity
    Many Audit Failure Event ID 4625
    https://social.technet.microsoft.com/Forums/windowsserver/en-US/8f7ebcf5-2310-42c3-9b6a-20205a6c17ef/many-audit-failure-event-id-4625?forum=winserveressentials
    Best Regards,
    Mandy 
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Reporting failed logins

    How can I report on failed login attempts through our ASA 5515's using AnyConnect?

    Michael,
    In practical terms, ASA has limited capabilities to store this kind of information.
    The best way to check this is on the AAA server you're using or by filtering syslogs.
    ASA itself will store counters of how many authentications took place, how many succeeded etc. on a per-server basis.
    Even the local server will store some info.
    Example:
    ASA# show aaa-serverServer Group:    LOCALServer Protocol: Local databaseServer Address:  NoneServer port:     NoneServer status:   ACTIVE, Last transaction at 14:07:19 UTC Thu Oct 3 2013Number of pending requests              0Average round trip time                 0msNumber of authentication requests       16888Number of authorization requests        0Number of accounting requests           0Number of retransmissions               0Number of accepts                       13Number of rejects                       16875Number of challenges                    0Number of malformed responses           0Number of bad authenticators            0Number of timeouts                      0Number of unrecognized responses        0
    Best place to get details are your syslogs and AAA server reports.
    Syslog messages:
    http://www.cisco.com/en/US/docs/security/asa/syslog-guide/logmsgs.html
    M.

  • Dell N2048P - Failed logins

    Hi allOur organisation recently had all it's swithces replaced with Dell N2048P's. In the logs on all of them I see constant failed login attempts for root, admin, and at least one of our user names.The logs are pretty unhelpful as that is all they say, would be good to get some more detail on where the attempt was coming from either IP or at least the switch Port number.I have been looking for a way to increase the logging but it does not seem to be an option. Does anyone know if this is possible?Also had an issue with one switch where one of the 10GB fibre links would keep dropping out, tracked to a dodgy patch lead, hwoever it only logs this as 'Notice' to me it should be higher and to get notification via SPiceworks Helpdesk I need to set the minimum level to Notice and end up with many emails per switch per hour. So is there a way...
    This topic first appeared in the Spiceworks Community

    Ised,
    It appears that in the past few days you have not received a response to your posting. That concerns us, and has triggered this automated reply.
    Has your problem been resolved? If not, you might try one of the following options:
    - Do a search of our knowledgebase at http://support.novell.com/search/kb_index.jsp
    - Check all of the other support tools and options available at http://support.novell.com in both the "free product support" and "paid product support" drop down boxes.
    - You could also try posting your message again. Make sure it is posted in the correct newsgroup. (http://support.novell.com/forums)
    If this is a reply to a duplicate posting, please ignore and accept our apologies and rest assured we will issue a stern reprimand to our posting bot.
    Good luck!
    Your Novell Product Support Forums Team
    http://support.novell.com/forums/

  • Failed logins problem

    Hello, everyone....
    OK, first of all, the players...
    1. NetWare 6.5 SP7 servers: a half dozen at the main office. One at each of
    three sites connected with an site to site VPN tunnel.
    2. User laptop: Windows XP SP3, pretty well patched.
    3. Other considerations: VPN tunnel is SonicWall, an NSA 3500 at the main
    office and TZ210 at each VPN location. Also ZenWorks 7.x is involved. I'm
    not sure of the exact version, but it is some variety of Zen 7.
    My problem: this laptop is single-handedly generating dozens of failed
    logins on at least two of the three VPN sites.I looked at the Remote Manager
    logs for these locations and the Zenworks Workstation Object is shown as the
    culprit.
    Example log entry from Remote Manager (OrgName and TreeName withhelf for
    security reasons):
    Time: Thursday, 9-24-2009 10:35 am
    Address: IP 172.26.100.04
    User: .CN=AOS36816 WINXP
    00:1F:E2:14:73:CC.OU=Workstations.O=<OrgName>.T=<T reeName>.
    I checked the NSA3500 device and the TZ210 device. There are packets (TCP
    524) going from the laptop to the NSA3500 device and then nothing is heard
    from them again on the TZ210 device.
    I'm wondering if the 524 packets are not getting send down the VPN tunnel.
    And if that is the case, WHY is the server on the other end of this given me
    failed logins?
    Am I making myself clear about this?
    Thanks in advance.
    Delon E. Weuve
    Senior Network Engineer
    Office of Auditor of State
    State of Iowa
    United States of America

