Updating NIC drivers, checking the switches, setting the speed of NIC's to auto might help you to solve the problem. Make sure you have installed the latest version of the Remote Desktop Connection in client computer or thin client.

Here is some interesting reading: http://blogs.technet.com/b/askperf/archive/2010/03/25/the-curious-case-of-event-id-56-with-source-termdd.aspx Some other things to look at: Are you running virus protection and have you disabled it to see if its involved?

The 2008 R2 VM still not allowed RDP connections. Changing the remote desktop setting on the target machine to allow connections from computer running any version of Remote Desktop (less secure) to see whether the issue still exists.

Please check whether too many users connect to the TS server and the performance loading is too heavy. Netsh Int Tcp Set Global Chimney=disabled Solution : The following actions solved the problem in our case. 1) Configure TCP Chimney Offload in the operating system
• To disable TCP Chimney Offload, follow these steps:

Locate the following registry subkey, and then click it: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters

The controllers use RDP sessions to remote control the instruments.

Little background on this problem.

Have you upgraded the RDP client to RDC 7 and tried with this verssion? The server is virtual vmware server and not joined to the domain.

Updating NIC drivers, checking the switches, setting the speed of NIC's to auto might help you to solve the problem.

I had other event with error code like 72 00 00 C0 and 0D 02 00 D0, but all indicate DRIVER_CORRUPTED_MMPOOL.

Reply Goodnet says: December 16, 2015 at 9:54 am Thanks!

Click Start, click Run, type regedit, and then click OK. Locate the following registry subkey, and then click it. Solved The Terminal Server security layer detected an error in the protocol stream and has disconnected the client.

The existence of the Dwm.exe process in the user session indicates that Aero is enabled for that session. Client IP: x.x.x.x Binary data: In Words 0000: 00040000 002C0002 00000000 C00A0038 0008: 00000000 C00A0038 00000000 00000000 0010: 00000000 00000000 D00000B5 In Bytes 0000: 00 00 04 00 02 00 2C

Both were running on my hyper-v box, as they are now, with 2012 R2. Client IP: fe80:0000:0000:0000:e499:f014:83ea:8221.

Client IP:

Mar 17, 2014 message string data: \Device\Termdd,

Nov 06, 2014 The Terminal Server security layer detected an error in the protocol stream and has disconnected the client. Use administrative credentials to open a command prompt.

Steps (8 total) 1Update NIC Drivers 2Disable IPv4 Large Send Offload, Checksum Offload, and TCP Connection Offload After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. UPD1: I also tried to change RDP-Tcp settings in Remote Desktop Session Host Configuration console on Network Adapters tab specifying exact adapter to use, but this had no effect.

Here is the error message: Log Name: System Source: TermDD Date: 1/9/2015 10:16:13 AM Event ID: 56 Task Category: None Level: Error Keywords: Classic User: N/A Computer: DPAAIC02.dpanet.dpa.stlouis.gov Description: The Terminal Server security layer detected an error in the protocol stream and has disconnected the client. The VMXNET3 NICs were mandated. In addition to an earlier blogpost about troubleshooting shadowing (remote controlling) sessions; http://microsoftplatform.blogspot.com/2011/04/troubleshooting-remote-control-session.html Microsoft released KB2533983 yesterday. It includes instructions on how to use err.exe to convert the binary data of the error code into a meaningful error message, and that might help you narrow down the cause

This happens sometimes when the connection has been dropped due to bad network conditions. Event Xml: 56 2 0 0x80000000000000

Mostly I wouldn't be too concerned as this is a very common occurrence on RDS/Terminal servers for Microsoft. I am logging a lot of errors once again.