<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Error message in Context Directory Agent, mapping doesn't work correctly. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/error-message-in-context-directory-agent-mapping-doesn-t-work/m-p/2070208#M396006</link>
    <description>&lt;P&gt;Hey guys!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We've started using the AD Agent a year back or so, and now we've migrated to CDA but we're having some issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have 4 domain controllers and they are configured in CDA and show as OK, so all good there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the ip to username mapping is not working correctly, only some users get mapped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I get this in the log very frequently.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE cellpadding="0" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="font-weight: bold; font-size: 10px; min-width: 120px; width: 120px; vertical-align: top;"&gt;event-text&lt;/TD&gt;&lt;TD style="vertical-align: top;"&gt;&lt;P style="white-space: normal;"&gt;instance of __InstanceCreationEvent { SECURITY_DESCRIPTOR = {1, 0, 4, 128, 108, 0, 0, 0, 120, 0, 0, 0, 0, 0, 0, 0, 20, 0, 0, 0, 2, 0, 88, 0, 3, 0, 0, 0, 0, 0, 24, 0, 95, 0, 15, 0, 1, 1, 0, 0, 0, 0, 0, 5, 18, 0, 0, 0, 67, 0, 45, 0, 0, 0, 28, 0, 69, 0, 0, 0, 1, 2, 0, 0, 0, 0, 0, 5, 32, 0, 0, 0, 32, 2, 0, 0, 53, 0, 49, 0, 0, 0, 28, 0, 0, 0, 0, 0, 1, 2, 0, 0, 0, 0, 0, 5, 32, 0, 0, 0, 39, 2, 0, 0, 53, 0, 49, 0, 1, 1, 0, 0, 0, 0, 0, 5, 18, 0, 0, 0, 1, 1, 0, 0, 0, 0, 0, 5, 18, 0, 0, 0}; TargetInstance = instance of Win32_NTLogEvent { Category = 9; CategoryString = "Account Logon"; ComputerName = "SEGRYDC2"; EventCode = 672; EventIdentifier = 672; EventType = 5; InsertionStrings = {"039s020", "GRYCKSBO.LOCAL", "-", "krbtgt/GRYCKSBO.LOCAL", "-", "0x40810010", "0x6", "-", "-", "192.168.187.213", "", "", ""}; Logfile = "Security"; Message = "Authentication Ticket Request: \n \n\tUser Name:\t\t039s020 \n \n\tSupplied Realm Name:\tGRYCKSBO.LOCAL \n \n\tUser ID:\t\t\t- \n \n\tService Name:\t\tkrbtgt/GRYCKSBO.LOCAL \n \n\tService ID:\t\t- \n \n\tTicket Options:\t\t0x40810010 \n \n\tResult Code:\t\t0x6 \n \n\tTicket Encryption Type:\t- \n \n\tPre-Authentication Type:\t- \n \n\tClient Address:\t\t192.168.187.213 \n \n\tCertificate Issuer Name:\t \n \n\tCertificate Serial Number:\t \n \n\tCertificate Thumbprint:\t \n \n"; RecordNumber = 132903567; SourceName = "Security"; TimeGenerated = "20121106080729.000000+060"; TimeWritten = "20121106080729.000000+060"; Type = "Audit Failure"; User = "NT AUTHORITY\\SYSTEM"; }; TIME_CREATED = "129966592493454297"; };&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE cellpadding="0" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="font-weight: bold; font-size: 10px; min-width: 120px; width: 120px; vertical-align: top;"&gt;dc-hostname&lt;/TD&gt;&lt;TD style="vertical-align: top;"&gt;&lt;DIV style="white-space: normal;"&gt;segrydc2.grycksbo.local/192.168.187.196&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE cellpadding="0" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="font-weight: bold; font-size: 10px; min-width: 120px; width: 120px; vertical-align: top;"&gt;&lt;SPAN class="GRcorrect" id="GRmark_cdaae3b2414dc9e2b0ca7a5a07ec21dc38b492ed_dc:0"&gt;dc&lt;/SPAN&gt;-name&lt;/TD&gt;&lt;TD style="vertical-align: top;"&gt;&lt;P style="white-space: normal;"&gt;segrydc2&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE cellpadding="0" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="font-weight: bold; font-size: 10px; min-width: 120px; width: 120px; vertical-align: top;"&gt;&lt;SPAN class="GRcorrect" id="GRmark_bd926dd31ca3ab0f725b614cc09e687d611e1f45_event:0"&gt;event&lt;/SPAN&gt;-source&lt;/TD&gt;&lt;TD style="vertical-align: top;"&gt;&lt;DIV style="white-space: normal;"&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_com:0"&gt;com&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_.:1"&gt;.&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_cisco:2"&gt;cisco&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_.:3"&gt;.&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_cda:4"&gt;cda&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_.:5"&gt;.