    Hello again...
    I also forgot something.
    It sometimes does this for minutes, hours, sometimes week after week and
    then
    It stops for no apparent reason and the count on failed logins starts to
    drop after an hour or so.
    That's the really weird part.
    Delon E. Weuve
    Senior Network Engineer
    Office of Auditor of State
    State of Iowa
    United States of America

  • Connection to [i]server[/i] failed (Error NT_STATUS_IO_TIMEOUT)

    Hi there,
    I'm a long time linux user (casual) and have recently got hold of a machine that I am using as a server. I am able to SSH into this fine from my laptop and I am doing all the setup from ssh.
    I am trying to set it up so I can use Samba, however keep getting the following error
    # smbclient -L [i]server[/i] -U%
    Connection to [i]server[/i] failed (Error NT_STATUS_IO_TIMEOUT)
    I thought I had followed the samba set up wiki to the letter
    My smb.conf looks like so
    [global]
    usershare path = /var/lib/samba/usershare
    usershare max shares = 100
    usershare allow guests = yes
    usershare owner only = false
    # workgroup = NT-Domain-Name or Workgroup-Name
    workgroup = MYGROUP
    # server string is the equivalent of the NT Description field
    server string = Samba Server
    # This option is important for security. It allows you to restrict
    # connections to machines which are on your local network. The
    # following example restricts access to two C class networks and
    # the "loopback" interface. For more examples of the syntax see
    # the smb.conf man page
    ; hosts allow = 192.168.1. 192.168.2. 127.
    # if you want to automatically load your printer list rather
    # than setting them up individually then you'll need this
    printcap name = /etc/printcap
    load printers = yes
    # It should not be necessary to spell out the print system type unless
    # yours is non-standard. Currently supported print systems include:
    # bsd, sysv, plp, lprng, aix, hpux, qnx
    ; printing = bsd
    # Uncomment this if you want a guest account, you must add this to /etc/passwd
    # otherwise the user "nobody" is used
    ; guest account = pcguest
    # this tells Samba to use a separate log file for each machine
    # that connects
    log file = /var/log/samba/%m.log
    # Put a capping on the size of the log files (in Kb).
    max log size = 50
    # Security mode. Most people will want user level security. See
    # security_level.txt for details.
    security = user
    # Use password server option only with security = server
    ; password server = <NT-Server-Name>
    # Password Level allows matching of _n_ characters of the password for
    # all combinations of upper and lower case.
    ; username level = 8
    # You may wish to use password encryption. Please read
    # ENCRYPTION.txt, Win95.txt and WinNT.txt in the Samba documentation.
    # Do not enable this option unless you have read those documents
    ; encrypt passwords = yes
    ; smb passwd file = /etc/samba/smbpasswd
    # The following are needed to allow password changing from Windows to
    # update the Linux sytsem password also.
    # NOTE: Use these with 'encrypt passwords' and 'smb passwd file' above.
    # NOTE2: You do NOT need these to allow workstations to change only
    # the encrypted SMB passwords. They allow the Unix password
    # to be kept in sync with the SMB password.
    ; unix password sync = Yes
    ; passwd program = /usr/bin/passwd %u
    ; passwd chat = *New*UNIX*password* %n\n *ReType*new*UNIX*password* %n\n *pass$
    # Unix users can map to different SMB User names
    ; username map = /etc/samba/smbusers
    # Using the following line enables you to customise your configuration
    # on a per machine basis. The %m gets replaced with the netbios name
    # of the machine that is connecting
    # Configure Samba to use multiple interfaces
    # If you have multiple network interfaces then you must list them
    # here. See the man page for details.
    ; interfaces = 192.168.12.2/24 192.168.13.2/24
    # Configure remote browse list synchronisation here
    # request announcement to, or browse list sync from:
    # a specific host or from / to a whole subnet (see below)
    ; remote browse sync = 192.168.3.25 192.168.5.255
    # Cause this host to announce itself to local subnets here
    ; remote announce = 192.168.1.255 192.168.2.44
    # Browser Control Options:
    # set local master to no if you don't want Samba to become a master
