<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Application Server Message Block v1 (SMBv1) experience in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Application-Server-Message-Block-v1-SMBv1-experience/m-p/240352#M46626</link>
    <description>&lt;P&gt;Hello CheckMates,&lt;/P&gt;&lt;P&gt;We are currently faced with a requirement to limit and block as much SMBv1 traffic as possible and restrict SMBv1 traffic to specific sources and destinations. For this use case we would like to implement firewall rules with the service (application) "Server Message Block v1 (SMBv1)" and also use the objects "Server Message Block v2 (SMBv2)" and "Server Message Block v3 (SMBv3)" instead of just allowing tcp/445 for example.&lt;/P&gt;&lt;P&gt;We are looking for some real life experience with these objects in a production ruleset. We are a little concerned about how reliable the detection of different SMB versions is in a production ruleset.&lt;/P&gt;&lt;P&gt;We have not been able to find much documentation in the Check Point support centre, knowledge base articles or fixes for these applications.&lt;/P&gt;&lt;P&gt;We would also be very interested to know how Check Point handles the different "dialects" of SMB such as 2.0.1, 3.0.2, 3.1.1 etc.&lt;/P&gt;&lt;P&gt;Any feedback would be appreciated!&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;</description>
    <pubDate>Tue, 04 Feb 2025 12:19:58 GMT</pubDate>
    <dc:creator>ProxyOps</dc:creator>
    <dc:date>2025-02-04T12:19:58Z</dc:date>
    <item>
      <title>Application Server Message Block v1 (SMBv1) experience</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Application-Server-Message-Block-v1-SMBv1-experience/m-p/240352#M46626</link>
      <description>&lt;P&gt;Hello CheckMates,&lt;/P&gt;&lt;P&gt;We are currently faced with a requirement to limit and block as much SMBv1 traffic as possible and restrict SMBv1 traffic to specific sources and destinations. For this use case we would like to implement firewall rules with the service (application) "Server Message Block v1 (SMBv1)" and also use the objects "Server Message Block v2 (SMBv2)" and "Server Message Block v3 (SMBv3)" instead of just allowing tcp/445 for example.&lt;/P&gt;&lt;P&gt;We are looking for some real life experience with these objects in a production ruleset. We are a little concerned about how reliable the detection of different SMB versions is in a production ruleset.&lt;/P&gt;&lt;P&gt;We have not been able to find much documentation in the Check Point support centre, knowledge base articles or fixes for these applications.&lt;/P&gt;&lt;P&gt;We would also be very interested to know how Check Point handles the different "dialects" of SMB such as 2.0.1, 3.0.2, 3.1.1 etc.&lt;/P&gt;&lt;P&gt;Any feedback would be appreciated!&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 12:19:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Application-Server-Message-Block-v1-SMBv1-experience/m-p/240352#M46626</guid>
      <dc:creator>ProxyOps</dc:creator>
      <dc:date>2025-02-04T12:19:58Z</dc:date>
    </item>
    <item>
      <title>Re: Application Server Message Block v1 (SMBv1) experience</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Application-Server-Message-Block-v1-SMBv1-experience/m-p/240861#M46718</link>
      <description>&lt;P&gt;I haven't seen many people comment on these specific Application definitions.&lt;BR /&gt;Note this does require using App Control for the relevant traffic, which means at least Medium Path for the relevant traffic.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure what you mean by "handles the different dialects" as I assume they identified as their major version number.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2025 19:25:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Application-Server-Message-Block-v1-SMBv1-experience/m-p/240861#M46718</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-10T19:25:18Z</dc:date>
    </item>
  </channel>
</rss>

