Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

No more endpoints available from the endpoint mapper

Posted on 2004-04-14
7
Medium Priority
?
19,943 Views
Last Modified: 2012-06-21
Hi all

I am getting this error from a Windows 2003 Enterprise server application event log:
14/04/2004 19:26:26
Userenv
Error      None      1053
NT AUTHORITY\SYSTEM      GATEWAY      Windows cannot determine the user or computer name. (There are no more endpoints available from the endpoint mapper. ). Group Policy processing aborted.

The error occurs during boot and after running GPUPDATE.EXE
Fully patched box where nothing has changed for weeks. I have tried the usual AV checks and windows update with no end in sight.

Lots of points as I have already spent ages and I can't even figure out what is eating all the endpoints.

Cheers

JamesDS
0
Comment
Question by:JamesDS
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 20

Accepted Solution

by:
What90 earned 2000 total points
ID: 10831974
Hi JamesDS,


I supposed you tried dropping the machine from the domain, rebooting, then rejoining it?
0
 
LVL 16

Author Comment

by:JamesDS
ID: 10831988
What90

Not yet, I was hoping for something non-invasive. In the absence of any other comments, i'll try it when I get home tonight and post the results then.

Cheers

JamesDS
0
 
LVL 16

Author Comment

by:JamesDS
ID: 10834642
What90

The plot thickens...

The server came off the domain fine and rebooted with impressive speed (no timing out for GPOs to run)

BUT it won't now rejoin the domain!
Instead of the usual "welcome to the xxx domain" I get the scary looking "There are no more endpoints available from the endpoint mapper"

Now, there are no errors like this in the local logs anymore, so the error looks like it's generated by the DC. The DC is a single windows 2003 AD domain full native, fully patched, 1 server only - my home installation!

I have run the usual tools and even looked at NTDSUTIL metadata cleanup to see if some old testing has come back and bit me on the ass - nothing anywhere.

I design this stuff for a living and I have never seen this before. how embarassing!

Any thoughts?

Cheers

JamesDS
0
Get your Disaster Recovery as a Service basics

Disaster Recovery as a Service is one go-to solution that revolutionizes DR planning. Implementing DRaaS could be an efficient process, easily accessible to non-DR experts. Learn about monitoring, testing, executing failovers and failbacks to ensure a "healthy" DR environment.

 
LVL 20

Expert Comment

by:What90
ID: 10838022
Buggered servers happen to use all. Sadly I get too many of them after user "repairs"

My thoughts would be back to basics:

First - have you run a fully Av scan on the server as this sugest it may be a DOS problem:
http://www.microsoft.com/technet/security/bulletin/MS01-048.mspx

Then check this link:
http://www.jsiinc.com/SUBD/tip1500/rh1597.htm

Finally give these ago:
1) Have you tried both netbios name and FQDN to re-join the domain
2) Re-apply patches
3) Possible damaged TCP/IP stack - repair it
4) Rename the Server then try to rejoin it


Let me know!
0
 
LVL 16

Author Comment

by:JamesDS
ID: 10840242
What90
We will never see this one again in a million years...

The machine in question is a Windows 2003 firewalling router box with 3 interfaces and about 3 dozen rules.
One of the rules had been setup to include port 1025TCP in its deny list, but the rule should have been acting only the external interface and was actually acting on all interfaces.

The eventual giveaway for me was when it refused to re-join the domain - yet the DC said everything was hunk-dory and I found another machine and joined it successfully.

I asked this question at the MS public newsgroups and got a load of rubbish about DNS and generic errors.

You're welcome to the points because without taking it off the domain I might never have found the duff block rule.

Cheers

JamesDS
0
 
LVL 20

Expert Comment

by:What90
ID: 10840956

So you block yourself off!  That'll teach you to have these fancy server configs ;-)

Ta for the points, but I'm much more interested in your setup and the why problem suddenly arose.

I take it you've got RRAS and the protocol filter rules in place rather than something like ISA?
Did you make any recent changes to to the rules or interfaces?







0
 
LVL 16

Author Comment

by:JamesDS
ID: 10841212
Yup, my own fault

I use the machine to build a gateway between 3 networks, one of which is a honeynet. The rule base is complex and is added to as I see threats hitting the honeynet. One of the recent additions was a trojan running on 1025TCP which should be blocking access to and from the honeynet but was actually blocking all interfaces. In order to keep the logs clear to show up new nasties hitting the honeynet I routinely don't log the threats I know about and actively kill off (not any more!), so I wasn't logging the blocked port.

The only time the error ever appeared was in the application logs during GPO refresh on the firewalling server - so I started looking at patch levels and corrupt GPOs.

I only use RRAS to provide an L2TP VPN from one network to another, all the rest of the firewalling is done with Kerio Winroute Firewall - in my opinoin the best SME firewall on the market.

The overall setup is pretty complex but I baseline all the configuration changes with virtual machines so once I had an idea it was the rulebase it only took about 10 minutes to find the culprit and nail it

The sad thing is, all this is in my house! I use it to help me design secure AD and DNS systems for my clients and consequently have no life ;)

Cheers

James
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many of us need to configure DHCP server(s) in their environment. We can do that simply via DHCP console on server or using MMC snap-in on each computer with Administrative Tools installed in a network. But what if we have to configure many DHCP ser…
Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
In this video, Percona Director of Solution Engineering Jon Tobin discusses the function and features of Percona Server for MongoDB. How Percona can help Percona can help you determine if Percona Server for MongoDB is the right solution for …
This lesson discusses how to use a Mainform + Subforms in Microsoft Access to find and enter data for payments on orders. The sample data comes from a custom shop that builds and sells movable storage structures that are delivered to your property. …
Suggested Courses

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question