Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to block inbound SMB traffic

I´m trying to block SMB traffic. This has to do with the WACRY ransomware. 

Im sure its an easy thing to do, but when im trying to add an firewall rule to block TCP / UDP. But i cannot edit the TCP / UDP to port 139. The "save" button is "grey". 

Whats the best way to block inbound ports? 

Thanks.

 



This thread was automatically locked due to age.
Parents
  • Martin,

    remember that a firewall acts as layer 3 devices, so you can block traffic only between vlan or different LAN. You cannot block traffic that does not traverse firewall. For example between 2 comnputers in the same lan.

    For the port, create a new rule where source port is * and destination is 139.

    Regards

Reply
  • Martin,

    remember that a firewall acts as layer 3 devices, so you can block traffic only between vlan or different LAN. You cannot block traffic that does not traverse firewall. For example between 2 comnputers in the same lan.

    For the port, create a new rule where source port is * and destination is 139.

    Regards

Children