Skip to main content

Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More

Loading...
Loading...

ERRMSG: AD Agent error: 104 Operation not allowed

Expand / Collapse


This article applies to:

  • AD Agent 
  • R3000
  • WF/WFR

Symptoms:

  • The AD Agent's session tab populates with data, but no authentications occur on the filter.  In the Activity tab of the Agent, the log periodically shows the following error in red text: TxData AuthMod ERROR Reply Code: 104 Operation not allowed&$Content-Length: 0&$&$

Causes:

  • The error "AuthMod ERROR Reply Code: 104 Operation not allowed" basically means that the Agent was rejected when it was trying to establish a connection with the filter.

Resolution:

There are two main causes of this problem. The first is simply that the passphrase which was set on both the Agent and filter does not match. You can try re-entering this on both sides.

The second is that in the R3000's Agent settings (found under System -> Authentication -> Enable/Disable Authentication -> Settings button in AD Agent section), the "computer name" is defined improperly. This computer name should be set as the netbios name of the server that the Agent is installed on, and not a fully qualified name.


To contact LevelBlue about this article or to request support:


Rate this Article:
     

Add Your Comments


Comment submission is disabled for anonymous users.
Please send feedback to Trustwave Technical Support or the Webmaster
.