Ms-Rpc Protocol - Stormshield SN series Configuration Manual

Hide thumbs Also See for SN series:
Table of Contents

Advertisement

The scan of the option "utimeout" has been added to the TFTP protocol scan.

MS-RPC protocol

In order to secure Microsoft RPC traffic based on the DCE/RPC standard, this module allows
authorizing or blocking traffic using this protocol, set out in detail by the Microsoft service
(Microsoft Exchange, for example).
Automatically detect
and inspect the
protocol
Microsoft Remote Procedure Call (RPC)
Predefined MS-RPC services
The DCE/RPC protocol allows remotely hosted procedures to be launched. These services, known
as MS-RPC, which have been predefined for the main Microsoft applications, are allowed by
default.
These services classified by applications can be allowed/blocked individually or in groups by
selecting several services using the Shift key together with the buttons available in the Action
menu. The buttons "Allow all" and "Block all" make it possible to assign an action to all services.
Prohibited services will raise the alarm "DCERPC forbidden service".
A tooltip will show the UUID (Universal Unique Identifier) of each service when the mouse is rolled
over it. A blacklist allows blocking an unlisted service by entering its UUID.
The main Microsoft applications that have predefined MS-RPC services are:
Microsoft Active Directory
l
Microsoft Distributed Transaction Coordinator service
l
Microsoft Exchange
l
Microsoft File Replication service
l
Microsoft IIS
l
Microsoft Inter-site Messaging
l
Microsoft Messenger
l
Microsoft Netlogon
l
Microsoft RPC services
l
Microsoft Scheduler
l
Blacklist of MS RPC services
This table allows you to enter the Universal Unique Identifiers (UUID) of MS-RPC services that you
wish to block. Such access is allowed by default, through the alarm "DCERPC unknown UUID".
Support
Disable intrusion
prevention
Log every DCE/RPC
query
Page 279/448
If this protocol has been enabled, it will automatically be used for discovering
corresponding packets in filter rules.
When this option is selected, the scan of the MS-RPC protocol will be disabled and
traffic will be authorized if the filter policy allows it.
Enables or disables the logging of MS-RPC queries.
SNS - USER CONFIGURATION MANUAL V.3
sns-en-user_configuration_manual-v3 - Copyright © Stormshield 2016
PROTOCOLS

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents