Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ProxyOps
Contributor

Application Server Message Block v1 (SMBv1) experience

Hello CheckMates,

We are currently faced with a requirement to limit and block as much SMBv1 traffic as possible and restrict SMBv1 traffic to specific sources and destinations. For this use case we would like to implement firewall rules with the service (application) "Server Message Block v1 (SMBv1)" and also use the objects "Server Message Block v2 (SMBv2)" and "Server Message Block v3 (SMBv3)" instead of just allowing tcp/445 for example.

We are looking for some real life experience with these objects in a production ruleset. We are a little concerned about how reliable the detection of different SMB versions is in a production ruleset.

We have not been able to find much documentation in the Check Point support centre, knowledge base articles or fixes for these applications.

We would also be very interested to know how Check Point handles the different "dialects" of SMB such as 2.0.1, 3.0.2, 3.1.1 etc.

Any feedback would be appreciated!

Kind regards

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

I haven't seen many people comment on these specific Application definitions.
Note this does require using App Control for the relevant traffic, which means at least Medium Path for the relevant traffic. 

Not sure what you mean by "handles the different dialects" as I assume they identified as their major version number. 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events