<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CIFS authentication security level in ONTAP Hardware</title>
    <link>https://community.netapp.com/t5/ONTAP-Hardware/CIFS-authentication-security-level/m-p/169477#M10968</link>
    <description>&lt;P&gt;Thank you so much!&amp;nbsp; I probably will terminate the sessions after the security update since we have less than 10 connections with NTLMv1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TT&lt;/P&gt;</description>
    <pubDate>Wed, 25 Aug 2021 18:10:25 GMT</pubDate>
    <dc:creator>SVHO</dc:creator>
    <dc:date>2021-08-25T18:10:25Z</dc:date>
    <item>
      <title>CIFS authentication security level</title>
      <link>https://community.netapp.com/t5/ONTAP-Hardware/CIFS-authentication-security-level/m-p/169440#M10959</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our security team wants to turn off NTLM&amp;nbsp; on our NetApp NAS.&amp;nbsp; From reading the KB below and verifying, our setting is set at the default which accepts everything listed from the article.&amp;nbsp; We want to allow NTLMv2 and Kerberos.&amp;nbsp; My question is by changing the setting, does it disconnect all current connections that are not reflective of the new security level?&amp;nbsp; Do I have to stop the SVM to disconnect all connections?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just want to make sure the security team no longer see any logs pertaining to NTLM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example: Device1 connected on NTLM.&amp;nbsp; Once the new security level is updated, does that connection get disconnected?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://library.netapp.com/ecmdocs/ECMP1610207/html/GUID-861C90E9-A8B2-405C-9020-0C38679BD72B.html" target="_blank"&gt;https://library.netapp.com/ecmdocs/ECMP1610207/html/GUID-861C90E9-A8B2-405C-9020-0C38679BD72B.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are on 9.3p18&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;TT&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:16:06 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Hardware/CIFS-authentication-security-level/m-p/169440#M10959</guid>
      <dc:creator>SVHO</dc:creator>
      <dc:date>2025-06-04T10:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS authentication security level</title>
      <link>https://community.netapp.com/t5/ONTAP-Hardware/CIFS-authentication-security-level/m-p/169450#M10961</link>
      <description>&lt;P&gt;Only new sessions will have the latest update (i.e changed -lm-compatibility-level). Rest of the sessions which are already logged in using NTLM will continue to stay up. In order to have them negotiate new security update, they need to be closed their session first.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You should be able to filter those users using NTLM via this cmd:&lt;BR /&gt;::&amp;gt; vserver cifs session show -vserver &amp;lt;vserver&amp;gt; -fields session-id,auth-mechanism&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You should then be able to close those session-id, once this is done, next time when they login they will use the updated security (auth-mechanism)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This article may help in closing sessions for those using NTLM security.&lt;BR /&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_terminate_a_CIFS_sessions_in_ONTAP_9_for_specific_Windows_users" target="_blank"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_terminate_a_CIFS_sessions_in_ONTAP_9_for_specific_Windows_users&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2021 20:32:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Hardware/CIFS-authentication-security-level/m-p/169450#M10961</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2021-08-24T20:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS authentication security level</title>
      <link>https://community.netapp.com/t5/ONTAP-Hardware/CIFS-authentication-security-level/m-p/169451#M10962</link>
      <description>&lt;P&gt;For filtering specific users using NTLMv1:&lt;/P&gt;&lt;P&gt;&amp;nbsp;vserver cifs session show -vserver &amp;lt;vserver&amp;gt; -fields session-id,auth-mechanism&amp;nbsp; -auth-mechanism NTMLv1&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2021 20:35:22 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Hardware/CIFS-authentication-security-level/m-p/169451#M10962</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2021-08-24T20:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS authentication security level</title>
      <link>https://community.netapp.com/t5/ONTAP-Hardware/CIFS-authentication-security-level/m-p/169452#M10963</link>
      <description>&lt;P&gt;Thank you for the response.&amp;nbsp; Lets say if I stop the SVM service, would that also terminate the sessions?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2021 20:45:54 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Hardware/CIFS-authentication-security-level/m-p/169452#M10963</guid>
      <dc:creator>SVHO</dc:creator>
      <dc:date>2021-08-24T20:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS authentication security level</title>
      <link>https://community.netapp.com/t5/ONTAP-Hardware/CIFS-authentication-security-level/m-p/169455#M10964</link>
      <description>&lt;P&gt;Stopping SVM Service will&amp;nbsp;stop data access on this SVM through all allowed protocols. Instead you can just stop the CIFS server and restart it. Of course this means, all the sessions currently active will drop off. However, when they re-connect they will be using new auth-mechanism.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2021 21:37:47 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Hardware/CIFS-authentication-security-level/m-p/169455#M10964</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2021-08-24T21:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS authentication security level</title>
      <link>https://community.netapp.com/t5/ONTAP-Hardware/CIFS-authentication-security-level/m-p/169477#M10968</link>
      <description>&lt;P&gt;Thank you so much!&amp;nbsp; I probably will terminate the sessions after the security update since we have less than 10 connections with NTLMv1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TT&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 18:10:25 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Hardware/CIFS-authentication-security-level/m-p/169477#M10968</guid>
      <dc:creator>SVHO</dc:creator>
      <dc:date>2021-08-25T18:10:25Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS authentication security level</title>
      <link>https://community.netapp.com/t5/ONTAP-Hardware/CIFS-authentication-security-level/m-p/445520#M11583</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone please guide me on how to set both the authentication methods(NTLMv2 &amp;amp; Kerberos) on cifs, any command reference is appreciated for ONTAP cluster.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;NetApp Release 9.1P14&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 18:04:33 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Hardware/CIFS-authentication-security-level/m-p/445520#M11583</guid>
      <dc:creator>harikapabba</dc:creator>
      <dc:date>2023-06-23T18:04:33Z</dc:date>
    </item>
  </channel>
</rss>

