How save is SMB3 Encryption ?

I was researching the SMB3 Encryption option under Server 4.0.

I was wondering how save is this ? When i open port 445 in my router to acces my SMB share outside the network ?


Without encryption i did see some information, like path of folders. With encryption there was nothing readable in my package capture.


Is there a way to sniff out my login and password ?

Is there a way to sniff out information inside documents that i open ?


If this is save than a VPN is not necessary anymore for file-sharing.

Mac mini, OS X Server, Server 4.x

Posted on Jan 26, 2015 11:22 AM

Reply
2 replies

Jan 27, 2015 8:05 AM in response to Patrick Savelberg (Private)

From general security principals you should not open any ports unless you have to. As you don't have to open the ports for SMB and can instead use a VPN it is best to stick with a VPN.


Remember also that with a VPN traffic is always encrypted, with SMB it will only be encrypted if both devices support SMB3 and both ends have not been configured to disable this, otherwise it might automatically drop down to SMB2 or even SMB1 which are not encrypted.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

How save is SMB3 Encryption ?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.