Agent-based backup of Windows, Linux, Max, AIX and Solaris machines.
Post Reply
EpicLPer
Novice
Posts: 8
Liked: 1 time
Joined: Aug 22, 2024 5:12 am
Full Name: Stefan Kern
Contact:

Force NTLM instead of Kerberos possible?

Post by EpicLPer »

Heya,

I've upgraded from v11 to v12 yesterday and now the connection to the backup host itself says it's failing in the console.
I'm getting the following errors:
  • "Failed to send certificate, but certificate is required for remote agent management Error: Failed to establish a connection: cannot find valid IP address"
  • Task failed. Error: Connection problems.
After a bit of research it seems that v12 changed the way it authenticates with Agents, using Kerberos instead of NTLM when using a hostname instead of an IP. I'm using Veeam in my homelab and don't have a domain set up, my Backup host (the one running B&R) is failing now while the second Windows Server is still backing up just fine.

Is there any way to "force" clients to use NTLM instead of Kerberos? Or can I somehow change this in some other way to make the connection work again?

Thanks!
Andreas Neufert
VP, Product Management
Posts: 7200
Liked: 1547 times
Joined: May 04, 2011 8:36 am
Full Name: Andreas Neufert
Location: Germany
Contact:

Re: Force NTLM instead of Kerberos possible?

Post by Andreas Neufert »

Please check the setting on your operating system. We follow with the connection what is set there. https://learn.microsoft.com/en-us/previ ... 6(v=ws.10)

In general you might ran into another issue. Let´s wait for the support feedback.
EpicLPer
Novice
Posts: 8
Liked: 1 time
Joined: Aug 22, 2024 5:12 am
Full Name: Stefan Kern
Contact:

Re: Force NTLM instead of Kerberos possible?

Post by EpicLPer »

For now I've deleted the hostname entry from my inventory and just added the server via its IP, this seems to work now at least. But I would love to have an option available to choose which authentication method it will use, I love Veeam B&R for its simplicity, but sometimes it's almost "too" simple already :)
Andreas Neufert
VP, Product Management
Posts: 7200
Liked: 1547 times
Joined: May 04, 2011 8:36 am
Full Name: Andreas Neufert
Location: Germany
Contact:

Re: Force NTLM instead of Kerberos possible?

Post by Andreas Neufert »

For many security reasons we will just follow what the operating system is doing. As shared the authentication method in this case is controlled by the group policy/registry setting in windows. My guess is that you had another issue with one of the certificates used and therefore adding the server again solved it. A wild guess but maybe an explanation.
Post Reply

Who is online

Users browsing this forum: No registered users and 10 guests