    # browser on your network. Otherwise the normal election rules apply
    ; local master = no
    # OS Level determines the precedence of this server in master browser
    # elections. The default value should be reasonable
    ; os level = 33
    # Domain Master specifies Samba to be the Domain Master Browser. This
    # allows Samba to collate browse lists between subnets. Don't use this
    # if you already have a Windows NT domain controller doing this job
    ; domain master = yes
    # Preferred Master causes Samba to force a local browser election on startup
    # and gives it a slightly higher chance of winning the election
    ; preferred master = yes
    # Use only if you have an NT server on your network that has been
    # configured at install time to be a primary domain controller.
    ; domain controller = <NT-Domain-Controller-SMBName>
    # Enable this if you want Samba to be a domain logon server for
    # Windows95 workstations.
    ; domain logons = yes
    # if you enable domain logons then you may want a per-machine or
    # per user logon script
    # run a specific logon batch file per workstation (machine)
    ; logon script = %m.bat
    # Where to store roving profiles (only for Win95 and WinNT)
    # %L substitutes for this servers netbios name, %U is username
    # You must uncomment the [Profiles] share below
    ; logon path = \\%L\Profiles\%U
    # All NetBIOS names must be resolved to IP Addresses
    # 'Name Resolve Order' allows the named resolution mechanism to be specified
    # the default order is "host lmhosts wins bcast". "host" means use the unix
    # system gethostbyname() function call that will use either /etc/hosts OR
    # DNS or NIS depending on the settings of /etc/host.config, /etc/nsswitch.conf
    # and the /etc/resolv.conf file. "host" therefore is system configuration
    # dependant. This parameter is most often of use to prevent DNS lookups
    # in order to resolve NetBIOS names to IP Addresses. Use with care!
    # The example below excludes use of name resolution for machines that are NOT
    # on the local network segment
    # - OR - are not deliberately to be known via lmhosts or via WINS.
    ; name resolve order = wins lmhosts bcast
    # Windows Internet Name Serving Support Section:
    # WINS Support - Tells the NMBD component of Samba to enable it's WINS Server
    ; wins support = yes
    # WINS Server - Tells the NMBD components of Samba to be a WINS Client
    # Note: Samba can be either a WINS Server, or a WINS Client, but NOT both
    ; wins server = w.x.y.z
    # WINS Proxy - Tells Samba to answer name resolution queries on
    # behalf of a non WINS capable client, for this to work there must be
    # at least one WINS Server on the network. The default is NO.
    ; wins proxy = yes
    # DNS Proxy - tells Samba whether or not to try to resolve NetBIOS names
    # via DNS nslookups. The built-in default for versions 1.9.17 is yes,
    # this has been changed in version 1.9.18 to no.
    dns proxy = no
    # Case Preservation can be handy - system default is _no_
    # NOTE: These can be set on a per share basis
    ; preserve case = no
    ; short preserve case = no
    # Default case is normally upper case for all DOS files
    ; default case = lower
    # Be very careful with case sensitivity - it can break things!
    ; case sensitive = no
    #============================ Share Definitions ==============================
    [homes]
    comment = Home Directories
    browseable = yes
    writable = yes
    # Un-comment the following and create the netlogon directory for Domain Logons
    ; [netlogon]
    ; comment = Network Logon Service
    ; path = /home/netlogon
    ; guest ok = yes
    ; writable = no
    ; share modes = no
    # Un-comment the following to provide a specific roving profile share
    # the default is to use the user's home directory
    ;[Profiles]
    ; path = /home/profiles
    ; browseable = no
    ; guest ok = yes
    # NOTE: If you have a BSD-style print system there is no need to
    # specifically define each individual printer
    [printers]
    comment = All Printers
    path = /var/spool/samba
    browseable = no
    # Set public = yes to allow user 'guest account' to print
    guest ok = no
    writable = no
    printable = yes
    [i]<everything else is commented out>[/i]
    I have no windows machines so it's only my laptop and desktop both running linux that I need to connect to this. I have tried googling and searching these forums to no avail
    Thanks for any help that can be offered
    Mike

