The free OSR Learning Library has more than 50 articles on a wide variety of topics about writing and debugging device drivers and Minifilters. From introductory level to advanced. All the articles have been recently reviewed and updated, and are written using the clear and definitive style you've come to expect from OSR over the years.
Check out The OSR Learning Library at: https://www.osr.com/osr-learning-library/
I am very new to networking domain. Currently, I am encountering an issue on my server. Mapped Network drives are getting disconnected when turning on web protection in a third party AV.
In the AV logs, I see lot of these message printed. UDP packets on port 137 are blocked saying that filtering has occurred. But TCP connection on port 445 was succeeded to the client machine on my LAN.
FWPM_LAYER_ALE_AUTH_RECV_ACCEPT_V4_DISCARD Src=172.16.255.255:137, Dst=172.16.35.178:137, Protocol=UDP, PId=4, PName=System, DiscardReason=FWPS_DISCARD_FIREWALL_POLICY
FWPM_LAYER_ALE_FLOW_ESTABLISHED, SRC=172.16.50.125:49860, Dst=172.16.35.178:445, Protocol=TCP, Direction=Outbound, PId=4, PName=System"
As per the MSDN doc, I understood that when incoming accept() calls are discard this AUTH_RECV_ACCEPT_V4_DISCARD layer gets invoked.
Also, I got to know that port 137 is used for file sharing. If we want to disable file sharing on my server, I can block the port 137 so that no other computer can access the files on the server machine. I have two questions on my mind.
1) Does disabling port 137 prevents local file access by other machines or it blocks the entire file sharing so that my pc also can't access other machine files (in case other machine not blocked port 137 on it)?
2) Because of the port 137 on my server is not accepting incoming accept() calls, the mapped network drives are disconnected?
|Upcoming OSR Seminars|
|OSR has suspended in-person seminars due to the Covid-19 outbreak. But, don't miss your training! Attend via the internet instead!|
|Developing Minifilters||24 May 2021||Live, Online|
|Writing WDF Drivers||14 June 2021||Live, Online|
|Internals & Software Drivers||2 August 2021||Live, Online|
|Kernel Debugging||27 Sept 2021||Live, Online|