From:
bob@sick-of-spam.invalid
In article <1097bmf$llip$
1@druck.eternal-september.org>,
druck <
news@druck.org.uk> wrote:
I would also recommend that once set up and working, you use the
Windows firewall to only allow access to the SMB ports from RISC
OS devices' IP addresses. Don't even allow all of your local
network in case of compromised devices such as security cameras or
guest's equipment.
SMBv1 is linked to ports 137,138,139 and google suggests either tcp
or udp, so to block them all is 6 firewall rules.
Are all 6 needed?
As 139 seems to be the most important, at the moment I've blocked it
for tcp and udp on a range of remote IP addresses
192.168.1.0 to 192,168.1.29
192.168.1.40 to 192.168.1.255
That leaves the 30 to 39 for RISCOS machines.
Thoughts?
Thanks.
Bob.
--- SoupGate-Linux v1.05
* Origin: Dragon's Lair ---:- FidoNet<>Usenet Gateway -:--- (3:633/10)