- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Port Scan and SMB
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Port Scan and SMB
For the GAiA gateways, sk110873 How to configure Security Gateway to detect and prevent port scan gives a detailed configuration guide for R7x and R80.x. But for SMB units, in IPS protections we only find the protection Masscan Port Scanner - but no description how it works. I would assume that the IPS is able to collect statistics, but is that done with locally managed SMB devices ? And what about SMBs managed by R7x / R80.x, can you configure an automatic SAM rule to close the port scanning connections also on SMB gateways ?
- Tags:
- smb
- smb configuration
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Günther, on locally managed SMB appliances, I believe that is all you have.
For centrally managed, they have the same protections, such as Host Port Scan, Zmap, Masscan, etc.
They do not support SAM rules, and using "Block source" automatic reactions in SmartEvent will have no effect.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Günther, on locally managed SMB appliances, I believe that is all you have.
For centrally managed, they have the same protections, such as Host Port Scan, Zmap, Masscan, etc.
They do not support SAM rules, and using "Block source" automatic reactions in SmartEvent will have no effect.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, it is just like that - as the fw sam command does not work on SMBs and only SAM Events created by CP SAM GWs will work (no 3rd party events), this is all we have (and we even do know no details)...
