Forum Discussion

RNalivaika's avatar
RNalivaika
Iron Contributor
Jan 26, 2021
Solved

Low success rate of active name resolution

New install of Azure ATP Sensor on Domain Controller getting warning "Low success rate of active name resolution".

 

Corp-DC1, failed more than 90% of the time when doing active resolution using NetBIOS, NetworkNameResolverMethodRdpTlsName, RPC over NTLM and reverse DNS. It might affect detections capabilities and increase amount of FPs.

Recommendations

Check that the sensor can reach the DNS server and that Reverse Lookup Zones are enabled.
Check that Port 137 is open for inbound communication from MDI sensors, on all computers in the environment.
Check that Port 135 is open for inbound communication from MDI sensors, on all computers in the environment.
Check all network configuration (firewalls), as these could prevent communication to the relevant ports.

 

Need assistance interpreting or getting more information about this error. Domain controller is Server 2019 serving several sites/subnets. All other services work fine, we see no error messages in DNS Server or DNS client.

 

10 Replies