<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMB share - Right clicking shared folder and selecting folder properties in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/smb-share-right-clicking-shared-folder-and-selecting-folder/m-p/579732#M2777</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Check out this article. Might help.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpfCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpfCAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Thu, 07 Mar 2024 21:57:57 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2024-03-07T21:57:57Z</dc:date>
    <item>
      <title>SMB share - Right clicking shared folder and selecting folder properties</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/smb-share-right-clicking-shared-folder-and-selecting-folder/m-p/579652#M2772</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have observed an issue with an SMB share which traverses our PA FW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The initial rule was setup simply such that the client was allowed to access the remote SMB share in the firewall rule base by use of the inbuilt ms-ds-smb application container.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Client was able to browse to the folder fine and upload/download files fine with no issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However upon the client right clicking on the mapped remote shared folder and running the properties command, there is a lengthy delay (over 30 seconds) before the properties dialogue box pops up for the user. The same behaviour for the user when accessing remote over VPN and bypassing the PA FW is not present, the response is immediate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When we looked at the PA FW logs between the client and the SMB share we could see there was a deny on TCP 445 but for the active-directory-base App ID. We added this into the rule (and its various dependencies (kerberos, ms-netlogon, netbios-dg, netbios-ns, netbios-ss)) and requested the client retest.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue was still present at this point for the client. The&amp;nbsp;active-directory-base deny log however no longer appeared but instead we were now seeing a deny of the msrpc App ID (again on TCP 445) . When this was also added in the issue was fixed and the client was able to get an immediate response back when running the properties command on the shared folder.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My query then is why are these additional App ID's required. It seems the additional App ID's we had to add in should be inherited by simply using the ms-ds-smb App ID container. I get the granularity argument but its not intuitive at all and seems over kill to have to troubleshoot and add in the above to just get a right click/properties function to work on an SMB share/folder.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reading through and for any feedback provided.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 14:17:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/smb-share-right-clicking-shared-folder-and-selecting-folder/m-p/579652#M2772</guid>
      <dc:creator>dmellors</dc:creator>
      <dc:date>2024-03-07T14:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: SMB share - Right clicking shared folder and selecting folder properties</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/smb-share-right-clicking-shared-folder-and-selecting-folder/m-p/579732#M2777</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Check out this article. Might help.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpfCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpfCAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 21:57:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/smb-share-right-clicking-shared-folder-and-selecting-folder/m-p/579732#M2777</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-03-07T21:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: SMB share - Right clicking shared folder and selecting folder properties</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/smb-share-right-clicking-shared-folder-and-selecting-folder/m-p/579778#M2780</link>
      <description>&lt;P&gt;Thanks that's useful should we run into slow throughput on the SMB share.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The query above was more around having to also specify additional App ID's in the rule to get the right click menu properties to work correctly for the user on the shared folder.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2024 08:42:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/smb-share-right-clicking-shared-folder-and-selecting-folder/m-p/579778#M2780</guid>
      <dc:creator>dmellors</dc:creator>
      <dc:date>2024-03-08T08:42:42Z</dc:date>
    </item>
  </channel>
</rss>

