November 5, 2002 at 9:07 am
Hi,
We have several SQL2000 servers in a DMZ that are setup to accept TCP/IP connections.
I started auditing the "Failed Log-ins" at the Windows system level and in no time I had a ton of Log-in failed messages under my Event Viewer's Security tab.
The messages indicate users (which, by the way, are indeed valid users and ARE logged through TCP/IP doing their work) have failed to login.
Notes:
- The event viewer picks up the machine name.
- This does not happen when there is no firewall is between the server and client.
Is the client trying to connect in any other way than intended?
A.
November 5, 2002 at 10:54 am
Might be attempting named pipes. Probably need to check clients for protocol bindings and perhaps sniff the network.
Steve Jones
November 5, 2002 at 11:56 am
That was also my thought. There is no indication on the client side to prove that.
Will keep digging.
Thanks
Viewing 3 posts - 1 through 2 (of 2 total)
You must be logged in to reply to this topic. Login to reply