Re: Problem with VPN and LMcompatibility level

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 01/29/05


Date: Fri, 28 Jan 2005 23:09:09 -0600

That is normal behavior for Windows 2000/2003 remote access servers and as
far as I know there is no workaround. Disabling lm authentication is much
more important than disabling ntlm. --- Steve

"Chris Gradden" <ChrisGradden@discussions.microsoft.com> wrote in message
news:31D65E7C-D0F8-4E80-AB67-CB22CA38EB3F@microsoft.com...
> Hi,
>
> I have a problem where a customers site is periodically unavailable via
> VPN.
> We have tracked it down to the LMcompatibility level
> (HKLM\system\CCS\control\lsa) which is setting itself to level 5. If is
> is
> set to anything lower then all is ok and people can connect. If we set it
> to
> something lower then it resets itself later.
>
> Anyone have an idea how we can resolve this issue? I understand that it
> is
> all to do with only allowing NTLM v2 and refusing NTLM and LM connections
> but
> not sure what to do to sort it fully.
>
>
> Thanks,
>
> Chris
>
>



Relevant Pages

  • Re: disabling root ssh, and ssh password authentification?
    ... > The question I have is, what good would disabling root ssh access do? ... Security protocols define authentication factors: ...
    (comp.os.linux.misc)
  • RE: Cannot connect with outlook 2007 RPC over HTTP
    ... Terminal Services Gateway or when you open the TS Gateway Manager snap-in. ... Outlook Anywhere authentication supports Basic authentication and NTLM ... I've tried disabling IPv6 as per this ...
    (microsoft.public.exchange.setup)
  • Re: NTLM
    ... We had problems disabling NTLMv1 i.e. cluster services not working ... > Test the settings working. ... > small problems without domian accounts and NTLM will come in userful. ... and call in to RRAS Remote Access by ...
    (microsoft.public.win2000.security)
  • Re: OWA 2003 Premium ... Script errors ! driving me crazy!!!
    ... why should I go down the path of disabling the Forms Based Authentication? ... Clear the IIS server files follow these steps: ... Open Exchange System Manager ...
    (microsoft.public.windows.server.sbs)
  • Re: [BUG/WARN] Error initialising drivers in PCI
    ... On 2/19/07, Bartlomiej Zolnierkiewicz wrote: ... Just disabling ata_piix should workaround the issue. ... I have done this and the message goes away in boot logs. ...
    (Linux-Kernel)