If you wish to run Samba on your firewall and access shares between the firewall and local hosts, you need the following rules:
ACTION SOURCE DEST PROTO DEST
PORT(S)SOURCE
PORT(S)ORIGINAL
DESTACCEPT fw loc udp 137:139 ACCEPT fw loc tcp 137,139,445 ACCEPT fw loc udp 1024: 137 ACCEPT loc fw udp 137:139 ACCEPT loc fw tcp 137,139,445 ACCEPT loc fw udp 1024: 137
To pass traffic SMB/Samba traffic between zones Z1 and Z2:
ACTION SOURCE DEST PROTO DEST
PORT(S)SOURCE
PORT(S)ORIGINAL
DESTACCEPT Z1
Z2
udp 137:139 ACCEPT Z1
Z2
tcp 137,139,445 ACCEPT Z1
Z2
udp 1024: 137 ACCEPT Z2
Z1
udp 137:139 ACCEPT Z2
Z1
tcp 137,139,445 ACCEPT Z2
Z1
udp 1024: 137
Last modified 10/22/2002 - Tom Eastep
Copyright © 2002 Thomas M. Eastep.