- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Re: Mobile Access Portal & FileServer
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Mobile Access Portal & FileServer
Hello mates,
We have a problem with a FileServer accesing through the mobile access portal.
We have the file server as "file share" on mobile access applications and the corresponging rule. The link url is on the MAP.
We can access the File Server internally without problem
We have this problem after upgrade the cluster from R81.10 to R81.20, and this happen on both members, doesn´t matter which one is the active one. The last JHF is installed (24)
Thanks in advance, best regards
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The problem was solved changing the SMB version on the gateway side
All Mobile Access blade versions on Security Gateways R80.30 3.10 and R80.40 and above support SMB v2/3. The default SMB version in the newer gateways is still '1.0'
You can change the default SMB version running: cvpnd_settings $CVPNDIR/conf/cvpnd.C set FileShareDefaultSmbVersion "<version>"
Per Microsoft from 2016: "SMB 1.0 is deprecated. Once this is removed, systems running Windows XP or Windows Server 2003 (or older) operating systems will not be able to access file shares. SMB 1.0 has been replaced by SMB 2.0 and newer versions." Therefore, if using SMBv1 for file-sharing, users might experience issue with accessing resources. Unless drops are specifically seen in traffic capture on gateway this is a non-Check Point issue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would involve TAC asap...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The problem was solved changing the SMB version on the gateway side
All Mobile Access blade versions on Security Gateways R80.30 3.10 and R80.40 and above support SMB v2/3. The default SMB version in the newer gateways is still '1.0'
You can change the default SMB version running: cvpnd_settings $CVPNDIR/conf/cvpnd.C set FileShareDefaultSmbVersion "<version>"
Per Microsoft from 2016: "SMB 1.0 is deprecated. Once this is removed, systems running Windows XP or Windows Server 2003 (or older) operating systems will not be able to access file shares. SMB 1.0 has been replaced by SMB 2.0 and newer versions." Therefore, if using SMBv1 for file-sharing, users might experience issue with accessing resources. Unless drops are specifically seen in traffic capture on gateway this is a non-Check Point issue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Good that you found a solution. SMBv1 is deprecated since years! Question is now WHY is it again in use in R81.20??
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, I don´t know why the default SMB version in R81.20 is still '1.0' and this is not carried over from previous version because a clean install was performed
