Hi all,
we are running our directory services in a private cloud environment as a service. In the beginning of the year we introduces Harmony Endpoint on all of our clients. After installing it on 4 Domain Controllers it began, that the operator of the ad controllers claimed, that one of the ad controllers (the PDC) sometimes starts to behave abnormal. This leads to crashin directory services and he makes the Check Point Endpoint security responsible for it.
We investigated several weeks with tac pulling memory dumps during crash time, without good results.
Yesterday I deep dived into the eventlog and created a sequence of eventlog messages that uccure every time this strange behavoiur happens.
The sequence is always the same:
25.09.2022 (Sunday)
- 8:04 AM: Active Directory Web Services was unable to determine if the computer is a global catalog server. --> EventID 1206 in Application and Services Logs / Active Directory Web Services
- 8:26 AM: The time service has stopped advertising as a time source because the local clock is not synchronized
- 8:47 AM:
- An error occurred when Active Directory Web Services attempted to connect to the directory instance. Verify that the directory instance is running.
- Directory instance: NTDS
- Directory instance LDAP port: 389
- Directory instance SSL port: 636
- Caller identity: S-1-5-21-4209190200-2177038297-167172362-20457
- 9:45 AM: Restart (Eventid 6005)
The first message with EventID 1206 occurs the first time one day after installing Check Point Harmony Endpoint which, in my eyes, makes it the cause of all this trouble.
Any Ideas of what could be the cause?
Thanks
Frank