Solved

How to enable SMB signing, syn-ack on windows 2008 domain controller

Posted on 2014-09-30
3
158 Views
Last Modified: 2015-02-10
Dear Support team,


Please advice, how we can implement below mentioned on windows 2008 domain controller

 
 
 How to enable

SMB Weaknesses
The SMB signing is disabled on the target systems.  
________________________

How we can set syn-ack

SYN-ACK retransmissions time limit has not been set;
'Turn off Untrusted Content' is not enabled;
________________________________________
 How to and which to services need to be stop

Active Processes
Multiple active processes are running on the system in-scope as listed in Appendix 2.
0
Comment
Question by:tabreed
  • 2
3 Comments
 
LVL 79

Accepted Solution

by:
David Johnson, CD, MVP earned 500 total points
ID: 40356164
Defaults
Enabled by default on DC's, Disabled on Member Servers

Administrative Tools|Local Security Policy.
Local Policies  | Security Options | Microsoft Network Server
Digitally sign communications (always) properties set to enabled

you can also use group policy (the drawback is a 15% network overhead)
0
 

Author Comment

by:tabreed
ID: 40356314
Thanks for your response, but in my DC it is disable. If I enable SMB is there will be any issues and can I enable on other servers like web server ERP server please advice

Thanks
0
 
LVL 79

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 500 total points
ID: 40358657
signing of packets will incur about a 15% overhead, if you need this to comply with an audit then that is what you need to do.
0

Featured Post

Master Your Team's Linux and Cloud Stack!

The average business loses $13.5M per year to ineffective training (per 1,000 employees). Keep ahead of the competition and combine in-person quality with online cost and flexibility by training with Linux Academy.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
P2v dell raid 5 servers to Hyper v 7 247
How to rename a domain with windows 2003 and exchange 2007 4 54
Windows 10 home to Pro 25 74
ost file to pst 10 141
The password reset disk is often mentioned as the best solution to deal with the lost Windows password problem. In Windows 2008, 7, Vista and XP, a password reset disk can be easily created. But besides Windows 7/Vista/XP, Windows Server 2008 and ot…
When you upgrade from Windows 8 to 8.1 or to Windows 10 or if you are like me you are on the Insider Program you may find yourself with many 450MB recovery partitions.  With a traditional disk that may not be a problem but with relatively smaller SS…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…

825 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question