I've noticed something strange in the domain log file when remote FTP users (using Windows Explorer) are working in there folders.
After the user logs on successfully, an anonymous logon attempt from the same IP trails the successful logon.
When the user copies a file or gets the directory list, an anonymous logon attempt is listed between commands from the same IP address. This all results in a failed logon attempts because, I turned off anonymous access.
I have it configured to ban an IP address for 3 failed logons. When these anonymous attempts happen within the users tasks, I don't want them to get banned for no reason.
I noticed that different clients result in different log entries. Is it possible that "Windows Explorer" tries to open multiple channels?
Is this normal to see this from time to time?