    If I run the following (on the machine I'm trying to set up the share)
    smbclient -L localhost -U%
    I got the following output
    Connection to localhost failed (Error NT_STATUS_CONNECTION_REFUSED)
    so I thought it might be something incorrect with the iptables side of things, however I haven't really touched that at all and it seems to look correct
    iptables -nvL
    Chain INPUT (policy ACCEPT 667 packets, 79977 bytes)
    pkts bytes target prot opt in out source destination
    Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
    pkts bytes target prot opt in out source destination
    Chain OUTPUT (policy ACCEPT 157 packets, 20724 bytes)
    pkts bytes target prot opt in out source destination
    So from my (very little) knowledge this appears correct (I think)... However it appears that something is blocking access somewhere.

  • Javax.servlet.jsp.JspException: REP-51002: Bind to Reports Server reportserver fail??

    why i cant open my report in JDeveloper tools but i can open in report builder ????
    this is the error i get ...
    Reports Error Page
    Fri Oct 18 15:41:54 SGT 2002
    javax.servlet.jsp.JspException: REP-51002: Bind to Reports Server reportserver failed
    javax.servlet.jsp.JspException: REP-51002: Bind to Reports Server reportserver failed
         int oracle.reports.jsp.ReportTag.doStartTag()
              ReportTag.java:329
         void MyReport.jspService(javax.servlet.http.HttpServletRequest, javax.servlet.http.HttpServletResponse)
              MyReport.jsp:4
         void oracle.jsp.runtime.HttpJsp.service(javax.servlet.ServletRequest, javax.servlet.ServletResponse)
              HttpJsp.java:119
         void oracle.jsp.runtimev2.JspPageTable.service(javax.servlet.http.HttpServletRequest, javax.servlet.http.HttpServletResponse, java.lang.String)
              JspPageTable.java:302
         void oracle.jsp.runtimev2.JspServlet.internalService(javax.servlet.http.HttpServletRequest, javax.servlet.http.HttpServletResponse)
              JspServlet.java:407
         void oracle.jsp.runtimev2.JspServlet.service(javax.servlet.http.HttpServletRequest, javax.servlet.http.HttpServletResponse)
              JspServlet.java:328
         void javax.servlet.http.HttpServlet.service(javax.servlet.ServletRequest, javax.servlet.ServletResponse)
              HttpServlet.java:336
         void com.evermind.server.http.ServletRequestDispatcher.invoke(javax.servlet.ServletRequest, javax.servlet.ServletResponse)
              ServletRequestDispatcher.java:684
         void com.evermind.server.http.ServletRequestDispatcher.forwardInternal(javax.servlet.ServletRequest, javax.servlet.http.HttpServletResponse)
              ServletRequestDispatcher.java:269
         boolean com.evermind.server.http.HttpRequestHandler.processRequest(com.evermind.server.ApplicationServerThread, com.evermind.server.http.EvermindHttpServletRequest, com.evermind.server.http.EvermindHttpServletResponse, java.io.InputStream, java.io.OutputStream, boolean)
              HttpRequestHandler.java:735
         void com.evermind.server.http.HttpRequestHandler.run(java.lang.Thread)
              HttpRequestHandler.java:243
         void com.evermind.util.ThreadPoolThread.run()
              ThreadPoolThread.java:64

