What is the make and model NAS that is being used? Also are the clients on different vlan's?
NAS server keeps blocking some user IP addresses.
Our client has a NAS server which is being accessed by users but the NAS keeps blocking some IPs with error repeatative bad password.
Then they have to unblock it from the NAS and then they get access.
While I have checked the user's password is not changed for a while.
After unblocking the IP we tried to access the drive and it was accessible without changing password.
I have changed the user password and tried to access the drive yet it was accessible, the IPs which are getting blocked are reandom.
Could it be issue with the AD or from the NAS server?
5 answers
Sort by: Most helpful
-
-
rr-4098 1,641 Reputation points
2022-07-24T08:30:43.577+00:00 I assume there no issues for user accessing the NAS while in the office and not through VPN correct? When a lockout happens, are you seeing anything odd in your firewall?
-
alta94 2,191 Reputation points
2022-07-24T10:22:30.77+00:00 Let me tell you about similar situation we had with fujitsu and ibm NAS. May be this will help you too.
1) Kindly check if there is any password policy running with NAS or NAS hold some policy like that. Some NAS box hold AUTOBLOCK policy where using bad password block the IP of clients
2) Kindly check with SOC team ( if you have ) or IT security Team if they are receiving any alert from your NAS IP address.---------IF YOU FIND THIS HELPFUL, PLEASE ACCEPT THE ANSWER-----------
-
rr-4098 1,641 Reputation points
2022-07-25T14:05:05.45+00:00 You may also want to reach out to you NAS vendor to see if they have heard of this before as well.
-
david dors 0 Reputation points
2024-12-06T12:17:39.8766667+00:00 Some vendors (ie. HNAS, https://community.hitachivantara.com/discussion/why-does-hnas-need-smb-client-barring-whereas-other-products-in-market-do-not-seem-to-have-a-need-of-the-same-functionality) implement SMB auto barring protection against unauthorized request that might fit the signature of a DDOS attack. If disabling such feature is not acceptable, possibly you would have to review your authentication flow to implement a more robust method.
Network traces captured simultaneously captured in both ends of the connection might show any possible errors taking place during SMB Session Setup (after SMB Dialect is negotiated).