<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NTLM V1 Required by Identity in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117588#M1504</link>
    <description>&lt;P&gt;What exactly doesn’t make sense? The fact that Check Point (not checkpoint) supports NTLMv2? What is this post that you refer to? The official resource of information is the admin guide.&lt;/P&gt;</description>
    <pubDate>Tue, 04 May 2021 01:01:09 GMT</pubDate>
    <dc:creator>Lari_Luoma</dc:creator>
    <dc:date>2021-05-04T01:01:09Z</dc:date>
    <item>
      <title>NTLM V1 Required by Identity</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117575#M1501</link>
      <description>&lt;P&gt;I don't understand Checkpoint's position on this.&amp;nbsp; &amp;nbsp; There are numerous security flaws with NTLM v1 and in addition to various security scanning tools, Microsoft is strongly advising the retirement of NTLM v1.&amp;nbsp; &amp;nbsp;But Checkpoint identity solution requires it for their identity solution,&amp;nbsp; and specifically requires it be enabled on domain controllers.&amp;nbsp; It is pretty audacious for Checkpoint to&amp;nbsp; say this is not a Checkpoint issue.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Solution&lt;BR /&gt;This is not a Check Point issue.&lt;/P&gt;&lt;P&gt;To fix this issue:&lt;/P&gt;&lt;P&gt;Open the Local Group Policy Editor from the DC: Windows key + R.&lt;/P&gt;&lt;P&gt;Type gpedit.msc and click on OK.&lt;/P&gt;&lt;P&gt;Go to Security Settings &amp;gt; Local Policies &amp;gt; Security Options.&lt;/P&gt;&lt;P&gt;Find the key LAN Manager authentication level. If it is set to "NTVLM2 only", change it to LM and NTVLM and V2 if negotiated or Not Defined.&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 18:22:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117575#M1501</guid>
      <dc:creator>Parauser</dc:creator>
      <dc:date>2021-05-03T18:22:49Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM V1 Required by Identity</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117581#M1502</link>
      <description>&lt;P&gt;NTLM v2 is supported and can be enabled. By default it’s disabled. See the admin guide for the relevant version for instructions how to enable it.&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 20:53:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117581#M1502</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2021-05-03T20:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM V1 Required by Identity</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117583#M1503</link>
      <description>&lt;P&gt;while i am hoping your response is correct, it make no sense.&amp;nbsp; &amp;nbsp;Why didn't the original checkpoint guidance (posted in the OP)&amp;nbsp; &amp;nbsp;provide the&amp;nbsp; instructions on how to enable NTLMv2&amp;nbsp; in checkpoint instead of instruct the poster how to downgrade Windows to accept NTLM v1 ?&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 21:45:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117583#M1503</guid>
      <dc:creator>Parauser</dc:creator>
      <dc:date>2021-05-03T21:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM V1 Required by Identity</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117588#M1504</link>
      <description>&lt;P&gt;What exactly doesn’t make sense? The fact that Check Point (not checkpoint) supports NTLMv2? What is this post that you refer to? The official resource of information is the admin guide.&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 01:01:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117588#M1504</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2021-05-04T01:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM V1 Required by Identity</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117589#M1505</link>
      <description>&lt;P&gt;Assuming you're talking about AD Query, you can enable NTLMv2 as described here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk91462" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk91462&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;That said, you should probably be using Identity Collector instead.&amp;nbsp;&lt;BR /&gt;If this isn't what you're referring to, please provide some additional context.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 01:11:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117589#M1505</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-04T01:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM V1 Required by Identity</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117643#M1506</link>
      <description>&lt;P&gt;Please see SK&amp;nbsp;161972 of which I copied the main part into the OP.&amp;nbsp; &amp;nbsp; When we deployed the registry so that the domain controllers would not authenticate NTLM V1, we started seeing the exact behavior from the SK.&amp;nbsp; &amp;nbsp;The SK says this is not a Checkpoint issue and gives the instructions on how to allow the DCs to use NTLM V1 instead of referencing how to enable Checkpoint to use NTLM v2.&amp;nbsp; Perhaps it is just a recent ability to use V2 since the article.&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 13:56:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117643#M1506</guid>
      <dc:creator>Parauser</dc:creator>
      <dc:date>2021-05-04T13:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM V1 Required by Identity</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117658#M1507</link>
      <description>&lt;P&gt;What specifically are you implementing this on?&lt;BR /&gt;Because this SK is specific to older SMB appliances, not CloudGuard (where you posted this) and believe it is specific to using AD Query.&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 16:14:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117658#M1507</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-04T16:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM V1 Required by Identity</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117666#M1508</link>
      <description>&lt;P&gt;We are having the exact the issue described in the SK.&amp;nbsp; &amp;nbsp;We are running identity with Identity Collector.&amp;nbsp; &amp;nbsp;We are also using LDAP account units on the the management server.&amp;nbsp; &amp;nbsp;When we disallowed NTLM&amp;nbsp; V1 on the domain controllers and only allowed v2, we started getting the exact behaviour defined in the SK (authentication bad password because the domain controller can no longer authenticate with ntlm v1.&amp;nbsp; &amp;nbsp; &amp;nbsp;The SK said the solution is to go back and allow NTLM v1 on the domain controller which really is not a solution at all.&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 16:55:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117666#M1508</guid>
      <dc:creator>Parauser</dc:creator>
      <dc:date>2021-05-04T16:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM V1 Required by Identity</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117679#M1509</link>
      <description>&lt;P&gt;Hm...&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;can you comment on this?&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 21:53:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117679#M1509</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-04T21:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM V1 Required by Identity</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117706#M1510</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/55411"&gt;@Parauser&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;The feature in question is AD Query, which does &lt;STRONG&gt;support NTLMv2 by default&lt;/STRONG&gt; (and can be controled with adlogconfig command).&lt;/P&gt;
&lt;P&gt;The solution you have mentioned is relevant to SMB products, and seems to be out of date - I will handle it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In a general note, NTLMv1 is not mandatory to be used, and we understand the security concerns. Therefore it is not required by ADQ or any other identity source IDA offers.&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 06:19:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/NTLM-V1-Required-by-Identity/m-p/117706#M1510</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2021-05-05T06:19:51Z</dc:date>
    </item>
  </channel>
</rss>

