Background: I began auditing some things in early March. The issue I'm asking about has only happened on one day, the 18th.
Issue: A pile of anonymous logons. The Event ID is 538, which means it is a logoff event, and the Logon Type is 3, meaning it is a network access.
Does anybody know why I would have a massive amount of network logoffs from ANONYMOUS LOGON, and with no logons??? I'm hoping it's something simple and that I just don't understand how it all works....
btw: I do realize that the ANONYMOUS LOGON is a built-in thing to Win2k, but I thought I had things configured well enough that no anonymous access was permitted.
Thanks a lot for any helpful info.
Oh, and a screenshot showing my audit is available here.
b
Issue: A pile of anonymous logons. The Event ID is 538, which means it is a logoff event, and the Logon Type is 3, meaning it is a network access.
Does anybody know why I would have a massive amount of network logoffs from ANONYMOUS LOGON, and with no logons??? I'm hoping it's something simple and that I just don't understand how it all works....
btw: I do realize that the ANONYMOUS LOGON is a built-in thing to Win2k, but I thought I had things configured well enough that no anonymous access was permitted.
Thanks a lot for any helpful info.
Oh, and a screenshot showing my audit is available here.
b
Comment