If you are using Active Directory for your site boundaries, you can monitor the Windows
System event log for specific event IDs based on the version of Windows Server:
▶ For Windows Server 2003 and Windows Server 2008 domain controllers (DCs), look
for Event ID 5807, Type: Warning, Source: NETLOGON on each DC.
▶ On Windows 2000 domain controllers, the Event ID will be 5778.
This event indicates that one or more computers have connected to the domain control-
ler from an IP address that is not part of a defined Active Directory site. For informa-
tion on troubleshooting and remediating this issue, see