1.2.1.1.1.2.6 Configure 'Windows Firewall: Allow inbound file and printer sharing exception'

Information

This policy setting creates an exception that allows file and printer sharing. It configures Windows Firewall to open UDP ports 137 and 138 and TCP ports 139 and 445. Enabling access to file and printer sharing could cause a user to unknowingly expose sensitive data. Additionally, there have been vulnerabilities in the resource sharing features that have been remotely exploitable.

Solution

Configure the following Group Policy setting in a manner that is consistent with the security and operational requirements of your organization-

Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile\Windows Firewall- Allow inbound file and printer sharing exception

Impact- If you enable this policy setting, Windows Firewall opens these ports so that the computer can receive print jobs and requests for access to shared files. You must specify the IP addresses or subnets from which such messages are allowed. If you disable the Windows Firewall- Allow inbound file and printer sharing exception setting, Windows Firewall blocks these ports and prevents the computer from sharing files and printers. Note If any policy setting opens TCP port 445, Windows Firewall allows inbound ICMP echo request messages (such as those sent by the Ping utility), even if the Windows Firewall- Allow ICMP exceptions policy setting would block them. Policy settings that can open TCP port 445 include Windows Firewall- Allow inbound file and printer sharing exception, Windows Firewall- Allow inbound remote administration exception, and Windows Firewall- Define inbound port exceptions.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(11), CCE|CCE-16675-1

Plugin: Windows

Control ID: 11b2f94eba9c5fc17fb9a62b1a2327697389d794865ecf57749bffdcac30a433