&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_rt:6"&gt;rt&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_.:7"&gt;.&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_adobserver:8"&gt;adobserver&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_.:9"&gt;.&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_adobserver:10"&gt;adobserver&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_.:11"&gt;.&lt;/SPAN&gt;CurrentEventsThread&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE cellpadding="0" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="font-weight: bold; font-size: 10px; min-width: 120px; width: 120px; vertical-align: top;"&gt;&lt;SPAN class="GRcorrect" id="GRmark_4d890b864ae3ca0a1ac06939794999c265a23b7a_event:0"&gt;event&lt;/SPAN&gt;-error&lt;/TD&gt;&lt;TD style="vertical-align: top;"&gt;&lt;DIV style="white-space: normal;"&gt;Audit type is not of type 4 (Audit Success)&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This message show on all the DC's with a random interval.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Two of the DC's are 2003 SP2 and the other two are 2008 R2 SP1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They &lt;SPAN style="color: #ff0000;"&gt;&lt;EM&gt;should&lt;/EM&gt;&lt;/SPAN&gt; be configured for all the requirements, and I doubt I missed something on all of them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;"&lt;EM&gt;Active Directory Requirements&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;Cisco CDA relies on Active Directory login audit events to gather mappings. In order for Cisco CDA to &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_c24602b9db00402465c47128ff73c267dcd24dca_work:0"&gt;work&lt;/SPAN&gt; appropriately, make sure that:&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;• Ensure that the “Audit Policy” (part of the “Group Policy Management” settings) allows successful &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_514e9db48f0b8a72698c328a8e2dc82f540d52b1_logons:0"&gt;logons&lt;/SPAN&gt; to generate the necessary events in the Windows Security Log of that AD domain controller &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_c9544d74f9553a8d97e1450be336e8924ca04138_machine:0"&gt;machine&lt;/SPAN&gt; (this is normally the Windows default setting, but you must explicitly ensure that this &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_13840b25e86bede4c02458112aa8e8a126c791de_setting:0"&gt;setting&lt;/SPAN&gt; is correct).&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;• The Active Directory server administrator account has the following permissions: &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;– The account must belong to the “Distributed COM Users” Active Directory group.&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;– The account must have permission to access WMI &lt;SPAN class="GRcorrect" id="GRmark_cfd4742d92bff1825e0287807ba2b263abc886a6_namespaces:0"&gt;namespaces&lt;/SPAN&gt; (CIMV2 &lt;SPAN class="GRcorrect" id="GRmark_cfd4742d92bff1825e0287807ba2b263abc886a6_namespace:1"&gt;namespace&lt;/SPAN&gt;) on the &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_b421b97f55e47da47570065f5863795885292984_domain:0"&gt;domain&lt;/SPAN&gt; controller machine.&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;– The account must have permission to read the security event log on the domain controller &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_4ae2f5f975d8a92bf55938c4f4897d5d0fcfea37_machine:0"&gt;machine&lt;/SPAN&gt;.&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;• Each individual domain controller machine running Windows Server 2008 or Windows Server 2008 &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;R2 have the appropriate Microsoft &lt;SPAN class="GRcorrect" id="GRmark_5f1443ae011672053c59ef231946725d47f069c3_hotfixes:0"&gt;hotfixes&lt;/SPAN&gt; installed.&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;For domain controller machines running Windows Server 2008, the following two Microsoft &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_5c899a6f7361c0077ad081f26256a24e944c7c06_hotfixes:0"&gt;hotfixes&lt;/SPAN&gt; must be installed:&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;a. &lt;A href="http://support.microsoft.com/kb/958124" style="color: #1155cc;" target="_blank"&gt;http://support.microsoft.com/kb/958124&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;This patch fixes a memory leak in Microsoft's WMI, which if left unfixed can prevent the AD Agent &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_21d6b8db448a498a7db29d4b4249645e34d3bd3b_from:0"&gt;from&lt;/SPAN&gt; successfully connecting &lt;SPAN class="GRcorrect" id="GRmark_21d6b8db448a498a7db29d4b4249645e34d3bd3b_with:1"&gt;with&lt;/SPAN&gt; that domain controller and achieving an “up” status.