Jump to content

Recommended Posts

Posted

Hello all. I have found a good few sites that go over step by step setting up file screening on a 2012r2 system, but none seem to answer some basic questions I have.

 

At my primary school I have 1 host with 2 vm servers, 1 DC and 1 Data.

 

Should I install FSRM on to the data server only? or should it get installed on to my DC? Does it only monitor local files or does it deploy across the network.

 

I am sure if I had time to installed and play with it, all the basic questions would be void, but I have not and someone else will already know these things.

 

Any good install step by steps or gotchas would be a great help also.

Posted

FSRM is put on any file server you want to monitor. It will then monitor a path that you define against a template you create. The template consists of a file group (list of file types or file names) and what to do.

 

The big question is what are you attempting to do with it?

  • Thanks 1
Posted

Yep only install on the file server. Standard basic setup would be to disallow executables on a file share or user area.

 

Very easy to setup, should only take 20mins.

  • Thanks 1
Posted
The big question is what are you attempting to do with it?

 

It was something that was mentioned on Edugeek during the wannacry attacks. I have disabled SMBv1, installed ransom protection on the server etc and this was next on my list.

Posted
Does anyone have a list of recommended executables to block?

 

If you can hold off for a few minutes I will find the PowerShell scripts that I used. This installs FSRM on any host you point it at and sets up the latest list.

  • Thanks 1
Posted

FSRM also has a template for program files.

 

Regarding ransomware, it doesnt really block it as the extensions change all the time. But its worth installing anyway.

  • Thanks 1
Posted

Think I will install manually on a test server, just so I understand the basics and then take a look at the script.

 

Is it OK to run the script on a server running Sims, SQL etc.

 

If I already have a file in a share and then install file screening and that file is on the disallow list, will it leave that file as is and only screen new files or will it block that file?

Posted

Yep I ran it on all my servers. Sims included. Not brace enough on DC's though.

I had FSRM already running on my shared area server and home drive server and just run the script and it just added the file screens

Posted
Think I will install manually on a test server, just so I understand the basics and then take a look at the script.

 

Is it OK to run the script on a server running Sims, SQL etc.

 

If I already have a file in a share and then install file screening and that file is on the disallow list, will it leave that file as is and only screen new files or will it block that file?

 

Depends on what you set. You can have it in passive mode and set it to send you an email for any issues. I'd probably recommend that if you are installing it on a server with files all ready there.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...