網頁

2012年7月14日 星期六

Account Lockout (part 2 of 4)

In Microsoft Download Center, search and download “Account Lockout and Management Tools”
ScreenHunter_01 Jun. 29 10.53Double-click “ALTools.exe” to extract all on 64-bit Windows Server 2008 R2 platformScreenHunter_06 Jun. 29 14.30The related files will be here.
ScreenHunter_07 Jun. 29 14.31
Scenario
One day, someone tell you that her or his account is locked and want to know what happen. In the moment, how to track this status?

By LockoutStatus utility
Right-click “LockoutStatus.exe” next to click Run as administrator in the menu
ScreenHunter_15 Jun. 29 17.10Click File –> Select Target…ScreenHunter_16 Jun. 29 17.11Key locked account name as “test_2” into Target User Name and its domain name as “dw.com” into Target Domain Name.
If need to use the enough AD right, please enable “Use Alternate Credentials” check box and key in the related data as User Name, Password and Domain Name.
ScreenHunter_17 Jun. 29 17.12Now you can know when this account is locked and which DC lock it.ScreenHunter_18 Jun. 29 17.13Right-click this next to click “Open Event Viewer" in menu
ScreenHunter_19 Jun. 29 17.13In Event Viewer, expand Windows Logs and right-click Security next to click “Filter Current Log…” in menu
ScreenHunter_20 Jun. 29 17.16Key in ID numbers as “4625,4740,4771,4772,4777” next to click “OK” button
ScreenHunter_21 Jun. 29 17.18Now you can see all filtered log
ScreenHunter_22 Jun. 29 17.19Open each log to realize which computer trigger the locked status.
ScreenHunter_23 Jun. 29 17.21Maybe we need to log on this computer to realize what reason trigger the locked happen.
According to common causes for account lockouts (reference 3), sometimes we cannot find the root cause event though follow its suggestion.

Reference
(1). Description of security events in Windows Vista and in Windows Server 2008
     or  Description of security events in Windows 7 and in Windows Server 2008 R2
(2). Standalone Utility --- Account Lockout Status (LockoutStatus.exe)
(3). Common Causes for Account Lockouts

<<<   Account Lockout (part 1 of 4)

2012年7月9日 星期一

Set RPC Dynamic Range port on Any Servers

In the DFSR mechanism, it always use RPC Dynamic port to communicate with DC when want to generate the Health Report.
Due to the firewall locates between DFSR Server and DC, so I need to set RPC Dynamic port to fixed port on DC.
How to do it? Add the registry entity,key and value!

Add Registry Entity
By Registry Editor, explore “HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc" and right-click “Rpc" next to click “New", "Key" in menuScreenHunter_15 Jun. 30 16.10Write down “Internet"
ScreenHunter_16 Jun. 30 16.11
Add Registry Key and Value
Right-click “Internet" next to click “New", "Multi-String Value" in menu
ScreenHunter_17 Jun. 30 16.12Write down “Ports
ScreenHunter_18 Jun. 30 16.13Right-click “Ports” and click “Modify…”
ScreenHunter_19 Jun. 30 16.13Write down “5000-5100” in Value data field next to click “OK” button
ScreenHunter_20 Jun. 30 16.14Right-click “Internet" next to click “New", "String Value" in menu
ScreenHunter_21 Jun. 30 16.14Write down “PortsInternetAvailable
ScreenHunter_22 Jun. 30 16.15Right-click “PortsInternetAvailable” and click “Modify…”
ScreenHunter_23 Jun. 30 16.16
Write down “Y” in Value data field next to click “OK” button
ScreenHunter_24 Jun. 30 16.16Right-click “Internet" next to click “New", "String Value" in menu
ScreenHunter_25 Jun. 30 16.17Write down “UseInternetPorts
ScreenHunter_26 Jun. 30 16.17
Right-click “UseInternetPorts” and click “Modify…”
ScreenHunter_27 Jun. 30 16.18Write down “Y” in Value data field next to click “OK” button
ScreenHunter_28 Jun. 30 16.18Now we have already finished the registry setting.
ScreenHunter_29 Jun. 30 16.18Restart this Server so that all applications use RPC dynamic port will run on between 5000 and 5100.

In the moment, the firewall need to create a rule for TCP/5000-5100 from DFSR Server to DC. So does that the health report will be generated now.

For reference KB 154596
Since 2010 Design by Davidwa
©Copyright Davidwa Inc. All rights reserved.