Block clients from accessing domain controllers

R

Rob McShinsky

I am looking for a quick and dirty way to block identified clients both
inside and outside the domain from making logon attempts to the domain
controller. We have had some internal problems with variant of the Gaobot
virus which try feverishly to use its list of username and passwords against
the domain controller. We have seen upwards of 200000 failed logon attempts
in 15 minutes. This is causing a type of denial of service situation where
the domain controllers at out main site are getting loaded so much that
logon requests are being sent to DC's at different AD sites across slower
links. Any thoughts would be helpful.

Rob McShinsky
 
P

paisher

-----Original Message-----
I am looking for a quick and dirty way to block identified clients both
inside and outside the domain from making logon attempts to the domain
controller. We have had some internal problems with variant of the Gaobot
virus which try feverishly to use its list of username and passwords against
the domain controller. We have seen upwards of 200000 failed logon attempts
in 15 minutes. This is causing a type of denial of service situation where
the domain controllers at out main site are getting loaded so much that
logon requests are being sent to DC's at different AD sites across slower
links. Any thoughts would be helpful.

Rob McShinsky


.
Close port 88? Disable or stop the authentication
service.
 
R

Rob McShinsky

A little too dirty. That would shutdown the other 5000 people who do not
have the virus on their machine.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top