    i still get the same error .. is it i need to set any environment variable or ... any setting ...??
    login Oracle Database
    user name = system
    password = manager
    services = dbhenry
    setting JSP Report
    Report Name = MyReport1
    Reports Server = reportserver
    Parameters = userid=system/manager@dbhenry
    the cource code below is my JSP report coding :
    <rw:report id="MyReport1" parameters="server=reportserver&userid=system/manager@dbhenry">
    <rw:objects id="objects">
    <?xml version="1.0" encoding="WINDOWS-1252" ?>
    <report name="MyReport1" DTDVersion="9.0.2.0.0">
    <xmlSettings xmlTag="MYREPORT1" xmlPrologType="text">
    <![CDATA[<?xml version="1.0" encoding="&Encoding"?>]]>
    </xmlSettings>
    <data>
    <dataSource name="Q_1">
    <select>
    <![CDATA[SELECT ALL HENRY.TEL, HENRY."ADD", HENRY.NAME, HENRY.ID
    FROM HENRY ]]>
    </select>

  • Network (IP) address is no longer listed as the source of multiple failed login attempts - Events 4776 in Windows 2008 R2

    Our Windows 2008R2 security log is full of failed login attempt events 4776, but we're unable to block them because no IP address is provided for the network source of these attempts - like it was in Windows 2003 Server.
    Log Name:      Security
    Source:        Microsoft-Windows-Security-Auditing
    Date:          9/26/2012 2:32:27 AM
    Event ID:      4776
    Task Category: Credential Validation
    Level:         Information
    Keywords:      Audit Failure
    User:          N/A
    Computer:      MAIL.XYZ.COM
    Description:
    The computer attempted to validate the credentials for an account.
    Authentication Package:    MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
    Logon Account:    admin
    Source Workstation:    MAIL
    Error Code:    0xc0000064
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
        <EventID>4776</EventID>
        <Version>0</Version>
        <Level>0</Level>
        <Task>14336</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8010000000000000</Keywords>
        <TimeCreated SystemTime="2012-09-26T06:32:27.570062500Z" />
        <EventRecordID>18318</EventRecordID>
        <Correlation />
        <Execution ProcessID="452" ThreadID="540" />
        <Channel>Security</Channel>
        <Computer>MAIL.XYZ.COM</Computer>
        <Security />
      </System>
      <EventData>
        <Data Name="PackageName">MICROSOFT_AUTHENTICATION_PACKAGE_V1_0</Data>
        <Data Name="TargetUserName">admin</Data>
        <Data Name="Workstation">MAIL</Data>
        <Data Name="Status">0xc0000064</Data>
      </EventData>
    </Event>

    The user names are all different in these log events, and they constantly change, which may indicate a hacking attempt.  However, in Windows 2003 these type of events looked like this, showing the IP address the request came from, so we could trace
    and block them -- but not in Windows 2008:
    Logon Failure:
    Reason: Unknown user name or bad password
    User Name: s
    Domain: MAIL
    Logon Type: 10
    Logon Process: User32 
    Authentication Package: Negotiate
    Workstation Name: MAIL
    Caller User Name: MAIL$
    Caller Domain: XXXX
    Caller Logon ID: (0x0,0x3E7)
    Caller Process ID: 3728
    Transited Services: -
    Source Network Address: 202.67.170.186
    Source Port: 57365

Maybe you are looking for

  • Special HTML Characters

    Hi, I encountered a problem with regards to the display of special HTML characters(chr 155). Crystal was not able to correctly display the cahracters. Instead a blank space was displayed. In addition to, when the report is exported to PDF, it is disp

  • Error message for iTunes update. "The operation was cancelled.(3072)" What can I do?

    I get an error message:

  • To_CHAR in OBIEE

    Hello All, I have 2 tables variance_trend and monthly_variance. Both tables have load_date column. In variance_trend it is varchar in the format YYYYMM, in monthly_variance load_date is date data type. I am trying to convert monthly_variance.load_dat

  • E7 fail to receive SMS after Belle update

    Hi there, I recently have a problem receiving SMS on E7 after updating to Belle. When I put the SIM card to another phone I do receive messages. However I do not receive those SMS that I have sent when the SIM was in the E7. Looks like the messages a

  • Access/Segmentation Violation errors

    Here's another one of those "Has anyone seen this" questions. We are currently stress testing one of our applications and get the following 'Access/Segmentation Violation' error on a server partition: Begin Stack Backtrace ===========================