Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Remote Log File Archives broken after SMBv1 disabled

After disabling SMB version 1 on our Windows servers per US-CERT best practices, UTM log file archiving is broken.
Anyone have a workaround or extra information about this?

SMBv1 disabled on Windows 2008R2 and Windows 2012R2 servers via;
Registry subkey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters Registry entry: SMB1
REG_DWORD: 0 = Disabled



This thread was automatically locked due to age.
Parents Reply
  • I can confirm both issues, based on my testings :

    1. Disabling SMB1 on the file server broke the remote log archiving (UTM 9.413-4).
    2. Disabling SMB1 on DCs (2008 R2) broke SSO AD authentication in FireFox (curiously, no problem with IE for the moment, only Firefox).
Children