If a server has specified that NTLMv2 session security is required,
then negotiation will fail as the client does not advertise this during
the handshake. The negoiate message needs to include the relevant
flag 'negotiateFlagNTLMSSPNEGOTIATEEXTENDEDSESSIONSECURITY'
To test enable this on the remote server by using regedt32 to modify the
key
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\NtlmMinServerSec and
set the value to 0x20080000