<div class="content"><p align="right"><a href="https://msdn.microsoft.com/en-us/library/8401a33f-34a8-40ca-bf03-c3484b66265f" data-linktype="external">msdn link</a></p><p>The NETLOGON_SAM_LOGON_RESPONSE_EX structure is the second
extended version of the server&#39;s response to an <a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_a01cea16-0836-469c-81d4-9eeb52be1ad6" data-linktype="relative-path">LDAP ping</a> (section <a href="895a7744-aff3-4f64-bcfa-f8c05915d2e9" data-linktype="relative-path">6.3.3</a>) or a <a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_0a5fd868-ff77-4beb-838e-79f98cbe3898" data-linktype="relative-path">mailslot ping</a> (section <a href="2cff75a9-5871-4493-a704-017b506f8df0" data-linktype="relative-path">6.3.5</a>).</p><table>
 <tbody><tr>
  <th><p><br/>0</p></th>
  <th><p><br/>1</p></th>
  <th><p><br/>2</p></th>
  <th><p><br/>3</p></th>
  <th><p><br/>4</p></th>
  <th><p><br/>5</p></th>
  <th><p><br/>6</p></th>
  <th><p><br/>7</p></th>
  <th><p><br/>8</p></th>
  <th><p><br/>9</p></th>
  <th><p>1<br/>0</p></th>
  <th><p><br/>1</p></th>
  <th><p><br/>2</p></th>
  <th><p><br/>3</p></th>
  <th><p><br/>4</p></th>
  <th><p><br/>5</p></th>
  <th><p><br/>6</p></th>
  <th><p><br/>7</p></th>
  <th><p><br/>8</p></th>
  <th><p><br/>9</p></th>
  <th><p>2<br/>0</p></th>
  <th><p><br/>1</p></th>
  <th><p><br/>2</p></th>
  <th><p><br/>3</p></th>
  <th><p><br/>4</p></th>
  <th><p><br/>5</p></th>
  <th><p><br/>6</p></th>
  <th><p><br/>7</p></th>
  <th><p><br/>8</p></th>
  <th><p><br/>9</p></th>
  <th><p>3<br/>0</p></th>
  <th><p><br/>1</p></th>
 </tr>
 <tr>
  <td colspan="16">
  <p>Opcode</p>
  </td>
  <td colspan="16">
  <p>Sbz</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>Flags</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>DomainGuid
  (16 bytes)</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>...</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>...</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>DnsForestName
  (variable)</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>...</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>DnsDomainName
  (variable)</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>...</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>DnsHostName
  (variable)</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>...</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>NetbiosDomainName
  (variable)</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>...</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>NetbiosComputerName
  (variable)</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>...</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>UserName (variable)</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>...</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>DcSiteName
  (variable)</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>...</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>ClientSiteName
  (variable)</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>...</p>
  </td>
 </tr>
 <tr>
  <td colspan="8">
  <p>DcSockAddrSize</p>
  </td>
  <td colspan="24">
  <p>DcSockAddr
  (16 bytes)</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>...</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>...</p>
  </td>
 </tr>
 <tr>
  <td colspan="8">
  <p>...</p>
  </td>
  <td colspan="24">
  <p>NextClosestSiteName
  (variable)</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>...</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>NtVersion</p>
  </td>
 </tr>
 <tr>
  <td colspan="16">
  <p>LmNtToken</p>
  </td>
  <td colspan="16">
  <p>Lm20Token</p>
  </td>
 </tr>
</tbody></table><p><b>Opcode (2 bytes): </b>Operation code (see section <a href="07133ff2-a9a3-4aa9-8896-a7dcb53bdfe9" data-linktype="relative-path">6.3.1.3</a>).</p><p><b>Sbz (2 bytes): </b>This MUST be set to 0.</p><p><b>Flags (4 bytes): </b>DS_FLAG Options (see section <a href="f55d3f53-351d-4407-940e-f53eb6154af0" data-linktype="relative-path">6.3.1.2</a>).</p><p><b>DomainGuid (16 bytes): </b>The value of the <a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_784c7cce-f782-48d8-9444-c9030ba86942" data-linktype="relative-path">NC&#39;s</a> <a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_f49694cc-c350-462d-ab8e-816f0103c6c1" data-linktype="relative-path">GUID</a> <a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_108a1419-49a9-4d19-b6ca-7206aa726b3f" data-linktype="relative-path">attribute</a> specified as a <a href="../ms-dtyp/4926e530-816e-41c2-b251-ec5c7aca018a" data-linktype="relative-path">GUID</a>
structure, which is defined in <a href="../ms-dtyp/cca27429-5689-4a16-b2b4-9325d93e4ba2" data-linktype="relative-path">[MS-DTYP]</a>
section 2.3.4.</p><p><b>DnsForestName (variable): </b><a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_409411c4-b4ed-4ab6-b0ee-6d7815f85a35" data-linktype="relative-path">UTF-8</a> encoded value of the <a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_102a36e2-f66f-49e2-bee3-558736b2ecd5" data-linktype="relative-path">DNS name</a> of the <a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_fd104241-4fb3-457c-b2c4-e0c18bb20b62" data-linktype="relative-path">forest</a>, compressed as
specified in <a href="https://go.microsoft.com/fwlink/?LinkId=90264" data-linktype="external">[RFC1035]</a>
section 4.1.4. To get the decompressed string, see section <a href="b0ef9479-78d8-40c1-b6d2-0baad834ed39" data-linktype="relative-path">6.3.7</a>.</p><p><b>DnsDomainName (variable): </b>UTF-8 encoded value
of the DNS name of the NC, compressed as specified in [RFC1035] section 4.1.4.
