Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Remote Log File Archives broken after SMBv1 disabled

After disabling SMB version 1 on our Windows servers per US-CERT best practices, UTM log file archiving is broken.
Anyone have a workaround or extra information about this?

SMBv1 disabled on Windows 2008R2 and Windows 2012R2 servers via;
Registry subkey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters Registry entry: SMB1
REG_DWORD: 0 = Disabled



This thread was automatically locked due to age.
Parents Reply
  • We're looking at disabling SMB1 on our DCs but when we tested this it broke our UTM AD SSO.  We're still running UTM v 9.4 at the moment.  Can anyone confirm that UTM still needs SMB1 for it's authentication?

    Obviously we need to take this seriously because of the "wanna..." ransomware attacks

Children