Every several minutes I get an audit failure from one of my clients running Windows 8 on ports 56280 to 56294 in the event log of my server which provides DHCP/DNS/DC for that client. Do you have any idea what those ports are or how I can find out more about this?
EventID 4625
Task 12544
LogonType 3
LogonProcessName NtLmSsp
AuthenticationPackageName NTLM