Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
Inbound authentication failed with error <error> for Receive connector <connector>. The authentication mechanism is <mechanism>. The source IP address of the client who tried to authenticate to Microsoft Exchange is <IP address>.
|English: Request a translation of the event description in plain English.|
This issue occurs if the Exchange server cannot authenticate with the remote Exchange server. There are many potential reasons for the authentication failure. Since it is based on Kerberos, problems such as clocks out of sync or firewalls blocking Kerberos traffic can create this situation. ME979174 provides some more details about troubleshooting this problem.
As per Microsoft: "This error event indicates that the inbound authentication from the specified source on the specified Receive connector has failed. The authentication error and the authentication mechanism are specified in the text of the error message.
To resolve this error, verify that the Receive connector and the remote client are configured to use a common authentication method with the correct credentials and required certificates". See MSEX2K3DB for additional information.
|Private comment: Subscribers only. See example of private comment|
|Links: MSEX2K3DB, ME979174|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
|Custom search for *****: Google - Bing - Microsoft - Yahoo|
Send comments or solutions
- Notify me when updated