05-30-2023 06:36 PM - last edited on 06-14-2023 08:01 PM by Mercedes_O
We've got SMBv1 Auditing enabled on our domain and SMBv1 disabled on everything including the Lansweeper scan servers.
We're seeing event log entries on our DCs from both of our scan servers like the one below. Nothing else is generating these events, just the scan servers. Judging by the timings it looks like it's IP range scanning that is triggering it.
--------------------------
Log Name: Microsoft-Windows-SMBServer/Audit
Source: Microsoft-Windows-SMBServer
Date: 5/30/2023 7:10:10 AM
Event ID: 3000
Task Category: None
Level: Information
Keywords:
User: N/A
Computer: DC01.Domain.Local
Description:
SMB1 access
Client Address: SCANServer01
--------------------------
Is there any way we can prevent scans from triggering this?
04-10-2024 09:39 AM
Did you resolve the issue? We have constant SMB1 logon attempts from scan server blocked on our QNAP system and i don't know how to stop scan servers from using SMB1.
04-11-2024 07:29 AM
You can create fw rule on ther LS server to block LS scan remote SMB port of the QNAP system.
04-10-2024 02:43 PM
No, I review the logs occasionally, but as the only thing generating those events is the the scan servers I've just started ignoring them, which isn't exactly best practice. 😞
05-31-2023 11:30 AM
Hi @Mister_Nobody ,
Sorry, I wasn't clear. I'm not picking up the events in Lansweeper, I'm seeing them as part of our general security monitoring processes.
If possible I want to prevent the scan process from generating SMBv1 connections in the first place. Partly just to reduce the noise in our SIEM system, but also because it makes me nervous that anything is apparently trying to use the very insecure SMBv1 at all.
05-31-2023 11:44 AM
You have to read about Windows Audit Policy to Enable or Disable Security Events Audit
05-31-2023 12:28 PM
I know how to enable or disable the audit events, that's why I'm getting them in the first place. I want to see events when something tries to make SMBv1 connections so we can monitor for insecure systems, I just want to know if I can stop Lansweeper from doing so.
05-31-2023 12:48 PM - edited 05-31-2023 12:51 PM
05-31-2023 05:29 PM
We're not using a Workgroup scanning target so I don't think that's relevant.
05-31-2023 07:16 AM
You can exclude such events from scanning
https://community.lansweeper.com/t5/scanning-your-network/excluding-events-from-scanning/ta-p/64348
Experience Lansweeper with your own data. Sign up now for a 14-day free trial.
Try Now