<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>RPC Endpoint Mapper in a network trace</title><link>http://blogs.technet.com/b/networking/archive/2009/02/03/rpc-endpoint-mapper-in-a-network-trace.aspx</link><description>Something to think about when looking at the Endpoint Mapper in a network trace. That is some title, it took a bit to come up with. In most cases when I find myself writing a technical document or blog it has to do with a specific fix for a specific problem</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: RPC Endpoint Mapper in a network trace</title><link>http://blogs.technet.com/b/networking/archive/2009/02/03/rpc-endpoint-mapper-in-a-network-trace.aspx#3256649</link><pubDate>Fri, 19 Jun 2009 11:52:37 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3256649</guid><dc:creator>Kerry</dc:creator><description>&lt;p&gt;We are seeing a strange issue with or DB2 clients (XP) joined to the domain. Once joined to the domain the application authetication windows takes 40 seconda to pop up as againt 2 sec when it was in a workgroup. From the frames, it looks like for some reason when the application is clicked, the clients trying to get the Auth Window from the AD DC (see GENA (5000) frames instead of DB2 Server...which i think is adding the delay. Can you assist as to how i can mitigate this delay? (DB 2 Server is running on AIX Machine and is configured to listed on port 50000...its a direct IP connection i.e. no name resolution issues)&lt;/p&gt;
&lt;p&gt;I have attached the capture file for your info. Any help would be much appreciated.&lt;/p&gt;
&lt;p&gt;First time 3-way Handshake&lt;/p&gt;
&lt;p&gt;8 0.000000 &amp;nbsp;{TCP:6, IPv4:5} DB2 Client &amp;nbsp; &amp;nbsp; AD DC TCP TCP:Flags=......S., SrcPort=1074, DstPort=DCE endpoint resolution(135), PayloadLen=0, Seq=2880073679, Ack=0, Win=65535 ( &amp;nbsp;) = 65535&lt;/p&gt;
&lt;p&gt;9 0.000000 &amp;nbsp;{TCP:6, IPv4:5} AD DC &amp;nbsp; &amp;nbsp; DB2 Client &amp;nbsp; &amp;nbsp;TCP TCP:Flags=...A..S., SrcPort=DCE endpoint resolution(135), DstPort=1074, PayloadLen=0, Seq=2774228518, Ack=2880073680, Win=16384 ( Scale factor not supported ) = 16384&lt;/p&gt;
&lt;p&gt;10 0.000000 &amp;nbsp;{TCP:6, IPv4:5} DB2 Client &amp;nbsp; &amp;nbsp; AD DC TCP TCP:Flags=...A...., SrcPort=1074, DstPort=DCE endpoint resolution(135), PayloadLen=0, Seq=2880073680, Ack=2774228519, Win=65535 (scale factor 0x0) = 65535&lt;/p&gt;
&lt;p&gt;RPC Bind to the Endpoint Mapper&lt;/p&gt;
&lt;p&gt;11 0.000000 &amp;nbsp;{MSRPC:7, TCP:6, IPv4:5} DB2 Client &amp;nbsp; &amp;nbsp;AD DC MSRPC MSRPC:c/o Bind: &amp;nbsp;UUID{E1AF8308-5D1F-11C9-91A4-08002B14A0FA} EPT &amp;nbsp;Call=0xD &amp;nbsp;Assoc Grp=0x0 &amp;nbsp;Xmit=0x16D0 &amp;nbsp;Recv=0x16D0 &lt;/p&gt;
&lt;p&gt;12 0.000000 &amp;nbsp;{MSRPC:7, TCP:6, IPv4:5} AD DC &amp;nbsp; &amp;nbsp; DB2 Client MSRPC MSRPC:c/o Bind Ack: &amp;nbsp;Call=0xD &amp;nbsp;Assoc Grp=0x2481B8 &amp;nbsp;Xmit=0x16D0 &amp;nbsp;Recv=0x16D0 &lt;/p&gt;
&lt;p&gt;End point Map Request to the Application&lt;/p&gt;
&lt;p&gt;13 0.000000 &amp;nbsp;{MSRPC:7, TCP:6, IPv4:5} DB2 Client &amp;nbsp; &amp;nbsp; AD DC EPM EPM:Request: ept_map: &lt;/p&gt;
&lt;p&gt;14 0.000000 &amp;nbsp;{MSRPC:7, TCP:6, IPv4:5} AD DC DB2 Client EPM EPM:Response: ept_map: &lt;/p&gt;
&lt;p&gt;Second time 3-way Handshake&lt;/p&gt;