&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;b. &lt;A href="http://support.microsoft.com/kb/973995" style="color: #1155cc;" target="_blank"&gt;http://support.microsoft.com/kb/973995&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;This patch fixes a memory leak in Microsoft's WMI, which if left unfixed can sporadically prevent &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;Active Directory from writing the necessary authentication-related events to the Security Log &lt;SPAN class="GRcorrect" id="GRmark_88336e719d5548a296c627beafc65b1267b3826b_for:0"&gt;for&lt;/SPAN&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_57f961e19338123699efe331f3c48ba0fc72f6bb_that:0"&gt;that&lt;/SPAN&gt; domain controller and would prevent the AD Agent from learning about the mappings &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_bf92c4182bb8b1ab9f2870d3404df7724eff9de7_corresponding:0"&gt;corresponding&lt;/SPAN&gt; to some of the user logins that authenticate through that domain controller.&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;For domain controller machines running Windows Server 2008 R2, the following Microsoft &lt;SPAN class="GRcorrect" id="GRmark_a8d6ef89b18d3d1c54316f905ec881d4da5d7ab5_hotfix:0"&gt;hotfix&lt;/SPAN&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_a32aa7c5050fb6d3ee93b7065441369edf2cb14c_must:0"&gt;must&lt;/SPAN&gt; be installed (unless SP1 is installed):&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;A href="http://support.microsoft.com/kb/981314" style="color: #1155cc;" target="_blank"&gt;http://support.microsoft.com/kb/981314&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;This patch fixes a memory leak in Microsoft's WMI, which if left unfixed can sporadically prevent &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;Active Directory from writing the necessary authentication-related events to the Security Log &lt;SPAN class="GRcorrect" id="GRmark_88336e719d5548a296c627beafc65b1267b3826b_for:0"&gt;for&lt;/SPAN&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_57f961e19338123699efe331f3c48ba0fc72f6bb_that:0"&gt;that&lt;/SPAN&gt; domain controller and would prevent the AD Agent from learning about the mappings &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;corresponding to some of the user logins that authenticate through that domain controller&lt;/EM&gt;."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;Cheers!&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:19:36 GMT</pubDate>
    <dc:creator>Martin Ostberg</dc:creator>
    <dc:date>2019-03-12T00:19:36Z</dc:date>
    <item>
      <title>Error message in Context Directory Agent, mapping doesn't work correctly.</title>
      <link>https://community.cisco.com/t5/network-security/error-message-in-context-directory-agent-mapping-doesn-t-work/m-p/2070208#M396006</link>
      <description>&lt;P&gt;Hey guys!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We've started using the AD Agent a year back or so, and now we've migrated to CDA but we're having some issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have 4 domain controllers and they are configured in CDA and show as OK, so all good there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the ip to username mapping is not working correctly, only some users get mapped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I get this in the log very frequently.