Great Circle Associates Firewalls
(July 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: TIS fwtk vs. NT SMB shares
From: Adam Shostack <adam @ homeport . org>
Date: Wed, 23 Jul 1997 22:13:44 -0400 (EDT)
To: marquis @ roble . com (Roger Marquis)
Cc: Firewalls @ GreatCircle . COM
In-reply-to: <Pine . SUN . 3 . 96 . 970723151605 . 7505A-100000 @ roble . com> from Roger Marquis at "Jul 23, 97 03:19:14 pm"

*Hobbit's white paper on CIFS security has more detail than you'll
ever want to know on CIFS, which will probably lead you to an
understanding that you need to allow some traffic on port 137 to get
browse working.

Adam

ftp://ftp.avian.org/avian/papers/cifs.txt

Roger Marquis wrote:
| We've successfully firewalled an NT fileserver using the TIS firewall
| toolkit, v2.0 plug-gw on port 139.  The problem is only Unix clients can
| access these shares/filesystems (using samba), Win95 clients cannot. 
|  
| Because the NT server checks the servername as well as sharename of each
| query we've edited the local LMHOSTS files so that the NT servername is
| mapped to the firewall's IP address.  However, although we see traffic
| going to and from the NT server, all our Win95 clients fail to mount the
| share.
|  
| Are there any white papers on firewalling NT SMB filesystems?
| 
| Roger Marquis
| 


-- 
He has erected a multitude of new offices, and sent hither swarms of
officers to harrass our people, and eat out their substance.



References:
Indexed By Date Previous: Re: FW-1 3.0 - buggy filtering ?
From: Rick Hardy <rick @ rapid . net>
Next: Re: HI
From: Casimiro de Almeida Barreto <casimiro @ snet . com . br>
Indexed By Thread Previous: TIS fwtk vs. NT SMB shares
From: Roger Marquis <marquis @ roble . com>
Next: RE: TIS fwtk vs. NT SMB shares
From: Russ <Russ . Cooper @ RC . on . ca>

Google
 
Search Internet Search www.greatcircle.com