For now, the problem has only occurred with servers that have SMB ports accessible from the outside. I imagine that someone (suspicious) tries to access using NT1, can I block access using the "min protocol" option or this could block authorized accesses as well? Thanks