&lt;p&gt;15 0.000000 &amp;nbsp;{TCP:8, IPv4:5} DB2 Client &amp;nbsp; &amp;nbsp; AD DC &amp;nbsp; &amp;nbsp; TCP TCP:Flags=......S., SrcPort=1075, DstPort=GENA(5000), PayloadLen=0, Seq=3342506103, Ack=0, Win=65535 ( &amp;nbsp;) = 65535&lt;/p&gt;
&lt;p&gt;16 0.000000 &amp;nbsp;{TCP:8, IPv4:5} AD DC &amp;nbsp; &amp;nbsp;DB2 Client &amp;nbsp; &amp;nbsp; TCP TCP:Flags=...A..S., SrcPort=GENA(5000), DstPort=1075, PayloadLen=0, Seq=1515412576, Ack=3342506104, Win=16384 ( Scale factor not supported ) = 16384&lt;/p&gt;
&lt;p&gt;17 0.000000 &amp;nbsp;{TCP:8, IPv4:5} DB2 Client &amp;nbsp; &amp;nbsp;AD DC TCP TCP:Flags=...A...., SrcPort=1075, DstPort=GENA(5000), PayloadLen=0, Seq=3342506104, Ack=1515412577, Win=65535 (scale factor 0x0) = 65535&lt;/p&gt;
&lt;p&gt;RPC Bind to the Endpoint Mapper&lt;/p&gt;
&lt;p&gt;18 0.000000 &amp;nbsp;{MSRPC:9, TCP:8, IPv4:5} DB2 Client &amp;nbsp; &amp;nbsp;AD DC &amp;nbsp; &amp;nbsp;MSRPC MSRPC:c/o Bind: &amp;nbsp;UUID{12345778-1234-ABCD-EF00-0123456789AB} LSARpc &amp;nbsp;Call=0xD &amp;nbsp;Assoc Grp=0x0 &amp;nbsp;Xmit=0x16D0 &amp;nbsp;Recv=0x16D0 &lt;/p&gt;
&lt;p&gt;19 0.000000 &amp;nbsp;{MSRPC:9, TCP:8, IPv4:5} AD DC &amp;nbsp; &amp;nbsp; DB2 Client MSRPC MSRPC:c/o Bind Ack: &amp;nbsp;Call=0xD &amp;nbsp;Assoc Grp=0x363A17 &amp;nbsp;Xmit=0x16D0 &amp;nbsp;Recv=0x16D0 &lt;/p&gt;
&lt;p&gt;End point Map Request to the Application&lt;/p&gt;
&lt;p&gt;20 0.000000 &amp;nbsp;{MSRPC:9, TCP:8, IPv4:5} DB2 Client &amp;nbsp; &amp;nbsp; AD DC &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; LSAT LSAT:LsarLookupNames4 Request, *Encrypted*&lt;/p&gt;
&lt;p&gt;21 0.000000 &amp;nbsp;{MSRPC:9, TCP:8, IPv4:5} AD DC &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;DC DB Client &amp;nbsp; &amp;nbsp; LSAT LSAT:LsarLookupNames4 Response, *Encrypted*&lt;/p&gt;
&lt;p&gt;After these frames only i see that the DB Client connecting to DB Server&lt;/p&gt;
&lt;p&gt;22 0.000000 Admin.exe {TCP:11, IPv4:10} DB2 Client &amp;nbsp; &amp;nbsp; DB2 Server &amp;nbsp; &amp;nbsp; TCP TCP:Flags=......S., SrcPort=1076, DstPort=50000, PayloadLen=0, Seq=2538123636, Ack=0, Win=65535 ( Negotiating scale factor 0x1 ) = 65535&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3256649" width="1" height="1"&gt;</description></item><item><title>BlogMS Weekly Articles Published – 2nd February to 8th February</title><link>http://blogs.technet.com/b/networking/archive/2009/02/03/rpc-endpoint-mapper-in-a-network-trace.aspx#3199442</link><pubDate>Mon, 09 Feb 2009 21:19:25 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3199442</guid><dc:creator>BlogMS - Official Microsoft Team Blogs</dc:creator><description>&lt;p&gt;214 Microsoft Team blogs searched, 93 blogs have new articles in the past 7 days. 212 new articles found&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3199442" width="1" height="1"&gt;</description></item><item><title>Active Directory and Firewalls &amp;laquo; IT notes</title><link>http://blogs.technet.com/b/networking/archive/2009/02/03/rpc-endpoint-mapper-in-a-network-trace.aspx#3197181</link><pubDate>Thu, 05 Feb 2009 00:36:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3197181</guid><dc:creator>Active Directory and Firewalls &amp;laquo; IT notes</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://virdep.wordpress.com/2009/02/04/active-directory-and-firewalls/"&gt;http://virdep.wordpress.com/2009/02/04/active-directory-and-firewalls/&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3197181" width="1" height="1"&gt;</description></item></channel></rss>