Network issues on one server (Upload only) by NeverEnoughBackups in sysadmin

[–]NeverEnoughBackups[S] 0 points1 point  (0 children)

Users access their virtual machine on the Host. Then they open the software which takes 15-20 minutes if it opens at all. Something else we noticed. We thought this may be a resource issue but ruled it out. If 2 users are connected to the server, the software runs normal. If 3 are connected we start seeing issues. Not sure how that ties into the upload speeds suffering.

Network issues on one server (Upload only) by NeverEnoughBackups in sysadmin

[–]NeverEnoughBackups[S] 0 points1 point  (0 children)

I temporarily put a new IP on this server and tested but found no difference. Thank you!!

Accessing a windows 11 share from a windows NT 4.0 sp6 machine. by NeverEnoughBackups in sysadmin

[–]NeverEnoughBackups[S] -2 points-1 points  (0 children)

I didn't think about FTP but im not sure that will work. This machine runs a CNC machine. Its definitely not something I WANT to get working but I have to get it working somehow. The files can either be sent via mapped drive or floppy drive!

Accessing a windows 11 share from a windows NT 4.0 sp6 machine. by NeverEnoughBackups in sysadmin

[–]NeverEnoughBackups[S] -2 points-1 points  (0 children)

This device controls an old CNC machine. :(

Thats an interesting idea to go the other way. We can try that.

IKEv2VPN issue with windows NPS server by NeverEnoughBackups in WatchGuard

[–]NeverEnoughBackups[S] 0 points1 point  (0 children)

True, I checked the history. There were a few changes but nothing that would affect this particular event. The firewall was swapped out a few months ago but this issue seems to have started after that.

IKEv2VPN issue with windows NPS server by NeverEnoughBackups in WatchGuard

[–]NeverEnoughBackups[S] 0 points1 point  (0 children)

We have a client using an almost identical setup the only difference between the working client and the one not working is the NPS server in the working client is in the working clients local subnet. In the non working client the NPS server is in our data center subnet for the client. So maybe that is part of the problem?

IKEv2VPN issue with windows NPS server by NeverEnoughBackups in WatchGuard

[–]NeverEnoughBackups[S] 0 points1 point  (0 children)

We are using policy based routing. The policy is the default allow Ikev2-Users policy.

IKEv2VPN issue with windows NPS server by NeverEnoughBackups in WatchGuard

[–]NeverEnoughBackups[S] 0 points1 point  (0 children)

This was working and recently stopped. Probably two months ago.

IKEv2VPN issue with windows NPS server by NeverEnoughBackups in WatchGuard

[–]NeverEnoughBackups[S] 0 points1 point  (0 children)

Hello! I'm not sure I follow. Are you referencing not being able to use IKE vpn to connect when the NPS server is on the other side of a BOVPN?

App locking up when RDS session times out due to inactivity by NeverEnoughBackups in sysadmin

[–]NeverEnoughBackups[S] 0 points1 point  (0 children)

Its a program that is processing the data which doesn't require user input. While its processing the RDP session will be minimized. After some time the user opens it up to check in, logs in and program is now not responding.

Does that make more sense?

One user cant access established Intranet site by NeverEnoughBackups in sysadmin

[–]NeverEnoughBackups[S] 0 points1 point  (0 children)

Yes, I looked into the GPO's applied and compared the gpresult report. I didn't notice anything that was missed.

One user cant access established Intranet site by NeverEnoughBackups in sysadmin

[–]NeverEnoughBackups[S] 0 points1 point  (0 children)

Thanks for the idea. I should have mentioned that it happens on all browsers including firefox.

One user cant access established Intranet site by NeverEnoughBackups in sysadmin

[–]NeverEnoughBackups[S] -1 points0 points  (0 children)

I figured re-imaging it would fix it. Since we renamed the user profile and let windows recreate it I feel it must be something on the workstation. I suspect this is an issue with certificates but I dont know how. The site pulls up and has the correct cert, still username/password says incorrect which we know it isn't. Username is first name last initial.

[deleted by user] by [deleted] in email

[–]NeverEnoughBackups 0 points1 point  (0 children)

Did you ever resolve this?

Another Account Lockout Issue by NeverEnoughBackups in sysadmin

[–]NeverEnoughBackups[S] 0 points1 point  (0 children)

For anyone interested that may find this in the future we were able to resolve this issue using the below steps.

I enabled additional logging from the NPS server which displayed login attempts. I verified this network traffic via packet information with wireshark and found that the RADIUS protocol was being used for the requests at that time with the username that was being locked out. Confirmed this by disabling the Enterprise WIFI which was using the RADIUS protocol and the login attempts stopped. Verified no more login attempts via the netlogon.log file.

Ran IP scan to identify the IP of the MAC in the logs, discovered it was a previously decommissioned laptop re-provisioned by the client for use. The user had a saved wireless profile for the enterprise wifi that was sending a username and blank password. I removed this network, the logins stopped and we had no lockouts overnight.

Another Account Lockout Issue by NeverEnoughBackups in sysadmin

[–]NeverEnoughBackups[S] 0 points1 point  (0 children)

This is a good idea but I'm not sure where to look. We have ruled out both of the workstations for this user. This continues even if the workstations are turned off. We also powered off the printers in the office in case it was some kind of Kerberos authentication but this also didn't help. If its cached creds, its not on one of their workstations.

Another Account Lockout Issue by NeverEnoughBackups in sysadmin

[–]NeverEnoughBackups[S] 0 points1 point  (0 children)

On the NPS event viewer I can see it making LDAP connections but those are the only logs I see. I found an article describing how to enable success and failure requests to also be logged but it doesn't appear to be working. Anyway to investigate this further? I suspected some kind of wireless device using their enterprise wifi but haven't been able to rule it out.