We've started
seeing the following entry in our event logs:
Event
Type: Warning
Event Source: LSASRV
Event Category: SPNEGO (Negotiator)
Event ID: 40961
Date: 3/6/2004
Time: 10:24:57 AM
User: N/A
Computer: DEEDEE
Description:
The Security System could not establish a secured connection with the server DNS/prisoner.iana.org. No authentication protocol was available.
Event Source: LSASRV
Event Category: SPNEGO (Negotiator)
Event ID: 40961
Date: 3/6/2004
Time: 10:24:57 AM
User: N/A
Computer: DEEDEE
Description:
The Security System could not establish a secured connection with the server DNS/prisoner.iana.org. No authentication protocol was available.
For more
information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 88 03 00 c0 ..�
Data:
0000: 88 03 00 c0 ..�
prisoner.iana.org
is a "blackhole" server set up on the Internet provided by the IANA to handle
DNS requests to what should be internal address ranges.
I believe that the
only way to stop these events from appearing in our logs is to set up a
reverse-dns entry on each server to handle our 10.0.0.* address range, which is
the private LAN between our servers.
I'm not fully
versed in this, so I'll be the first to admit if the information above is
incorrect in whole or part, but my question is this:
How should the
reverse lookup appear in Microsoft DNS, for the address range 10.0.0.* (subnet
mask 255.255.255.0) ? Do I need to add just the zone, or do I need to add
additional information to the zone? And do you believe this would stop the
events from appearing?
Thanks, and
apologies for the OT post -- but you all are so very experienced!! Feel
free to respond off-list to keep the static down.
| |||
|
Marc Funaro,
President |
5547 State Highway
12 | ||
|
Are your virus signatures up-to-date? Take a few minutes and check them now! :) | |||
