Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Clustering > Cluster issue following security tweaks (DISA Gold)

Reply
Thread Tools Display Modes

Cluster issue following security tweaks (DISA Gold)

 
 
GDKenoyer
Guest
Posts: n/a

 
      11-10-2008
After applying several Default Domain policy tweaks from Sep-Oct 2008 DISA
Gold disk (a US Government security configuration/assesment tool), both of
our 2-node, active/passive, Windows 2003 sp2 Clusters started throwing errors
on restart or reboot.

We started seeing the following failures:
1) The cluster nodes could not communicate; the cluster network interfaces
showed "unavailable". Additionally the event log showed repeated series of 2
event ID 1107 (one for each NIC) and 1 1079, as described here:
http://support.microsoft.com/kb/317232, but failed to respond to the
Resolution listed.

2) Trying to start the service using the GUI yielded "Error 1067: The
process terminated unexpectedly."

Attempting to run cluster.exe from a CMD window resulted in a RPC "no
endpoints" error, which led me back to two of the DISA Golfd policy fixes:
-- RPC Endpoint mapper Client Authentication
-- Restriction for Unauthenticated RPC clients
Both are found under Computer Configuration -> Administrative Templates ->
System -> Remote Procedure Call.

Setting these two back to the "not configured" setting and forcing the
policy update immediately freed the clusters of the errors and allowed normal
startup.

Note: it's is possible (likely?) that only one of these policy items is
responsible for the problem, but in the interest of restoring service I
flipped them both back.

My reasons for posting this issue are two:
1) To document this for others who might encounter it, and
2) To ask if anyone has any insight into this: is there further
configuration that would allow the cluster to run correctly with these
enabled?
 
Reply With Quote
 
 
 
 
Edwin vMierlo [MVP]
Guest
Posts: n/a

 
      11-11-2008
Did you contact support for this "package/tool" and ask them what their best
practices are for clustering ?



"GDKenoyer" <> wrote in message
news:180B1BC2-8E97-4CB7-96EF-...
> After applying several Default Domain policy tweaks from Sep-Oct 2008 DISA
> Gold disk (a US Government security configuration/assesment tool), both of
> our 2-node, active/passive, Windows 2003 sp2 Clusters started throwing

errors
> on restart or reboot.
>
> We started seeing the following failures:
> 1) The cluster nodes could not communicate; the cluster network interfaces
> showed "unavailable". Additionally the event log showed repeated series

of 2
> event ID 1107 (one for each NIC) and 1 1079, as described here:
> http://support.microsoft.com/kb/317232, but failed to respond to the
> Resolution listed.
>
> 2) Trying to start the service using the GUI yielded "Error 1067: The
> process terminated unexpectedly."
>
> Attempting to run cluster.exe from a CMD window resulted in a RPC "no
> endpoints" error, which led me back to two of the DISA Golfd policy fixes:
> -- RPC Endpoint mapper Client Authentication
> -- Restriction for Unauthenticated RPC clients
> Both are found under Computer Configuration -> Administrative Templates ->
> System -> Remote Procedure Call.
>
> Setting these two back to the "not configured" setting and forcing the
> policy update immediately freed the clusters of the errors and allowed

normal
> startup.
>
> Note: it's is possible (likely?) that only one of these policy items is
> responsible for the problem, but in the interest of restoring service I
> flipped them both back.
>
> My reasons for posting this issue are two:
> 1) To document this for others who might encounter it, and
> 2) To ask if anyone has any insight into this: is there further
> configuration that would allow the cluster to run correctly with these
> enabled?



 
Reply With Quote
 
GDKenoyer
Guest
Posts: n/a

 
      11-11-2008
Yep, a case has just been openned.

gdk

"Edwin vMierlo [MVP]" wrote:

> Did you contact support for this "package/tool" and ask them what their best
> practices are for clustering ?

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Exchange and Cluster Issues following DISA Security Tweaks GDKenoyer Server Security 0 11-18-2008 06:24 PM
Any Plans for a DISA Platinum Security Template For Vista KB86 Windows Vista Security 1 03-26-2006 05:07 PM
Digi TV Tuner issue (UK Black Gold) Roger Windows Media Center 0 09-01-2005 11:52 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59