Issues with NTLMv2 only scanning

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • rthonpm
    Field Supervisor

    2,500+ Posts
    • Aug 2007
    • 2847

    #1

    Issues with NTLMv2 only scanning

    I have a government customer with their domain security level set to level 5, meaning the DC only accepts NTLMv2 responses. Since that change was made scan to folder has stopped working entirely. All of the machines have a unique AD account with rights to the shares they are trying to scan to. When trying to scan, the devices cannot connect to the share. It is affecting different models from different manufacturers. The machines are:

    Canon Image Runner Advance C5055
    Canon Image Runner Advance C7055
    Ricoh MP C3000
    Xerox Work Centre 7655

    The Canons and Ricoh are up to date on firmware levels, and should support NTLMv2; I can't say anything with certainty on the Xerox though. I'm coming into the situation as a second pair of eyes, but I'm mainly a Ricoh guy so I'm not quite sure what to look for on the Canons or Xerox.

    I've tried using both a standard user account with rights to the shares as well as a domain administrator account with global rights and still no connection. I get the prompt to check the user name and password for the destination each time. This is the first time I've seen this particular network setup so I'm hoping someone else has ran their head against this wall and found a way around it.

    Any tips or advice, or further information needed, just let me know.
  • TheOwl
    Service Manager

    Site Contributor
    1,000+ Posts
    • Nov 2008
    • 1732

    #2
    Re: Issues with NTLMv2 only scanning

    Been a long long time since I worked with Canons and I certainly haven't work on the Ricohs or Xerox before, but...

    With these machine, do you know if you can use a Windows 2000 username or FQDN?

    Windows 2000 - Domain\Username

    FQDN - Username@domain.local
    Please don't ask me for firmware or service manuals as refusal often offends.

    Comment

    • rthonpm
      Field Supervisor

      2,500+ Posts
      • Aug 2007
      • 2847

      #3
      Re: Issues with NTLMv2 only scanning

      The existing AD server is 2003 R2. There are no Windows 2000 boxes on the network as they don't meet the security requirements. Scanning to the individual workstations is also out as users do not have modify rights to any folders on the root of their drive except for their own Documents and Settings folders.

      Comment

      • TheOwl
        Service Manager

        Site Contributor
        1,000+ Posts
        • Nov 2008
        • 1732

        #4
        Re: Issues with NTLMv2 only scanning

        If you go into AD and select the account and fo to the TAB account, you will find a legancy Windows 2000 login. This is still true for Windows Server 2008.
        Please don't ask me for firmware or service manuals as refusal often offends.

        Comment

        • TheOwl
          Service Manager

          Site Contributor
          1,000+ Posts
          • Nov 2008
          • 1732

          #5
          Re: Issues with NTLMv2 only scanning

          HAHAHAHA... I just read my last post and thought "God I must have been on acid when I wrote that"!

          To find the legacy login (which is still present in Windows Server 2008 R2), go through the following:

          1. Open up Active Directory
          2. Go to the Properties of the account which you are trying to use
          3. Click on the Account Tab
          4. There you will find the legacy Windows 2000 login (which is basically the same as a standard login anyway)
          Please don't ask me for firmware or service manuals as refusal often offends.

          Comment

          • rreasonover
            Junior Member
            • Oct 2011
            • 9

            #6
            Re: Issues with NTLMv2 only scanning

            Hey I found this. May be it will help. SMB scanning on a MPC 6501 to MS Server 2012. Make sure that all your firmware is up to date.
            Attached Files

            Comment

            • rthonpm
              Field Supervisor

              2,500+ Posts
              • Aug 2007
              • 2847

              #7
              Re: Issues with NTLMv2 only scanning

              Originally posted by rreasonover
              Hey I found this. May be it will help. SMB scanning on a MPC 6501 to MS Server 2012. Make sure that all your firmware is up to date.
              This did the trick for the Ricoh. Thanks!

              Comment

              Working...