Networking-Blog

My WordPress Blog

Cisco Deny Netbios Traffic Access-List (NETBIOS OVER TCP/IP)

We will look at what this port is used for, and how it relates to the security in Windows 2000.
SMB over TCP vs SMB over NBT The SMB (Server Message Block) protocol is used among other things
for file sharing in Windows NT / 2000.

In Windows NT it ran on top of NBT (NetBIOS over TCP/IP), which used the famous ports 137, 138 (UDP)
and 139 (TCP). In Windows 2000, Microsoft added the possibility to run SMB directly over TCP/IP,
without the extra layer of NBT. For this they use TCP port 445.

When Windows 2000 uses port 445, and when it uses 139 In Windows 2000 you have the possibility to
disable NetBIOS over TCP/IP.

1. You do this by right-clicking on My Network Places and selecting Properties.
2.  Then right-click on the appropriate Local Area Connection icon, and select Properties.
3. Next, click on Internet Protocol (TCP/IP) and Properties.
4. Now click Advanced, and select the WINS tab. There you can enable or disable NetBIOS over TCP/IP.

The changes take effect immediately without rebooting the system. From now on I will refer to the “client“
as the computer from where you map drives and other shared resources, and to the “server” as the
computer with resources that are shared. I will also refer to NetBIOS over TCP/IP only as NBT.
If the client has NBT enabled, it will always try to connect to the server at both port 139 and 445
simultaneously.

If there is a response from port 445, it sends a RST to port 139, and continues it’s SMB session to
port 445 only. If there is no response from port 445, it will continue it’s SMB session to port 139 only,
if it gets a response from there.If there is no response from either of the ports,
the session will fail completely.

If the client has NBT disabled, it will always try to connect to the server at port 445 only.
If the server answers on port 445, the session will be established and continue on that port.
If it doesn’t answer, the session will fail completely.

This is the case if the server for example runs Windows NT 4.0. If the server has NBT enabled, it listens on
UDP ports 137, 138, and on TCP ports 139, 445.

If it has NBT disabled, it listens on TCP port 445 only.

If you want it to never use anything but port 445, disable NBT.

Created an access-list on the LAN interface of internal LAN traffic going out.

ip access-list extended LAN
deny ip host 172.20.19.255 any
deny ip host 172.20.19.0 any
deny ip host 0.0.0.0 any
deny tcp 172.20.19.0 0.0.0.255 any eq 135
deny udp 172.20.19.0 0.0.0.255 any eq 136
deny udp 172.20.19.0 0.0.0.255 any eq netbios-ns
deny udp 172.20.19.0 0.0.0.255 any eq netbios-dgm
deny tcp 172.20.19.0 0.0.0.255 any eq 139
permit ip 172.20.19.0 0.0.0.255 172.20.0.0 0.0.255.255
permit ip 172.20.19.0 0.0.0.255 any
!
!
Assign ACL to Vlan Interface:

config t
interface vlan 1
ip access-group LAN in

Resulting in :

show ip access-list LAN

Extended IP access list LAN
5 deny ip host 172.20.19.255 any
10 deny ip host 172.20.19.0 any
15 deny ip host 0.0.0.0 any (17 matches)
20 deny tcp 172.20.19.0 0.0.0.255 any eq 135 (207211 matches)
25 deny udp 172.20.19.0 0.0.0.255 any eq 136
30 deny udp 172.20.19.0 0.0.0.255 any eq netbios-ns (1622677 matches)
35 deny udp 172.20.19.0 0.0.0.255 any eq netbios-dgm (5305 matches)
40 deny tcp 172.20.19.0 0.0.0.255 any eq 139 (107979 matches)
45 permit ip 172.20.19.0 0.0.0.255 172.20.0.0 0.0.255.255 (7586488 matches)
50 permit ip 172.20.19.0 0.0.0.255 any (262280 matches)

