Is their any way to monitor the traffic on a NT 4.0 RAS/VPN server. After reviewing our events we noticed there were allot of Event 529 errors.
User administrator from domain SOUP tried to logon (Type 3) from the machine \\MBB to the machine *** and specified either a bad username or bad password.
I would like to know what the best way to track this down. Can I log their IP?
Thanks
DL
User administrator from domain SOUP tried to logon (Type 3) from the machine \\MBB to the machine *** and specified either a bad username or bad password.
I would like to know what the best way to track this down. Can I log their IP?
Thanks
DL