Intermittent SMB authentication issues due to inaccessible port 445
Applies to
- ONTAP 9
- SMB
Issue
- Intermittent access challenges to various SMB shares
EMS
event logs show:
ERROR secd.cifaAuth.problem: vaerver (SVM1) General CIPS authentication problem. Error: User authentication procedure failed
CIFS SMB2 Share mapping - Client Ip 10.20.20.40
[O ms] Login attempt by domain user DOMAIN\user1 using NTLMv2 style security
[2001] TOP connection to ip 10.10.10.2, port 445 failed: Operation timed out.
[2001] Unable to connect to NetLogon service on dc1.domain.local (Error: RESULT ERROR SPINCLIENT UNABLE TO RESOLVE SERVER)
[4034] TCP connection to ip 10.10.10.3, port 445 failed: Operation timed out.
[4034] Unable to connect to NetLogon service on dc2.domain.local (Error: RESULT ERROR SPINCLIENT UNABLE TO RESOLVE SERVER)
[6039] TOP connection to ip 10.10.10.4, port 445 failed: Operation timed out.
[6040] Unable to connect to NetLogon service on dc3.domain.local (Error: RESULT ERROR SPINCLIENT UNABLE TO RESOLVE BERVER)
[2040] TCP connection to ip 10.10.10.5, port 445 failed: Operation timed out.
[8040] Unable to connect to NetLogon service on dc4.domain.local (Error: RESULT ERROR SPINCLIENT UNABLE TO RESOLVE SERVER)
[8041] FAILURE: Unable to make connection (Netlogon:DOMAIN.LOCAL), Result: RESULT PRROR SECD NO CONNECTIONS AVAILABLE
[8041] CIFS authentication failed
[8041] Retry requested, but the retry window (7000 ms) has expired, giving up.