How to configure a firewall for domains and trusts

epmap           Port 135 TCP         DCE endpoint resolution
epmap           Port 135 UDP         DCE endpoint resolution
profile         Port 136 TCP         PROFILE Naming System
profile         Port 136 UDP         PROFILE Naming System
netbios-ns      Port 137 TCP         NETBIOS Name Service
netbios-ns      Port 137 UDP         NETBIOS Name Service
netbios-dgm     Port 138 TCP         NETBIOS Datagram Service
netbios-dgm     Port 138 UDP         NETBIOS Datagram Service
netbios-ssn     Port 139 TCP         NETBIOS Session Service
netbios-ssn     Port 139 UDP         NETBIOS Session Service

To establish a domain trust or a security channel across a firewall, the following ports must be opened. Be aware that there may be hosts functioning with both client and server roles on both sides of the firewall. Therefore, ports rules may have to be mirrored.

Windows NT

In this environment, one side of the trust is a Windows NT 4.0 trust, or the trust was created by using the NetBIOS names.

Collapse this tableExpand this table
Client Port(s) Server Port Service
137/UDP 137/UDP NetBIOS Name
138/UDP 138/UDP NetBIOS Netlogon and Browsing
1024-65535/TCP 139/TCP NetBIOS Session
1024-65535/TCP 42/TCP WINS Replication

Windows Server 2003 and Windows 2000 Server

For a mixed-mode domain that uses either Windows NT domain controllers or legacy clients, trust relationships between Windows Server 2003-based domain controllers and Windows 2000 Server-based domain controllers may necessitate that all the ports for Windows NT that are listed in the previous table be opened in addition to the following ports.

Note The two domain controllers are both in the same forest, or the two domain controllers are both in a separate forest. Also, the trusts in the forest are Windows Server 2003 trusts or later version trusts.

Client Port(s) Server Port Service
1024-65535/TCP 135/TCP RPC
1024-65535/TCP 1024-65535/TCP LSA RPC Services (*)
1024-65535/TCP/UDP 389/TCP/UDP LDAP
1024-65535/TCP 636/TCP LDAP SSL
1024-65535/TCP 3268/TCP LDAP GC
1024-65535/TCP 3269/TCP LDAP GC SSL
53,1024-65535/TCP/UDP 53/TCP/UDP DNS
1024-65535/TCP/UDP 88/TCP/UDP Kerberos
1024-65535/TCP 445/TCP SMB

Windows Server 2008/Windows Server 2008 R2

In a mixed-mode domain that consists of Windows Server 2003 domain controllers, Windows 2000 Server-based domain controllers, or legacy clients, the default dynamic port range is 1025 through 5000. Windows Server 2008 and Windows Server 2008 R2, in compliance with Internet Assigned Numbers Authority (IANA) recommendations, has increased the dynamic client port range for outgoing connections. The new default start port is 49152, and the default end port is 65535. Therefore, you must increase the RPC port range in your firewalls.

Client Port(s) Server Port Service
49152 -65535/UDP 123/UDP W32Time
49152 -65535/TCP 135/TCP RPC-EPMAP
49152 -65535/TCP 138/UDP Netbios
49152 -65535/TCP 49152 -65535/TCP RPC
49152 -65535/TCP/UDP 389/TCP/UDP LDAP
49152 -65535/TCP 636/TCP LDAP SSL
49152 -65535/TCP 3268/TCP LDAP GC
49152 -65535/TCP 3269/TCP LDAP GC SSL
53, 49152 -65535/TCP/UDP 53/TCP/UDP DNS
49152 -65535/TCP 135, 49152 -65535/TCP RPC DNS
49152 -65535/TCP/UDP 88/TCP/UDP Kerberos
49152 -65535/TCP/UDP 445/NP-TCP/NP-UDP SAM/LSA

Active Directory

For Active Directory to function correctly through a firewall, the Internet Control Message Protocol (ICMP) protocol must be allowed through the firewall from the clients to the domain controllers so that the clients can receive Group Policy information.

ICMP is used to determine whether the link is a slow link or a fast link. ICMP is a legitimate protocol that Active Directory uses for Group Policy detection and for Maximum Transfer Unit (MTU) detection. The Windows Redirector also uses ICMP to verify that a server IP is resolved by the DNS service before a connection is made.