Minimum SMB version

Moderators: Gully, peteru

Post Reply
User avatar
peteru
Uber Wizard
Posts: 9735
Joined: Tue Jun 12, 2007 23:06
Location: Sydney, Australia
Contact:

Minimum SMB version

Post by peteru » Sat Feb 15, 2020 20:38

This weekend I upgraded my file server to Samba 4.11.6-r2 and found that my T4 would no longer mount SMB shares if they were configured without the vers=2.1 option. Upon reading the current Samba man pages, I discovered that by default the minimum required SMB protocol version is 2.0.2 aka SMB2

This means that all currently shipping platforms that provide SMB sharing (Linux, OSX and Windows) now require SMB2 as minimum.

The 19.3 series Beyonwiz firmware is ready for this and by default all SMB mounts will use SMB2.1.

It seems that there are a number of turnkey NAS solutions (QNAP has been identified as one) that are at security risk and by default only enable the old NT1 aka SMB1 protocol. These will not work with the default Beyonwiz settings in firmware 19.3 and later, which use SMB2.1.

The recommended solution for this problem is to leave the vers=2.1 mount option in place on your Beyonwiz and update the firmware on your NAS. If your NAS will allow it, set the minimum protocol to SMB2 and maximum protocol to SMB3.

If your SMB server is not capable of supporting SMB2 and you are willing to continue using such an insecure device, you can remove the vers=2.1 mount option from your Beyonwiz configuration. Please be aware that this is not recommended from a security point of view.

"Beauty lies in the hands of the beer holder."
Blog.

Post Reply

Return to “Networking”