Feature Request - Disable Firewall Changes on Updates

Availability for the Always-On Enterprise

Feature Request - Disable Firewall Changes on Updates

Veeam Logoby bg.ranken » Mon May 15, 2017 5:23 pm


I recently upgraded from Veeam 9.0 Update 1 to Veeam 9.5 Update 1. I noticed after the upgrade that it re-enabled all firewall rules that were previously disabled within the Windows Firewall.

Is there any way that this can be removed or put an option to disable firewall changes during the upgrade? I'm not sure if this applies to a same version update as well (9.5U1 to 9.5U2) but if so it would be nice to have that as well.

The reason I ask is because our Veeam servers are locked down, off the domain. We have all Windows firewall rules disabled to only allow necessary Veeam functionality. However after the upgrade which I did Friday, the install re-enabled a lot of the File and Printer Sharing rules, to include the SMB-In rules. All of these were previously disabled to avoid possible encryption via Cryptolocker attacks. But the update left us vulnerable to the latest ETERNALBLUE exploit that exploded this weekend.

Also, as a side question, is there any reason the install even enables all these file and printer sharing features in the first place? We have had them disabled since we built the server and all functionality (backups, backup-copy, application aware processing, SureBackups, etc) has not been affected. I even remember gostev saying a few times in his weekly digest that disabling these firewall rules (specifically SMB) would be a good idea to avoid specific attacks like what happened this weekend.
Posts: 56
Liked: 10 times
Joined: Wed Feb 18, 2015 8:13 pm
Full Name: Randall Kender

Re: Feature Request - Disable Firewall Changes on Updates

Veeam Logoby foggy » Thu May 18, 2017 1:57 pm

Hi Randall, I don't believe this is caused by the Veeam B&R update. Any chance the firewall profile for the network adapter has switched for some reason?
Veeam Software
Posts: 15872
Liked: 1198 times
Joined: Mon Jul 11, 2011 10:22 am
Full Name: Alexander Fogelson

Return to Veeam Backup & Replication

Who is online

Users browsing this forum: Google Feedfetcher and 1 guest