Any reference material on Windows XP client traffic in an AD domain?

T

Trust No One®

Hi Folks,

Hoping someone here can help. I've been searching around both on the Net and
in various technical references with no real luck so far.

I'm after information on the types of client - domain controller
communications that typically occur in an Active Directory domain. In
particular I'm interested in the traffic between Windows XP clients and
Active Directory domain controllers.

This is in relation to an ongoing problem regarding hundreds of thousands of
538/540 event ids being logged daily in the security logs of our domain
controllers. These are generated as a result of setting the logon events
Audit policy to success and failures.

I've been monitoring one of our XP workstation over the course of a day and
I've noticed that it appears to connect to each domain controller in the
domain at 15 minute intervals - resulting in the logging of 540 and 538
events. I installed a nifty Microsoft port logging utility on the
workstation and the log shows that a connection is made to port 445 on each
domain controller at roughly 15 minute intervals. The module initiating the
connection is called "SYSTEM" which I believe is shared by many OS specific
functions. Over 10,000 workstations generating 538/540 events every 15
minutes adds up to a huge total as you might have guessed :(

We disable the computer browser service as a matter of course on our client
workstations, but this could still be the culprit. I've thoroughly virus
checked the test workstation and checked for Trojans etc.

I'm left with the possibility that this communication is entirely normal and
that perhaps the auditing of the success of logon events does not scale well
in large networks. There seems to be precious little information available
on Windows XP client communication with domain controllers in an AD domain -
unless I'm not looking in the right places.

Can anyone advise any references I can try. Any advice in general on this
one would be appreciated.
 
A

Ace Fekay [MVP]

Trust No One® said:
Hi Folks,

Hoping someone here can help. I've been searching around both on the Net
and
in various technical references with no real luck so far.

I'm after information on the types of client - domain controller
communications that typically occur in an Active Directory domain. In
particular I'm interested in the traffic between Windows XP clients and
Active Directory domain controllers.

This is in relation to an ongoing problem regarding hundreds of thousands
of
538/540 event ids being logged daily in the security logs of our domain
controllers. These are generated as a result of setting the logon events
Audit policy to success and failures.

I've been monitoring one of our XP workstation over the course of a day
and
I've noticed that it appears to connect to each domain controller in the
domain at 15 minute intervals - resulting in the logging of 540 and 538
events. I installed a nifty Microsoft port logging utility on the
workstation and the log shows that a connection is made to port 445 on
each
domain controller at roughly 15 minute intervals. The module initiating
the
connection is called "SYSTEM" which I believe is shared by many OS
specific
functions. Over 10,000 workstations generating 538/540 events every 15
minutes adds up to a huge total as you might have guessed :(

We disable the computer browser service as a matter of course on our
client
workstations, but this could still be the culprit. I've thoroughly virus
checked the test workstation and checked for Trojans etc.

I'm left with the possibility that this communication is entirely normal
and
that perhaps the auditing of the success of logon events does not scale
well
in large networks. There seems to be precious little information available
on Windows XP client communication with domain controllers in an AD
domain -
unless I'm not looking in the right places.

Can anyone advise any references I can try. Any advice in general on this
one would be appreciated.

I don't have a reference with me at this time (not in the office), but can
comment on detuning the number of failures and successes you are monitoring.
This is default 'keep-alive' traffic (not really, but what I call it), and
is expected behavior. You are seeing the proccesses authenticating with your
auditing settints. Clients will also refresh GPO settings every 90 min, +/-
30, as well. There's always traffic in the bacground.


--
Regards,
Ace

G O E A G L E S !!!
Please direct all replies ONLY to the Microsoft public newsgroups
so all can benefit.

This posting is provided "AS-IS" with no warranties or guarantees
and confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft Windows MVP - Windows Server - Directory Services

Security Is Like An Onion, It Has Layers
HAM AND EGGS: A day's work for a chicken;
A lifetime commitment for a pig.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top