ArchChancellor
October 1st, 2007, 11:04 PM
Here is a copy of the log errors I get whenever I try to connect to a shared directory on my Windows Vista PC.
If I turn off all protection, then I can connect. If I turn off the SMB Relay attack detection, but leave the rest of the firewall on, I cannot connect.
Here is the log:
10/1/2007 9:24:40 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:24:30 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:24:24 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:24:21 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:24:20 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:23:11 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:22:39 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:22:15 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:22:03 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:21:53 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:21:47 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:21:44 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:21:43 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:20:46 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:20:14 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:19:50 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:19:38 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:19:29 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:19:23 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:19:20 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:19:18 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:16:48 PM Incorrect IP packet checksum 0
10/1/2007 9:16:46 PM Incorrect IP packet checksum 0
If I turn off all protection, then I can connect. If I turn off the SMB Relay attack detection, but leave the rest of the firewall on, I cannot connect.
Here is the log:
10/1/2007 9:24:40 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:24:30 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:24:24 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:24:21 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:24:20 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:23:11 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:22:39 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:22:15 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:22:03 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:21:53 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:21:47 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:21:44 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:21:43 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:20:46 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:20:14 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:19:50 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:19:38 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:19:29 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:19:23 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:19:20 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:19:18 PM Detected SMB Relay attack 10.0.1.200 10.0.1.2 TCP
10/1/2007 9:16:48 PM Incorrect IP packet checksum 0
10/1/2007 9:16:46 PM Incorrect IP packet checksum 0