Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Parauser
Participant

NTLM V1 Required by Identity

I don't understand Checkpoint's position on this.    There are numerous security flaws with NTLM v1 and in addition to various security scanning tools, Microsoft is strongly advising the retirement of NTLM v1.   But Checkpoint identity solution requires it for their identity solution,  and specifically requires it be enabled on domain controllers.  It is pretty audacious for Checkpoint to  say this is not a Checkpoint issue.   

 

Solution
This is not a Check Point issue.

To fix this issue:

Open the Local Group Policy Editor from the DC: Windows key + R.

Type gpedit.msc and click on OK.

Go to Security Settings > Local Policies > Security Options.

Find the key LAN Manager authentication level. If it is set to "NTVLM2 only", change it to LM and NTVLM and V2 if negotiated or Not Defined.

0 Kudos
9 Replies
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.