• Home
  • Topics
    • Office 365
    • Teams
    • SharePoint
    • Exchange 2019
    • Exchange 2016
    • Exchange 2013
    • Hybrid
    • Certificates
    • PowerShell
    • Migration
    • Security
    • Azure
  • Blog
  • Podcast
  • Webinars
  • Books
  • About
  • Subscribe
    • Facebook
    • Twitter
    • RSS
    • YouTube

Practical 365

You are here: Home / Exchange Server / MS08-037 causes port conflicts with DNS and IAS services

MS08-037 causes port conflicts with DNS and IAS services

January 28, 2009 by Paul Cunningham 2 Comments

You may encounter an issue with servers running both the DNS and IAS services that have installed update MS08-037 (Vulnerabilities in DNS could allow spoofing – 953230).  The IAS services will fail to start and any authentication that relies on IAS (such as VPNs) will fail.

When connecting to the IAS server with the IAS management console the following errors may appear:

An error occurred while trying to make a connection to the datastore

There was an error getting connection to the data store. The handle is invalid.

Event ID 7023 will appear in the System event log of the IAS server.

 

Event Type:    Error
Event Source:    Service Control Manager
Event Category:    None
Event ID:    7023
Date:        28/01/2009
Time:        9:15:17 AM
User:        N/A
Computer:    SERVER
Description:

The Internet Authentication Service service terminated with the following error:

Only one usage of each sock address (protocol/network address/port) is normally permitted.

The cause of the issue is explained in KB956188:

 

You experience issues with UDP-dependent network services after you install DNS Server service security update 953230 (MS08-037)

This issue occurs because the service cannot obtain the port that it requires to function correctly. This issue occurs because of changes to the port allocation in the DNS Service after security update 953230 is installed.

Read full article

The solution is to reserve the IAS ports from the ephemeral port range to ensure that the DNS Server service does not dynamically allocate those ports to itself.  To determine which ports are being used by IAS open the IAS management console, right-click the server name and select Properties.

iasconfig01

Navigate to the Ports tab and note the port numbers in use.

iasconfig02

Follow the instructions in KB812873 (How to reserve a range of ephemeral ports on a computer that is running Windows Server 2003) and enter the correct ports in the registry key like this.

regconfig

The server must be restarted for the change to take effect.  After the restart the DNS Server will no longer allocate the IAS ports to itself, which will allow IAS to start properly.

Exchange Server DNS, Event ID 7023, IAS, MS08-037, Server 2003

Comments

  1. PeteNetLive says

    November 16, 2010 at 2:05 am

    Awesome I had a similar problem also

    http://www.petenetlive.com/KB/Article/0000353.htm

    Pete

    Reply
  2. Dirk says

    August 12, 2009 at 7:57 am

    Thank you. Thank you. Thank you.

    Reply

Leave a Reply Cancel reply

You have to agree to the comment policy.

Recent Articles

  • The Practical 365 Weekly Update: S2, Ep 8 – What to expect in 2021, Solarigate, TLS in Exchange and new Teams updates
  • Security updates released for Exchange and SharePoint Servers 2010 to 2019
  • The Practical 365 Weekly Update: S2, Ep 7 – Urgent Exchange security updates, new Teams features launch
  • How to train your users against threats with Attack Simulation Training
  • Fall 2020 roundup of compliance updates
Practical 365

Related Posts

Related Posts

Training Courses

  • Configuring and Managing Office 365 Security
  • Office 365 Admin Playbook
  • Exchange 2016 Exam 70-345
  • Managing Exchange Mailboxes and Distribution Groups in PowerShell
  • More Training Courses...

Recommended Resources

  • Office 365 Security Resources
  • Office 365 Books
  • Exchange Server Books
  • Exchange Server Migrations
  • Exchange Analyzer
  • Digicert SSL Certificates

About This Site

Practical 365 is a leading site for Office 365 and Exchange Server news, tips and tutorials. Read more...

Find out more about advertising with us.

Contact us


Subscribe to our newsletter
  • Facebook
  • Twitter
  • RSS
  • YouTube

Copyright © 2021 Quadrotech Solutions AG · Disclosure · Privacy Policy
Alpenstrasse 15, 6304 Zug, Switzerland