Table 14 Server-side SMB1 signing Registry entries
Registry entries Values Purpose
enablesecuritysignatur
e
l
0 disabled (default)
l
1 enabled
Determines if SMB signing is
enabled.
requiresecuritysignatu
re
l
0 disabled (default)
l
1 enabled
Determines if SMB signing is
required.
The client-side settings are located in: HKEY_LOCAL_MACHINE\System
\CurrentControlSet\Services\lanmanworkstation\parameters\
Table 15 Client-side SMB1 signing Registry entries
Registry entries Values Purpose
enablesecuritysignatur
e
l
0 disabled
l
1 enabled (default)
Determines if SMB signing is
enabled.
requiresecuritysignatu
re
l
0 disabled (default)
l
1 enabled
Determines if SMB signing is
required.
IP packet reflect
IP packet reflect provides your network with an additional security level. Because the
majority of network traffic on a NAS server (including all file system I/O) is client
initiated, the NAS server uses Packet Reflect to reply to client requests. With Packet
Reflect, there is no need to determine the route to send the reply packets. Because
reply packets always go out the same interface as the request packets, request
packets cannot be used to indirectly flood other LANs. In cases where two network
devices exist, one connected to the Internet and the other connected to the intranet,
replies to Internet requests do not appear on the intranet. Also, the internal networks
used by the storage system are not affected by any packet from external networks.
IP multi-tenancy
IP multi-tenancy provides the ability to assign isolated, file-based storage partitions to
the NAS servers on a storage processor. Tenants are used to enable the cost-
effective management of available resources, while at the same time ensuring that
tenant visibility and management is restricted to assigned resources only.
With IP multi-tenancy, each tenant can have its own:
l
IP addresses and port numbers.
l
VLAN domain.
l
Routing table.
l
IP firewall.
l
DNS server or other administrative servers to allow the tenant to have its own
authentication and security validation.
Communication Security
48 EMC Unity All Flash, EMC Unity Hybrid, EMC UnityVSA 4.0 Security Configuration Guide