<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[NTLMv2 Is Required For Secure Networks]]></title><description><![CDATA[<p dir="auto">This is probably a feature request.</p>
<p dir="auto">We are using pfSense in front of our Active Directory domain. Authentication in pfSense is implemented through RADIUS on AD. Group Policy for the domain  is to "Send NTLMv2 Response Only - Refuse LM and NTLM". However, because MS-CHAPv2 in pfSense uses NTLMv1, this breaks authentication, and we have to apply an exception in group policy for the pfSense machine in order to get RADIUS to work.</p>
<p dir="auto">In Windows RAS, there is a registry workaround to allow NTLMv2 compatibility for MS-CHAPv2 encryption (see <a href="https://support.microsoft.com/en-us/help/2811487" target="_blank" rel="noopener noreferrer nofollow ugc">KB2811487</a>). I am unable to find a way to implement NTLMv2 on the pfSense machine except by installing Samba.</p>
<p dir="auto">Samba. On an internet-facing firewall, gateway, and VPN server.</p>
<p dir="auto">I won't do that ever.</p>
<p dir="auto">It would be nice if pfSense could use NTLMv2 out-of-the-box.</p>
]]></description><link>https://forum.netgate.com/topic/144767/ntlmv2-is-required-for-secure-networks</link><generator>RSS for Node</generator><lastBuildDate>Thu, 11 Jun 2026 22:09:49 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/144767.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 08 Jul 2019 19:16:49 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to NTLMv2 Is Required For Secure Networks on Mon, 08 Jul 2019 19:42:58 GMT]]></title><description><![CDATA[<p dir="auto">Why can you not just LDAP to auth to your AD?</p>
]]></description><link>https://forum.netgate.com/post/852274</link><guid isPermaLink="true">https://forum.netgate.com/post/852274</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Mon, 08 Jul 2019 19:42:58 GMT</pubDate></item></channel></rss>