Schannel Fatal Alert (70)

Hey guys,

Exchange 2010 latest SP3 with RU 10.

Been getting a lot of these, I installed wireshark and changed it's filter to ssl, once I was able to determine that alert 70 meant protocol version not supported.

I managed to link it to my boses phone Note 4, running android 5.01...

26518 2015-08-20 13:44:10.758922000 172.#.#.# 172.16.20.38 TLSv1 73 Alert (Level: Fatal, Description: Protocol Version)

Thing is at first he was having issues with ActiveSync internally but not externally (Split DNS for our activesync.

I went into his settings and unchecked "use SSL" -> Auth Failed (AS it should as SSL is required) -> "Use SSL" -> internal ActiveSync started to work, at which point I had hoped the events would stop.. I did this just before lunch today...

As you can tell by the timestamp they are still occurring... does anyone know what I could possible check to help resolve the issue?

I checked the packets from other ip addresses and they all seem to be using the same protocol version of TLS 1.0.

Any thoughts welcome, and thanks!

August 20th, 2015 2:57pm

All I did was told my boss to completely remove his account on his phone.

Then re-create it from scratch... I have no seen the event or the alert packet in wireshark since he did this.

  • Marked as answer by Zewwy 10 hours 58 minutes ago
Free Windows Admin Tool Kit Click here and download it now
August 20th, 2015 4:33pm

All I did was told my boss to completely remove his account on his phone.

Then re-create it from scratch... I have no seen the event or the alert packet in wireshark since he did this.

  • Marked as answer by Zewwy Thursday, August 20, 2015 8:33 PM
August 20th, 2015 8:33pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics