<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows based file shares - what applications? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/windows-based-file-shares-what-applications/m-p/41723#M30692</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;gsamuels wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Best practice would be to temporarily allow any application on this policy at which point the traffic log should indicate all applications required to allow the the remote disk share.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem with that is two-fold.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) The traffic you're looking for quickly gets "lost in the wash" - it's difficult to tell which traffic is what you want/need and which is not, especially if the destination server is multi-purpose.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) This kind of defeats the purpose of having a firewall and DMZ - if I wanted unfetted communications, I would just have the server inside and not put any rules on it at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Jan 2011 03:09:38 GMT</pubDate>
    <dc:creator>dagibbs</dc:creator>
    <dc:date>2011-01-14T03:09:38Z</dc:date>
    <item>
      <title>Windows based file shares - what applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-based-file-shares-what-applications/m-p/41721#M30690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone tell me what applications you need to allow in a PA policy rule to allow Microsoft remote disk drive shares to be accessed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, I have a server in my DMZ I want to be able to access drive shares on from my inside network by simply typing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;\\&amp;lt;server&amp;gt;\share$&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've added the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ms-ds-smb&lt;/P&gt;&lt;P&gt;netbios-dg&lt;/P&gt;&lt;P&gt;netbios-ns&lt;/P&gt;&lt;P&gt;netbios-ss&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And yet I can't get a share mapped properly through the PA. It fails every time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone cast some light on what I might be missing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 00:01:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-based-file-shares-what-applications/m-p/41721#M30690</guid>
      <dc:creator>dagibbs</dc:creator>
      <dc:date>2011-01-13T00:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: Windows based file shares - what applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-based-file-shares-what-applications/m-p/41722#M30691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Best practice would be to temporarily allow any application on this policy at which point the traffic log should indicate all applications required to allow the the remote disk share.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jan 2011 02:45:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-based-file-shares-what-applications/m-p/41722#M30691</guid>
      <dc:creator>gsamuels</dc:creator>
      <dc:date>2011-01-14T02:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: Windows based file shares - what applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-based-file-shares-what-applications/m-p/41723#M30692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;gsamuels wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Best practice would be to temporarily allow any application on this policy at which point the traffic log should indicate all applications required to allow the the remote disk share.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem with that is two-fold.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) The traffic you're looking for quickly gets "lost in the wash" - it's difficult to tell which traffic is what you want/need and which is not, especially if the destination server is multi-purpose.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) This kind of defeats the purpose of having a firewall and DMZ - if I wanted unfetted communications, I would just have the server inside and not put any rules on it at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jan 2011 03:09:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-based-file-shares-what-applications/m-p/41723#M30692</guid>
      <dc:creator>dagibbs</dc:creator>
      <dc:date>2011-01-14T03:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: Windows based file shares - what applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-based-file-shares-what-applications/m-p/41724#M30693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;if you are using DFS, this should be the open ports:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;System service name: DfsApplication protocol Protocol Ports &lt;BR /&gt;NetBIOS Datagram Service UDP 138 &lt;BR /&gt;NetBIOS Session Service TCP 139 &lt;BR /&gt;LDAP Server TCP 389 &lt;BR /&gt;LDAP Server UDP 389 &lt;BR /&gt;SMB TCP 445 &lt;BR /&gt;RPC TCP 135 &lt;BR /&gt;Randomly allocated high TCP ports TCP random port number between 1024 - 65535*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Opening any ports between the two devices is the only way to identify how many ports are used. This because any system configurations could vary the ports used/necessary and it's related always to your infrastructure (version of S.O, apps, etc).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jan 2011 11:03:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-based-file-shares-what-applications/m-p/41724#M30693</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-01-14T11:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: Windows based file shares - what applications?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/windows-based-file-shares-what-applications/m-p/41725#M30694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi dagibbs,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can always lock the ports and src/dst ip's down while you are performing the application investigation phase.&amp;nbsp; Then you are no less secure than a traditional firewall until you get the information you need to further lock down the application(s).&amp;nbsp; It's also very simple to filter the logs by src/dst to see all of the relevant conversations and weed out the others while testing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jan 2011 16:11:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/windows-based-file-shares-what-applications/m-p/41725#M30694</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2011-01-14T16:11:42Z</dc:date>
    </item>
  </channel>
</rss>

