?
Solved

How to enable SMB signing, syn-ack on windows 2008 domain controller

Posted on 2014-09-30
3
Medium Priority
?
170 Views
Last Modified: 2015-02-10
Dear Support team,


Please advice, how we can implement below mentioned on windows 2008 domain controller

 
 
 How to enable

SMB Weaknesses
The SMB signing is disabled on the target systems.  
________________________

How we can set syn-ack

SYN-ACK retransmissions time limit has not been set;
'Turn off Untrusted Content' is not enabled;
________________________________________
 How to and which to services need to be stop

Active Processes
Multiple active processes are running on the system in-scope as listed in Appendix 2.
0
Comment
Question by:tabreed
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 82

Accepted Solution

by:
David Johnson, CD, MVP earned 1500 total points
ID: 40356164
Defaults
Enabled by default on DC's, Disabled on Member Servers

Administrative Tools|Local Security Policy.
Local Policies  | Security Options | Microsoft Network Server
Digitally sign communications (always) properties set to enabled

you can also use group policy (the drawback is a 15% network overhead)
0
 

Author Comment

by:tabreed
ID: 40356314
Thanks for your response, but in my DC it is disable. If I enable SMB is there will be any issues and can I enable on other servers like web server ERP server please advice

Thanks
0
 
LVL 82

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 1500 total points
ID: 40358657
signing of packets will incur about a 15% overhead, if you need this to comply with an audit then that is what you need to do.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Have you ever had a hard drive that you can't boot into, but need to change the registry? Here is the solution! This article guides you through accessing and editing a registry of a non-primary drive. To read registry information on a non-prim…
INTRODUCTION The purpose of this document is to demonstrate the Installation and configuration of the Data Protection Manager product. Note that this demonstration was prepared on the basis of Windows OS is 2008 R2 and DPM 2010. DATA PROTECTI…
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question