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE cellpadding="0" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="font-weight: bold; font-size: 10px; min-width: 120px; width: 120px; vertical-align: top;"&gt;event-text&lt;/TD&gt;&lt;TD style="vertical-align: top;"&gt;&lt;P style="white-space: normal;"&gt;instance of __InstanceCreationEvent { SECURITY_DESCRIPTOR = {1, 0, 4, 128, 108, 0, 0, 0, 120, 0, 0, 0, 0, 0, 0, 0, 20, 0, 0, 0, 2, 0, 88, 0, 3, 0, 0, 0, 0, 0, 24, 0, 95, 0, 15, 0, 1, 1, 0, 0, 0, 0, 0, 5, 18, 0, 0, 0, 67, 0, 45, 0, 0, 0, 28, 0, 69, 0, 0, 0, 1, 2, 0, 0, 0, 0, 0, 5, 32, 0, 0, 0, 32, 2, 0, 0, 53, 0, 49, 0, 0, 0, 28, 0, 0, 0, 0, 0, 1, 2, 0, 0, 0, 0, 0, 5, 32, 0, 0, 0, 39, 2, 0, 0, 53, 0, 49, 0, 1, 1, 0, 0, 0, 0, 0, 5, 18, 0, 0, 0, 1, 1, 0, 0, 0, 0, 0, 5, 18, 0, 0, 0}; TargetInstance = instance of Win32_NTLogEvent { Category = 9; CategoryString = "Account Logon"; ComputerName = "SEGRYDC2"; EventCode = 672; EventIdentifier = 672; EventType = 5; InsertionStrings = {"039s020", "GRYCKSBO.LOCAL", "-", "krbtgt/GRYCKSBO.LOCAL", "-", "0x40810010", "0x6", "-", "-", "192.168.187.213", "", "", ""}; Logfile = "Security"; Message = "Authentication Ticket Request: \n \n\tUser Name:\t\t039s020 \n \n\tSupplied Realm Name:\tGRYCKSBO.LOCAL \n \n\tUser ID:\t\t\t- \n \n\tService Name:\t\tkrbtgt/GRYCKSBO.LOCAL \n \n\tService ID:\t\t- \n \n\tTicket Options:\t\t0x40810010 \n \n\tResult Code:\t\t0x6 \n \n\tTicket Encryption Type:\t- \n \n\tPre-Authentication Type:\t- \n \n\tClient Address:\t\t192.168.187.213 \n \n\tCertificate Issuer Name:\t \n \n\tCertificate Serial Number:\t \n \n\tCertificate Thumbprint:\t \n \n"; RecordNumber = 132903567; SourceName = "Security"; TimeGenerated = "20121106080729.000000+060"; TimeWritten = "20121106080729.000000+060"; Type = "Audit Failure"; User = "NT AUTHORITY\\SYSTEM"; }; TIME_CREATED = "129966592493454297"; };&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE cellpadding="0" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="font-weight: bold; font-size: 10px; min-width: 120px; width: 120px; vertical-align: top;"&gt;dc-hostname&lt;/TD&gt;&lt;TD style="vertical-align: top;"&gt;&lt;DIV style="white-space: normal;"&gt;segrydc2.grycksbo.local/192.168.187.196&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE cellpadding="0" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="font-weight: bold; font-size: 10px; min-width: 120px; width: 120px; vertical-align: top;"&gt;&lt;SPAN class="GRcorrect" id="GRmark_cdaae3b2414dc9e2b0ca7a5a07ec21dc38b492ed_dc:0"&gt;dc&lt;/SPAN&gt;-name&lt;/TD&gt;&lt;TD style="vertical-align: top;"&gt;&lt;P style="white-space: normal;"&gt;segrydc2&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE cellpadding="0" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="font-weight: bold; font-size: 10px; min-width: 120px; width: 120px; vertical-align: top;"&gt;&lt;SPAN class="GRcorrect" id="GRmark_bd926dd31ca3ab0f725b614cc09e687d611e1f45_event:0"&gt;event&lt;/SPAN&gt;-source&lt;/TD&gt;&lt;TD style="vertical-align: top;"&gt;&lt;DIV style="white-space: normal;"&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_com:0"&gt;com&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_.:1"&gt;.&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_cisco:2"&gt;cisco&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_.:3"&gt;.&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_cda:4"&gt;cda&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_.:5"&gt;.&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_rt:6"&gt;rt&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_.:7"&gt;.&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_adobserver:8"&gt;adobserver&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_.:9"&gt;.&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_adobserver:10"&gt;adobserver&lt;/SPAN&gt;&lt;SPAN class="GRcorrect" id="GRmark_889f1fda4251b20d362b8ad97660524f479405b5_.:11"&gt;.&lt;/SPAN&gt;CurrentEventsThread&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE cellpadding="0" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="font-weight: bold; font-size: 10px; min-width: 120px; width: 120px; vertical-align: top;"&gt;&lt;SPAN class="GRcorrect" id="GRmark_4d890b864ae3ca0a1ac06939794999c265a23b7a_event:0"&gt;event&lt;/SPAN&gt;-error&lt;/TD&gt;&lt;TD style="vertical-align: top;"&gt;&lt;DIV style="white-space: normal;"&gt;Audit type is not of type 4 (Audit Success)&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This message show on all the DC's with a random interval.