To get the decompressed string, see section 6.3.7.</p><p><b>DnsHostName (variable): </b>UTF-8 encoded value of
the DNS name of the server, compressed as specified in [RFC1035] section 4.1.4.
To get the decompressed string, see section 6.3.7.</p><p><b>NetbiosDomainName (variable): </b>UTF-8 encoded
value of the <a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_b86c44e6-57df-4c48-8163-5e3fa7bdcff4" data-linktype="relative-path">NetBIOS</a>
name of the NC, compressed as specified in [RFC1035] section 4.1.4. To get the
decompressed string, see section 6.3.7.</p><p><b>NetbiosComputerName (variable): </b>UTF-8 encoded
value of the NetBIOS name of the server, compressed as specified in [RFC1035]
section 4.1.4. To get the decompressed string, see section 6.3.7.</p><p><b>UserName (variable): </b>UTF-8 encoded value of
the user specified in the client&#39;s request, compressed as specified in
[RFC1035] section 4.1.4. To get the decompressed string, see section 6.3.7.</p><p><b>DcSiteName (variable): </b>UTF-8 encoded value of
the <a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_8abdc986-5679-42d9-ad76-b11eb5a0daba" data-linktype="relative-path">site</a> name of the
server, compressed as specified in [RFC1035] section 4.1.4. To get the
decompressed string, see section 6.3.7.</p><p><b>ClientSiteName (variable): </b>UTF-8 encoded value
of the site name of the client, compressed as specified in [RFC1035] section
4.1.4. To get the decompressed string, see section 6.3.7.</p><p><b>DcSockAddrSize (1 byte): </b>A <a href="../ms-dtyp/77e1033f-b31d-4bd2-b3d5-9f3c9faa22eb" data-linktype="relative-path">CHAR</a>
that contains the size of the server&#39;s IP address. This field is included only
if the client specifies NETLOGON_NT_VERSION_5EX_WITH_IP in the request.</p><p><b>DcSockAddr (16 bytes): </b>The <a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_76a05049-3531-4abd-aec8-30e19954b4bd" data-linktype="relative-path">domain controller</a> IPv4
address, structured as shown in the following diagram. This field is included
only if the client specifies NETLOGON_NT_VERSION_5EX_WITH_IP in the request.</p><dl>
<dd>
<table>
 <tbody><tr>
  <th><p><br/>0</p></th>
  <th><p><br/>1</p></th>
  <th><p><br/>2</p></th>
  <th><p><br/>3</p></th>
  <th><p><br/>4</p></th>
  <th><p><br/>5</p></th>
  <th><p><br/>6</p></th>
  <th><p><br/>7</p></th>
  <th><p><br/>8</p></th>
  <th><p><br/>9</p></th>
  <th><p>1<br/>0</p></th>
  <th><p><br/>1</p></th>
  <th><p><br/>2</p></th>
  <th><p><br/>3</p></th>
  <th><p><br/>4</p></th>
  <th><p><br/>5</p></th>
  <th><p><br/>6</p></th>
  <th><p><br/>7</p></th>
  <th><p><br/>8</p></th>
  <th><p><br/>9</p></th>
  <th><p>2<br/>0</p></th>
  <th><p><br/>1</p></th>
  <th><p><br/>2</p></th>
  <th><p><br/>3</p></th>
  <th><p><br/>4</p></th>
  <th><p><br/>5</p></th>
  <th><p><br/>6</p></th>
  <th><p><br/>7</p></th>
  <th><p><br/>8</p></th>
  <th><p><br/>9</p></th>
  <th><p>3<br/>0</p></th>
  <th><p><br/>1</p></th>
 </tr>
 <tr>
  <td colspan="16">
  <p>sin_family</p>
  </td>
  <td colspan="16">
  <p>sin_port</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>sin_addr</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>sin_zero</p>
  </td>
 </tr>
 <tr>
  <td colspan="32">
  <p>...</p>
  </td>
 </tr>
</tbody></table>
</dd>
<dd>
<p><b>sin_family (2 bytes): </b>The
socket family, represented in little-endian byte order. The value SHOULD always
be AF_INET (that is, 2).</p>
</dd>
<dd>
<p><b>sin_port (2 bytes): </b>The
socket port, represented in little-endian byte order. The value SHOULD always
be zero.</p>
</dd>
<dd>
<p><b>sin_addr (4 bytes): </b>The
socket address, represented in <a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_6f6f9e8e-5966-4727-8527-7e02fb864e7e" data-linktype="relative-path">big-endian</a> byte order. The
value is an IPv4 address. If the domain controller does not have an IPv4
address, this value SHOULD be 127.0.0.1.</p>
</dd>
<dd>
<p><b>sin_zero (8 bytes): </b>Reserved.
MUST be set to zero when sending and ignored on receipt.</p>
</dd></dl><p><b>NextClosestSiteName (variable): </b>This field is
included only if the client specifies NETLOGON_NT_VERSION_WITH_CLOSEST_SITE in
the request, and if the responding DC has <a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_a98902f5-21e9-470f-b56b-cc6f8fde2141" data-linktype="relative-path">DC functional level</a>
DS_BEHAVIOR_WIN2008 or greater. When included, NextClosestSiteName contains the
name of the site that is closest by cost to ClientSiteName without being equal
to it. The site name is UTF-8 encoded, compressed as specified in [RFC1035]
section 4.1.4. To get the decompressed string, see section 6.3.7.</p><p><b>NtVersion (4 bytes): </b>NETLOGON_NT_VERSION_1 |
NETLOGON_NT_VERSION_5EX.</p><p><b>LmNtToken (2 bytes): </b>This MUST be set to
0xFFFF.</p><p><b>Lm20Token (2 bytes): </b>This MUST be set to
0xFFFF.</p><p><b>Note</b>  All multibyte quantities are
represented in little-endian byte order.</p></div>