TCP / port 80 connection attempt when accessing a share ?

Fromhro 1 Reputation point
2022-09-14T16:37:30.587+00:00

Dear all,

I would like to have your opinion/advice on this issue.

We have a Windows 2019 server exposing a Windows Share.

Windows 10 users allowed to access this share have no issues to access the share if they are connected to our company network with a VPN connection.

However when they are directly connected to our company network without VPN, they cannot access the share
241132-image.png

From a network/firewall standpoint, only the port 445 connection is allowed on the Windows server.

When users are unsuccessfully trying to access internally to the Windows share, firewall team noticed :

  • some denied TCP connections on port 80 of the Windows Server from the user IP trying to access
  • some accepted TCP connections on port 445 of the Windows Server from the user IP trying to access

This seems to show that the server is working as expected and that the firewall is correctly configured but somehow clients are trying to connect to the port 80 of the Windows server when they are connected directly to our internal network.

Do you see what could be the explanation ? Or what could be interesting to check ?

Thank you

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,109 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,751 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Fromhro 1 Reputation point
    2022-09-23T07:34:54.477+00:00

    Hello,
    Thank you.
    In fact it turns out that it was simply coming from an AWS security group filtering the 445 port.
    We were only checking at the firewall level but there was also this AWS security group filtering the 445 connections between the end user workstations and the Windows server exposing the share.

    0 comments No comments