DCOM Errors Event ID 10009

Hi all,

I am having an issue with a server in a secure domain, the event log is full of DCOM errors. The log is full of them and new logs appear at a rate of 3 per second which is difficult to work with when troubleshooting issues.
Now I am aware that these errors could be caused by any number of reasons but whats strange is that the addresses DCOM is trying to contact are on an external WLAN and none of the addresses can be pinged..
I have tried installing Wireshark to capture the traffic to find out what is generating these errors but nothing obvious shows up.. just wondering if anyone has any suggestions on how to troubleshoot this?

RPC port is not blocked as far as I can see
Addresses are on external WLAN do not have access to the server anyway so not sure what happens there
DNS Scavenging is configured and runs every day

Many Thanks
LVL 1
Nolan GustavoAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Kamal KhaleefaInformation Security SpecialistCommented:
Put the public ip in browser and check what service is running
0
PaulOffordCommented:
Hi, You can use the Windows command

ipconfig /displaydns > dnscache.txt

to dump out the DNS cache on your server to a text file then search the file to find the unknown IP addresses and matching names.

In this case you may be better using Microsoft NetMon on the server to check what is generating the requests rather than Wireshark.  NetMon shows the process details (program name and pid).  I believe Message Analyser does the same but I'm not familiar with it.  You can still download NetMon 3.4.

Best regards...Paul
0
Nolan GustavoAuthor Commented:
King 2002, please could you elaborate? I am not sure if I understand your suggestion.

PaulOffrod, I tried installing NetMon but the installation fails at the moment so going to reboot the server in attempt to resolve this.. Unfortunately Message Analyser does not run on Server 2008, has to be R2 or Win7. I will let you know once I have rebooted the server and tried installing this again.

 Many Thanks!
0
Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

PaulOffordCommented:
Hi Nolan,

I hadn't noticed that this is 2008 r1.  I'm not sure if you will get the process information - there are quite a few additional capabilities n this area in r2.

If you don't we can talk about using netstat instead.  Not quite as neat but may be good enough.

Best regards...Paul
0
Kamal KhaleefaInformation Security SpecialistCommented:
I mean first open ie browser http://public ip making error
And check what is the site
As dcom error with external url
You need to find what service website cuse it in advance to troubleshoot 'dcom error is too genaric'
0
Nolan GustavoAuthor Commented:
Hi apologies it has been a while but I finally managed to get to the bottom of this. Problem was with DNS scavenging not enabled on one of the domain controllers.. as soon as we enabled DNS scavenging these errors stopped immediately! Going to check again on Monday and will let you know if this is resolved.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.