01-25-2011 06:23 AM
I'm wondering if it is possible to define an 'application' based on an SMB URI path?
Example - I have two shares on a SMB SAN server \\san\public and \\san\secret; is it possible to apply a firewall rule to a Palo device that sits between this server and clients such that access to the shares can be restricted based the destination path, not just the server identity/IP?
The intent is that this would supplement the core ACL functionality on the datastore, serving as a failsafe way of restricting access to network storage in the event that inappropriate ACL rights are granted in error.
Thanks
01-25-2011 08:26 AM
I don't believe we have access to the SMB decoder to create an application like that.
01-25-2011 09:06 AM
At least PAN claims to be able to scan smb traffic for virus. This implies they have a decoder for smb or am I wrong ?
rgds
Roland
01-25-2011 09:14 AM
01-25-2011 11:05 AM
Hi There,
The SMB decoder is currently not available for configuration like the HTTP decoder.
Please contact your local sales team (that'll be me ) to file a feature request apackard.
Thanks
James
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!