Article ID: 956189 - Last Review: July 25, 2008 - Revision: 1.1 Some services may not start or may not work correctly on a computer that is running Windows SBS after you install the DNS Server security update 953230 (MS08-037)
SYMPTOMS
You may experience many network-related problems after you install the Domain Name System (DNS) security update 953230 (MS08-037) on a computer that is running Windows Small Business Server (SBS), and then you restart the computer. For example, you may experience any of the following problems. Problem 1The Internet Authentication Service (IAS) does not start, and an Error event that resembles the following is logged in the System event log:
Event Type: Error Event Source: Service Control Manager Event Category: None Event ID: 7023 Date: Date Time: Time User: N/A Computer: Server_name Description: The Internet Authentication Service service terminated with the following error: Only one usage of each socket address (protocol/network address/port) is normally permitted. Problem 2Microsoft Exchange Server Always Up To Date (AUTD) notifications for ActiveSync fail, and Error events that resemble the following are logged in the Application event log: Event Type: Error Event Source: Server ActiveSync Event Category: None Event ID: 3015 Date: Date Time: Time User: N/A Computer: Server_name Description: IP-based AUTD failed to initialize because the processing of notifications could not be set up. Error code [0x80004005]. Verify that no other applications are currently bound to UDP port [2883], or try specifying a different port number.
Event Type: Error Event Source: Server ActiveSync Event Category: None Event ID: 3024 Date: Date Time: Time User: N/A Computer: Server_name Description: IP-based AUTD failed to initialize. Error code: [0x80004005]. Problem 3The IPSEC Services service does not start, and Error events that resemble the following are logged in the System event log:
Event Type: Error Event Source: Service Control Manager Event Category: None Event ID: 7023 Date: Date Time: Time User: N/A Computer: Server_name Description: The IPSEC Services service terminated with the following error: Only one usage of each socket address (protocol/network address/port) is normally permitted.
Event Type: Error Event Source: IPSec Event Category: None Event ID: 4292 Date: Date Time: Time User: N/A Computer: Server_name Description: The IPSec driver has entered Block mode. IPSec will discard all incoming and outgoing TCP/IP network traffic that is not permitted by boot-time IPSec Policy exemptions. User Action: To restore full unsecured TCP/IP connectivity, disable the IPSec services, and then restart the computer. For detailed troubleshooting information, review the events in the Security event log. CAUSE
This problem occurs because the DNS Server service is listening on the UDP port that is required by another service. This problem occurs when the MaxUserPort registry entry is present. This registry entry is located in the following subkey in the registry:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\
Collapse this table
RESOLUTIONImportant
This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base: 322756
(http://support.microsoft.com/kb/322756/
)
How to back up and restore the registry in Windows To resolve this problem, add the port that is needed by the service to the ReservedPorts registry value. This prevents the DNS Server service from listening on that port.
The following ports are known to cause conflicts:
Collapse this table
STATUSMicrosoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section. MORE INFORMATION
For more information, click the following article numbers to view the article in the Microsoft Knowledge Base:
953230
(http://support.microsoft.com/kb/953230/
)
MS08-037: Vulnerabilities in DNS could allow spoofing
812873
(http://support.microsoft.com/kb/812873/
)
How to reserve a range of ephemeral ports on a computer that is running Windows Server 2003 or Windows 2000 Server
APPLIES TO
| Other Resources Other Support Sites
CommunityGet Help NowArticle Translations
|





















Back to the top