Comprehensive data protection for all workloads
Post Reply
aabdelhakim
Lurker
Posts: 2
Liked: never
Joined: Dec 13, 2024 10:57 am
Full Name: Amr Abdelhakim
Contact:

NTLM & Keberos

Post by aabdelhakim »

Hello ,
we are trying to edit the policy on our DC to completely stop NTLMv1

Code: Select all

Refuse LM & NTLM
.
i started Auditing our Log-on as per this documenthttps://learn.microsoft.com/en-us/troub ... ler-ntlmv1

I have found Anonymous login repeated for VEEAM server , which according to MS , this can be ignored , also in the same link i included above.
I looked at Some of the VEEAM logs and i found the below entries alot

Code: Select all

[13.12.2024 09:54:30.296]    <71>    Info (3)    [SNetworkAddressResolver] Resolved ['rtm-vishared.infra.local', '10.141.24.12'] by NTLM strategy IP addresses and host names. IPAddressKind: [IPv4]. Result: ['10.64.24.48'].

[SNetworkAddressResolver] Resolved ['dcasvr99.hosting.local', '10.141.1.15'] by NTLM strategy IP addresses and host names. IPAddressKind: [IPv4]. Result: ['10.232.1.15'].

[13.12.2024 10:14:30.494]    <71>    Info (3)    [SNetworkAddressResolver] Resolved ['rtm-vishared.infra.local', '10.64.24.48'] by NTLM strategy IP addresses and host names. IPAddressKind: [IPv4]. Result: ['10.64.24.48'].

[SNetworkAddressResolver] Resolved ['xam-hv04.infra.local', '10.64.24.44'] by NTLM strategy IP addresses and host names. IPAddressKind: [IPv4]. Result: ['10.64.24.44'].

[13.12.2024 10:56:43.381]    <14>    Info (3)    [SNetworkAddressResolver] Host not joined to domain. Using NTLM only strategy.

[13.12.2024 10:56:43.400]    <14>    Info (3)    [SNetworkAddressResolver] Resolved ['ALB-VEEAM', '10.141.1.40'] by NTLM strategy IP addresses and host names. IPAddressKind: [IPv4]. Result: ['10.141.1.40'].

[13.12.2024 11:48:37.407]    <55>    Info (3)    [SNetworkAddressResolver] Resolved ['alb-cattools.hosting.local', '10.141.1.120'] by NTLM strategy IP addresses and host names. IPAddressKind: [IPv4]. Result: ['10.141.1.120'].
Do i understand from these lins that VEEAM is communicating still using NTLM ?

Note that i am using VEEAM v12 which supposedly uses Kerberos. and i am using FQDN with all managed servers /backup proxies ..etc

I would appreciate any help
Gostev
Chief Product Officer
Posts: 32237
Liked: 7598 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: NTLM & Keberos

Post by Gostev »

Hello, I can confirm that Veeam fully supports Kerberos-only environments with NTLM completely disabled. If you run into any actual issues with product functionality in such configuration (some random log lines mentioning NTLM are not an issue) then feel free to open a support case. Thanks
Andreas Neufert
VP, Product Management
Posts: 7204
Liked: 1547 times
Joined: May 04, 2011 8:36 am
Full Name: Andreas Neufert
Location: Germany
Contact:

Re: NTLM & Keberos

Post by Andreas Neufert »

I think NTLMv1 is since a while completely disabled in all windows versions by default since many years, starting from Win7/Win2008R2.
Veeam products do not have any issues with this and as Anton has said above, we even support Kerberos only environments if you want to completely get rid of NTLM (all versions). Please see https://helpcenter.veeam.com/docs/backu ... ml?ver=120
Post Reply

Who is online

Users browsing this forum: Baidu [Spider], Semrush [Bot] and 63 guests