• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Problem with GPO

Scheduled Pinned Locked Moved Routing and Multi WAN
3 Posts 2 Posters 2.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • F
    FMFREAK
    last edited by Dec 15, 2010, 7:41 AM Dec 14, 2010, 7:45 PM

    We are routinh through a pfsense machine. Everything works fine. The only thing is that we getting errors when we login with Windows XP clients on our Windows 2008 R2 servers. A couple of time there is no problem with login but after 3 a 4 times the login is very slow. In the Windows XP event log we've got the following error:

    Windows cannot query for the list of Group Policy objects. A message that describes the reason for this was previously logged by the policy engine

    Windows cannot bind to ***.local domain. (Local Error). Group Policy processing aborted.

    The Security System could not establish a secured connection with the server ldap/..local/.local@.LOCAL.  No authentication protocol was available.

    The Security System detected an attempted downgrade attack for server ldap/..local/.local@.LOCAL.  The failure code from authentication protocol Kerberos was "There are currently no logon servers available to service the logon request.
    (0xc000005e)".

    The Security System could not establish a secured connection with the server ldap/..local/.local@.LOCAL.  No authentication protocol was available.

    The Security System detected an attempted downgrade attack for server ldap/..local/.local@.LOCAL.  The failure code from authentication protocol Kerberos was "There are currently no logon servers available to service the logon request.
    (0xc000005e)".

    The problem only exist when we route over 2 different VLANs (with a different subnet) (User net to server net) With all protocols enabled (via rules setting). When the workstation is in the same vlan there is no problem.

    Does anyone know a solution ?

    1 Reply Last reply Reply Quote 0
    • S
      sinac
      last edited by Dec 19, 2010, 11:42 PM

      I'm having the same issue (using ipsec though). Looks like this is an UDP Fragmentation issue.

      1 Reply Last reply Reply Quote 0
      • S
        sinac
        last edited by Dec 25, 2010, 1:20 PM

        Just to keep you updated: In my case, disabling the scrubbing function did the trick.

        1 Reply Last reply Reply Quote 0
        3 out of 3
        • First post
          3/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received