Re: file sharing issue

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Dmitry Korolyov [MVP] (d__k_at_removethispart.mail.ru)
Date: 04/06/04


Date: Tue, 6 Apr 2004 16:41:45 -0700

Generally speaking, disabling Netbios won't allow you to achieve what you
want, plus, it is not a good idea to do hardening at a client side. You
should do it at the server side instead.

Following KB articles might help with the detailed port numbers:
http://support.microsoft.com/default.aspx?scid=kb;en-us;204279
http://support.microsoft.com/default.aspx?scid=kb;en-us;298804

Quote from the last one:
The following ports are associated with file sharing and server message
block (SMB) communications:
  a.. Microsoft file sharing SMB: User Datagram Protocol (UDP) ports from
135 through 139 and Transmission Control Protocol (TCP) ports from 135
through 139.
  b.. Direct-hosted SMB traffic without network basic input/output system
(NetBIOS) uses port 445 (TCP and UPD).

-- 
Dmitry Korolyov [d__k@removethispart.mail.ru]
MVP: Windows Server - Active Directory
"Frodo" <lyekw@cannonfareast.com> wrote in message 
news:OawKbM%23GEHA.912@TK2MSFTNGP12.phx.gbl...
> Thanks for your reply.
> Can u elaborate in more details which are the ports should I filter under
> RRAS.
> I don't think i can filter entire subnet/network because all my servers
> residing
> within the same subnet/network.
> Another alternative, if i disabled the netbios under the VPN connection at
> client notebook, will it prevent them from accessing the resources??
>
> Thanks.
>
>
> "Dmitry Korolyov [MVP]" <d__k@removethispart.mail.ru> wrote in message
> news:u5ne6yvGEHA.3556@TK2MSFTNGP11.phx.gbl...
>> Yes, you will need to use packet filtering then. If you have routing set
> up
>> for your VPN connection, just removing "file and printer sharing" 
>> protocol
>> from VPN connection itself won't do any good - since you have a lan
> address
>> for that server and file and printer sharing is bound to than lan 
>> address,
>> VPN users will be able to use that address instead.
>> So you should block inbound packets with destination port 445 and network
>> address being the lan address of that server or entire subnet. This can 
>> be
>> done from RRAS console, see under General, "Inbound filters"
>>
>> "Frodo" <lyekw_cfe@hotmail.com> wrote in message
>> news:eQY1QbsGEHA.1272@TK2MSFTNGP12.phx.gbl...
>> >I have a DC configured as file & print sharing role.
>> > Win2k srv SP4.
>> > At the same time, this DC is a VPN server as well.
>> >
>> > Problem:
>> >
>> > How can i stop the remote vpn client from accessing the network
>> > resources while they are on vpn connection ?
>> >
>> >
>> > Thanks.
>> >
>> >
>>
>>
>
> 


Relevant Pages

  • Re: Two LANs behind a single Router - How to setup VPNs for both?
    ... I can't see this working easily as apart from TCP 1723 the other part of the PPTP protocol is GRE You could keep PPTP VPN on the existing server then setup the new one to use L2TP/IPSEC, this uses different ports so the router won't get confused and still makes use of the client inbuilt into Windows machines. ... We have this setup to allow a VPN connection remotely, and the only ports forwarded to LAN1 ... I now need to add a server to the second LAN port on the router which will be totally separate from the first LAN / Domain and setup VPN access to that server too. ...
    (microsoft.public.windows.server.sbs)
  • Re: Question On Internet Access While Logged In As VPN CLient
    ... > Firewall, be able to access the internet through another ... > port on the Firewall or from their own systems without ... Why not just let them go out to the Internet through the VPN connection? ... access policy solution] or the Windows 2003 Server Quarantine Server feature ...
    (microsoft.public.inetserver.iis.security)
  • Re: Active Sync Pass Thru on Router?
    ... Hey Alan ... Even if I put the server on the Router's DMZ port, ... VPN connection to the server first, ...
    (microsoft.public.windows.server.sbs)
  • RE: VPN Connection Problem
    ... Here is the PPP log from the server after a VPN connection and disconnection: ... port = 6 ...
    (microsoft.public.windows.server.sbs)
  • Re: Windows Messenger for Exchange 2000 over VPN
    ... If it is TCP port 1503, ... but application sharing does not. ... >> that all communications was between the clients and the server on tcp ...
    (microsoft.public.windowsxp.messenger)