Netbios Cifs; Profiles Screen; Netbios Ssn; Epmap Protocol - Stormshield SN series Configuration Manual

Hide thumbs Also See for SN series:
Table of Contents

Advertisement

NetBios CIFS

NetBios is a protocol that is used for sharing files/printers, generally by Microsoft systems.

Profiles screen

"IPS" tab
Automatically detect
and inspect the
protocol
Maximum size of elements (bytes)
Name of files (SMB2
format)
Microsoft RPC (DCE/RPC)
Inspect Microsoft RPC
(DCE/RPC) protocol
Authentication
Verify user legitimacy If this option is selected, you will be enabling user authentication via the CIFS header.
Support
Disable intrusion
prevention

NetBios SSN

The screens are the same as for the previous protocol, except that they allow configuring the
NetBios SSN protocol, making it possible to exchange messages in connected mode.

EPMAP protocol

This protocol allows launching procedures that are remotely hosted (bootstrap) through the
distribution of an MS-RPC service's IP address and protocol. The options of this module may
restrict the use of these relays. Dynamic connections can be opened on EPMAP (portmapper).
Automatically detect
and inspect the
protocol
Dynamic connections
As this protocol is used for relaying access to Microsoft services, the following options allow
restricting the services and options relayed by the EPMAP server.
Page 280/448
If this protocol has been enabled, it will automatically be used for discovering
corresponding packets in filter rules.
This number has to be between 1 and 65536 bytes. This file name size (SMB2 - ioctl
referral request) is set by default to 61640 to protect the system from the
vulnerability CVE 2009-2526.
As the DCE/RPC protocol can be encapsulated in this protocol, this option allows
enabling or disabling its inspection.
The CIFS plugin will therefore be capable of extracting the user ID and comparing it
against the list of users authenticated on the firewall.
When no authenticated users match, the packet will be blocked.
When this option is selected, the scan of the NetBios CIFS protocol will be disabled
and traffic will be authorized if the filter policy allows it.
If this protocol has been enabled, it will automatically be used for discovering
corresponding packets in filter rules.
SNS - USER CONFIGURATION MANUAL V.3
sns-en-user_configuration_manual-v3 - Copyright © Stormshield 2016
PROTOCOLS

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents