SMB sharing not accessible when TCP port 445 listening in Windows Server - Windows Server (2024)

  • Article

This article provides a solution to an issue where you can't access a Server Message Block (SMB) shared resource even when the shared resource is enabled in the target Windows Server.

Original KB number: 4471134

Symptoms

You can't access a Server Message Block (SMB) shared resource even when the shared resource is enabled on the target Windows Server. When you run the netstat command to show the network connections, the results show that TCP port 445 is listening. However, network traces show that communication on TCP port 445 is failing as follows:

SourceDestinationProtocolDescription
ClientSERVERTCPTCP:Flags=......S., SrcPort=62535, DstPort=Microsoft-DS(445), PayloadLen=0, Seq=4085616235, Ack=0, Win=8192 (Negotiating scale factor 0x8) = 8192
ClientSERVERTCPTCP:[SynReTransmit #600]Flags=......S., SrcPort=62535, DstPort=Microsoft-DS(445), PayloadLen=0, Seq=4085616235, Ack=0, Win=8192 (Negotiating scale factor 0x8) = 8192
ClientSERVERTCPTCP:[SynReTransmit #600]Flags=......S., SrcPort=62535, DstPort=Microsoft-DS(445), PayloadLen=0, Seq=4085616235, Ack=0, Win=8192 (Negotiating scale factor 0x8) = 8192

After you enable the auditing of Filtering Platform Policy Change events by using the following command, you may experience some events (such as event ID 5152) that indicate blocking.

auditpol /set /subcategory:"Filtering Platform Packet Drop" /success:enable /failure:enable

Example of event ID 5152:

Event logEvent sourceEvent IDMessage text
SecurityMicrosoft-Windows-Security-Auditing5152Description:
The Windows Filtering Platform has blocked a packet.

Application Information:
Process ID: 0
Application Name: -
Network Information:
Direction: Inbound
Source Address: 192.168.88.50
Source Port: 52017
Destination Address: 192.168.88.53
Destination Port: 445
Protocol: 6Filter Information:
Filter Run-Time ID: 67017
Layer Name: Transport
Layer Run-Time ID: 12

Cause

This issue occurs because the Adylkuzz malware that leverages the same SMBv1 vulnerability as Wannacrypt adds an IPSec policy that's named NETBC that blocks incoming traffic on the SMB server that's using TCP port 445. Some Adylkuzz-cleanup tools can remove the malware but fail to delete the IPSec policy. For details, see Win32/Adylkuzz.B.

Resolution

To fix this issue, follow these steps:

  1. Install the security update MS17-010 version appropriate to the operating system.

  2. Follow the steps on the "What to do now tab" of Win32/Adylkuzz.B.

  3. Run a scan by using the Microsoft Security Scanner.

  4. Check whether the IPSec policy blocks the TCP port 445 by using the following commands (and see the cited results for examples).

    netsh ipsec static show policy all
    Policy Name: netbc Description: NONE Last Modified: <DateTime> Assigned: YES Master PFS: NO Polling Interval: 180 minutes
    netsh ipsec static show filterlist all level=verbose
    FilterList Name: block Description: NONE Store: Local Store <WIN> Last Modified: <DateTime> GUID: {ID} No. of Filters: 1 Filter(s) --------- Description: 445 Mirrored: YES Source IP Address: <IP Address> Source Mask: 0.0.0.0 Source DNS Name: <IP Address> Destination IP Address: <IP Address> Destination DNS Name: <IP Address> Protocol: TCP Source Port: ANY Destination Port : 445 

    Note

    When you run the commands on an uninfected server, there is no policy.

  5. If the IPSec policy exists, delete it by using one of the following methods.

    • Run the following command:

      netsh ipsec static delete policy name=netbc
    • Use Group Policy Editor (GPEdit.msc):

      Local Group Policy Editor/Computer Configuration/Windows Settings/Security Settings/IPSec Security

More information

Since October 2016, Microsoft has been using a new servicing model for the supported versions of Windows Server updates. This new servicing model for distributing updates simplifies the way that security and reliability issues are addressed. Microsoft recommends keeping your systems up-to-date to make sure that they are protected and have the latest fixes applied.

This threat can run the following commands:

netsh ipsec static add policy name=netbcnetsh ipsec static add filterlist name=blocknetsh ipsec static add filteraction name=block action=blocknetsh ipsec static add filter filterlist=block any srcmask=32 srcport=0 dstaddr=me dstport=445 protocol=tcp description=445netsh ipsec static add rule name=block policy=netbc filterlist=block filteraction=blocknetsh ipsec static set policy name=netbc assign=y

It can also add firewall rules to allow connections by using these commands:

netsh advfirewall firewall add rule name="Chrome" dir=in program="C:\Program Files (x86)\Google\Chrome\Application\chrome.txt" action=allownetsh advfirewall firewall add rule name="Windriver" dir=in program="C:\Program Files (x86)\Hardware Driver Management\windriver.exe" action=allow
SMB sharing not accessible when TCP port 445 listening in Windows Server - Windows Server (2024)
Top Articles
How to Avoid Capital Gains When Selling a House
Does Your Teen Have to Pay Taxes?
Encore Atlanta Cheer Competition
Wordscapes Level 6030
Goodbye Horses: The Many Lives of Q Lazzarus
Vaya Timeclock
San Diego Terminal 2 Parking Promo Code
Soap2Day Autoplay
Carter Joseph Hopf
Stream UFC Videos on Watch ESPN - ESPN
13 The Musical Common Sense Media
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Spelunking The Den Wow
Yesteryear Autos Slang
Sport Clip Hours
Blog:Vyond-styled rants -- List of nicknames (blog edition) (TouhouWonder version)
finaint.com
Moonshiner Tyler Wood Net Worth
D10 Wrestling Facebook
Dr Manish Patel Mooresville Nc
Highland Park, Los Angeles, Neighborhood Guide
Nick Pulos Height, Age, Net Worth, Girlfriend, Stunt Actor
Free Online Games on CrazyGames | Play Now!
360 Tabc Answers
What Is Vioc On Credit Card Statement
Morristown Daily Record Obituary
O'Reilly Auto Parts - Mathis, TX - Nextdoor
Vegito Clothes Xenoverse 2
Football - 2024/2025 Women’s Super League: Preview, schedule and how to watch
Contracts for May 28, 2020
Dragonvale Valor Dragon
Craigslist Pennsylvania Poconos
Page 2383 – Christianity Today
Bj타리
Imagetrend Elite Delaware
Insidious 5 Showtimes Near Cinemark Southland Center And Xd
Trust/Family Bank Contingency Plan
Boneyard Barbers
Que Si Que Si Que No Que No Lyrics
Wasmo Link Telegram
Aveda Caramel Toner Formula
Watchseries To New Domain
Felix Mallard Lpsg
Mixer grinder buying guide: Everything you need to know before choosing between a traditional and bullet mixer grinder
Directions To The Closest Auto Parts Store
Canada Life Insurance Comparison Ivari Vs Sun Life
Caesars Rewards Loyalty Program Review [Previously Total Rewards]
New Starfield Deep-Dive Reveals How Shattered Space DLC Will Finally Fix The Game's Biggest Combat Flaw
Germany’s intensely private and immensely wealthy Reimann family
Pelican Denville Nj
Who We Are at Curt Landry Ministries
Latest Posts
Article information

Author: Kerri Lueilwitz

Last Updated:

Views: 5310

Rating: 4.7 / 5 (47 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Kerri Lueilwitz

Birthday: 1992-10-31

Address: Suite 878 3699 Chantelle Roads, Colebury, NC 68599

Phone: +6111989609516

Job: Chief Farming Manager

Hobby: Mycology, Stone skipping, Dowsing, Whittling, Taxidermy, Sand art, Roller skating

Introduction: My name is Kerri Lueilwitz, I am a courageous, gentle, quaint, thankful, outstanding, brave, vast person who loves writing and wants to share my knowledge and understanding with you.