We've started seeing the following entry in our event logs:
 
Event Type: Warning
Event Source: LSASRV
Event Category: SPNEGO (Negotiator)
Event ID: 40961
Date:  3/6/2004
Time:  10:24:57 AM
User:  N/A
Computer: DEEDEE
Description:
The Security System could not establish a secured connection with the server DNS/prisoner.iana.org.  No authentication protocol was available.
 
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 88 03 00 c0               ˆ..�   
 
 
prisoner.iana.org is a "blackhole" server set up on the Internet provided by the IANA to handle DNS requests to what should be internal address ranges.
 
I believe that the only way to stop these events from appearing in our logs is to set up a reverse-dns entry on each server to handle our 10.0.0.* address range, which is the private LAN between our servers.
 
I'm not fully versed in this, so I'll be the first to admit if the information above is incorrect in whole or part, but my question is this:
 
How should the reverse lookup appear in Microsoft DNS, for the address range 10.0.0.* (subnet mask 255.255.255.0) ?  Do I need to add just the zone, or do I need to add additional information to the zone?  And do you believe this would stop the events from appearing?
 
Thanks, and apologies for the OT post -- but you all are so very experienced!!  Feel free to respond off-list to keep the static down.


Advantex LLC
Technical Consulting Services

Marc Funaro, President

Macromedia Certified
Advanced ColdFusion
5.0 Developer

5547 State Highway 12
Norwich, NY 13815

VOX: 607-336-6895
FAX: 801-383-4864


Are your virus signatures up-to-date?
Take a few minutes and check them now! :)
 

Reply via email to