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Two of the DC's are 2003 SP2 and the other two are 2008 R2 SP1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They &lt;SPAN style="color: #ff0000;"&gt;&lt;EM&gt;should&lt;/EM&gt;&lt;/SPAN&gt; be configured for all the requirements, and I doubt I missed something on all of them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;"&lt;EM&gt;Active Directory Requirements&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;Cisco CDA relies on Active Directory login audit events to gather mappings. In order for Cisco CDA to &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_c24602b9db00402465c47128ff73c267dcd24dca_work:0"&gt;work&lt;/SPAN&gt; appropriately, make sure that:&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;• Ensure that the “Audit Policy” (part of the “Group Policy Management” settings) allows successful &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_514e9db48f0b8a72698c328a8e2dc82f540d52b1_logons:0"&gt;logons&lt;/SPAN&gt; to generate the necessary events in the Windows Security Log of that AD domain controller &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_c9544d74f9553a8d97e1450be336e8924ca04138_machine:0"&gt;machine&lt;/SPAN&gt; (this is normally the Windows default setting, but you must explicitly ensure that this &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_13840b25e86bede4c02458112aa8e8a126c791de_setting:0"&gt;setting&lt;/SPAN&gt; is correct).&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;• The Active Directory server administrator account has the following permissions: &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;– The account must belong to the “Distributed COM Users” Active Directory group.&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;– The account must have permission to access WMI &lt;SPAN class="GRcorrect" id="GRmark_cfd4742d92bff1825e0287807ba2b263abc886a6_namespaces:0"&gt;namespaces&lt;/SPAN&gt; (CIMV2 &lt;SPAN class="GRcorrect" id="GRmark_cfd4742d92bff1825e0287807ba2b263abc886a6_namespace:1"&gt;namespace&lt;/SPAN&gt;) on the &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_b421b97f55e47da47570065f5863795885292984_domain:0"&gt;domain&lt;/SPAN&gt; controller machine.&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;– The account must have permission to read the security event log on the domain controller &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_4ae2f5f975d8a92bf55938c4f4897d5d0fcfea37_machine:0"&gt;machine&lt;/SPAN&gt;.&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;• Each individual domain controller machine running Windows Server 2008 or Windows Server 2008 &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;R2 have the appropriate Microsoft &lt;SPAN class="GRcorrect" id="GRmark_5f1443ae011672053c59ef231946725d47f069c3_hotfixes:0"&gt;hotfixes&lt;/SPAN&gt; installed.&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;For domain controller machines running Windows Server 2008, the following two Microsoft &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_5c899a6f7361c0077ad081f26256a24e944c7c06_hotfixes:0"&gt;hotfixes&lt;/SPAN&gt; must be installed:&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;a. &lt;A href="http://support.microsoft.com/kb/958124" style="color: #1155cc;" target="_blank"&gt;http://support.microsoft.com/kb/958124&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;This patch fixes a memory leak in Microsoft's WMI, which if left unfixed can prevent the AD Agent &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_21d6b8db448a498a7db29d4b4249645e34d3bd3b_from:0"&gt;from&lt;/SPAN&gt; successfully connecting &lt;SPAN class="GRcorrect" id="GRmark_21d6b8db448a498a7db29d4b4249645e34d3bd3b_with:1"&gt;with&lt;/SPAN&gt; that domain controller and achieving an “up” status.&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;b. &lt;A href="http://support.microsoft.com/kb/973995" style="color: #1155cc;" target="_blank"&gt;http://support.microsoft.com/kb/973995&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;This patch fixes a memory leak in Microsoft's WMI, which if left unfixed can sporadically prevent &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;Active Directory from writing the necessary authentication-related events to the Security Log &lt;SPAN class="GRcorrect" id="GRmark_88336e719d5548a296c627beafc65b1267b3826b_for:0"&gt;for&lt;/SPAN&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_57f961e19338123699efe331f3c48ba0fc72f6bb_that:0"&gt;that&lt;/SPAN&gt; domain controller and would prevent the AD Agent from learning about the mappings &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_bf92c4182bb8b1ab9f2870d3404df7724eff9de7_corresponding:0"&gt;corresponding&lt;/SPAN&gt; to some of the user logins that authenticate through that domain controller.