Consider the following scenario:
- You have multiple domains in one or more forests that have Windows Server 2012 domain controllers.
- You have at least one direct trust relationship between the domains.
- On domain controllers, you set the value of the RestrictRemoteClients registry key to 2 and the value of the EnableAuthEpResolution registry key to 1. These two registry key settings help secure RPC Endpoint Mapper.
- The secure channel between the domains is lost when you perform cross-domain NT LAN Manager (NTLM) authentication.
Log Name: System
Source: NETLOGON
Event ID: 5816
Level: Error
Description:
Netlogon has failed an authentication request of account username in domain user domain FQDN. The request timed out before it could be sent to domain controller directly trusted domain controller FQDN in domain directly trusted domain name. This is the first failure. If the problem continues, consolidated events will be logged about every event log frequency in minutes. Please see http://support.microsoft.com/kb/2654097 for more information.
Source: NETLOGON
Event ID: 5816
Level: Error
Description:
Netlogon has failed an authentication request of account username in domain user domain FQDN. The request timed out before it could be sent to domain controller directly trusted domain controller FQDN in domain directly trusted domain name. This is the first failure. If the problem continues, consolidated events will be logged about every event log frequency in minutes. Please see http://support.microsoft.com/kb/2654097 for more information.