&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;For domain controller machines running Windows Server 2008 R2, the following Microsoft &lt;SPAN class="GRcorrect" id="GRmark_a8d6ef89b18d3d1c54316f905ec881d4da5d7ab5_hotfix:0"&gt;hotfix&lt;/SPAN&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_a32aa7c5050fb6d3ee93b7065441369edf2cb14c_must:0"&gt;must&lt;/SPAN&gt; be installed (unless SP1 is installed):&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;A href="http://support.microsoft.com/kb/981314" style="color: #1155cc;" target="_blank"&gt;http://support.microsoft.com/kb/981314&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;This patch fixes a memory leak in Microsoft's WMI, which if left unfixed can sporadically prevent &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;Active Directory from writing the necessary authentication-related events to the Security Log &lt;SPAN class="GRcorrect" id="GRmark_88336e719d5548a296c627beafc65b1267b3826b_for:0"&gt;for&lt;/SPAN&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;&lt;SPAN class="GRcorrect" id="GRmark_57f961e19338123699efe331f3c48ba0fc72f6bb_that:0"&gt;that&lt;/SPAN&gt; domain controller and would prevent the AD Agent from learning about the mappings &lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;EM&gt;corresponding to some of the user logins that authenticate through that domain controller&lt;/EM&gt;."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:19:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-message-in-context-directory-agent-mapping-doesn-t-work/m-p/2070208#M396006</guid>
      <dc:creator>Martin Ostberg</dc:creator>
      <dc:date>2019-03-12T00:19:36Z</dc:date>
    </item>
    <item>
      <title>Error message in Context Directory Agent, mapping doesn't work c</title>
      <link>https://community.cisco.com/t5/network-security/error-message-in-context-directory-agent-mapping-doesn-t-work/m-p/2070209#M396008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have the same problem for one of 4 AD servers.&lt;/P&gt;&lt;P&gt;At the beginning it was because I needed to edit the registry as note at the guide.&lt;/P&gt;&lt;P&gt;But now after double and triple checking I don't understand what causing this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 09:01:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-message-in-context-directory-agent-mapping-doesn-t-work/m-p/2070209#M396008</guid>
      <dc:creator>aharon-n</dc:creator>
      <dc:date>2013-05-22T09:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: Error message in Context Directory Agent, mapping doesn't wo</title>
      <link>https://community.cisco.com/t5/network-security/error-message-in-context-directory-agent-mapping-doesn-t-work/m-p/2070210#M396009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I ran into this same error message and we discovered the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A co-worker had turned off a number of audit events to troubleshoot someone getting their account locked. The events he turned off were:&lt;UL&gt;&lt;LI&gt;login/log off events&lt;/LI&gt;&lt;LI&gt;Kerberos logging&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;He turned the login/log off events back on, this did NOT fix the issue.&lt;/LI&gt;&lt;LI&gt;As soon as he turned on Kerberos logging, we got all the new mappings.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Windows Server 2008 R2 and Windows 2012, choose Advanced Audit Policy Configuration &amp;gt; Audit Policies &amp;gt; Account Logon. For the two Policy items, Audit Kerberos Authentication Service and Audit Kerberos Service Ticket Operations, ensure that the corresponding Policy Setting for each of these either directly or indirectly includes the Success condition as described above.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jan 2014 21:24:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-message-in-context-directory-agent-mapping-doesn-t-work/m-p/2070210#M396009</guid>
      <dc:creator>howe.bill</dc:creator>
      <dc:date>2014-01-27T21:24:47Z</dc:date>
    </item>
  </channel>
</rss>

