Aligning on mDNS: ramping down NetBIOS name resolution and LLMNR

Published Apr 22 2022 09:00 AM 5,170 Views

The modern standard for multicast name discovery is mDNS. However, Windows supports other multicast name resolutions protocols for historical reasons, including NetBIOS name resolution and LLMNR. More details about the documentation for each of these protocols can be found here.

 

NetBIOS name resolution and LLMNR are rarely used today. This means that having them enabled needlessly expands the attack surface of devices and increases the load on the networks they use. Disabling these protocols needs to be balanced with real-world deployments which may still depend on them, but it is still the right direction to go.

 

NetBIOS name resolution has been turned off by default on cellular interfaces for some time because it should never be applicable there. In the latest Windows Dev and Beta Insider builds, it has been placed in “learning mode” where NetBIOS is only used as a fallback after mDNS and LLMNR queries fail. This means devices will typically stop using NetBIOS name resolution unless it is manually re-enabled because mDNS will most frequently answer first.

 

If this causes connectivity issues, the previous NetBIOS name resolution functionality can be restored by enabling the “Configure NetBIOS settings” Group Policy and select one of the allow or learning modes. This Group Policy can be found under Computer Configuration > Administrative Templates > Network > DNS Client.

 

tojens_1-1650495363980.png

 

 

Another way to restore the original NetBIOS name resolution behavior is to use the registry. Under the “Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters” key, create a REG_DWORD called “EnableNetbios” and set it to one of the following values:

 

0 Disabled
1 Allowed
2 Disabled on public networks
3 Learning mode (the current default in Insider builds)

 

The default LLMNR behavior has not been changed in Windows yet. This will be part of the next steps toward the “mDNS is the only multicast name resolution protocol on by default” goal.

 

Going forward, depending on how this first stage goes (so far, the data indicate it is going well), these protocols will progress toward being turned off by default in all cases. Like any other case of disabling long-enabled OS functionality, this will be a careful process open to feedback.

6 Comments
%3CLINGO-SUB%20id%3D%22lingo-sub-3290816%22%20slang%3D%22en-US%22%3EAligning%20on%20mDNS%3A%20ramping%20down%20NetBIOS%20name%20resolution%20and%20LLMNR%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3290816%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20modern%20standard%20for%20multicast%20name%20discovery%20is%20mDNS.%20However%2C%20Windows%20supports%20other%20multicast%20name%20resolutions%20protocols%20for%20historical%20reasons%2C%20including%20NetBIOS%20name%20resolution%20and%20LLMNR.%20More%20details%20about%20the%20documentation%20for%20each%20of%20these%20protocols%20can%20be%20found%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fopenspecs%2Fwindows_protocols%2Fms-wpo%2Ff00add7f-a321-4a5f-a5d8-1748e748cd44%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehere%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ENetBIOS%20name%20resolution%20and%20LLMNR%20are%20rarely%20used%20today.%20This%20means%20that%20having%20them%20enabled%20needlessly%20expands%20the%20attack%20surface%20of%20devices%20and%20increases%20the%20load%20on%20the%20networks%20they%20use.%20Disabling%20these%20protocols%20needs%20to%20be%20balanced%20with%20real-world%20deployments%20which%20may%20still%20depend%20on%20them%2C%20but%20it%20is%20still%20the%20right%20direction%20to%20go.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ENetBIOS%20name%20resolution%20has%20been%20turned%20off%20by%20default%20on%20cellular%20interfaces%20for%20some%20time%20because%20it%20should%20never%20be%20applicable%20there.%20In%20the%20latest%20Windows%20Dev%20and%20Beta%20Insider%20builds%2C%20it%20has%20been%20placed%20in%20%E2%80%9Clearning%20mode%E2%80%9D%20where%20NetBIOS%20is%20only%20used%20as%20a%20fallback%20after%20mDNS%20and%20LLMNR%20queries%20fail.%20This%20means%20devices%20will%20typically%20stop%20using%20NetBIOS%20name%20resolution%20unless%20it%20is%20manually%20re-enabled%20because%20mDNS%20will%20most%20frequently%20answer%20first.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20this%20causes%20connectivity%20issues%2C%20the%20previous%20NetBIOS%20name%20resolution%20functionality%20can%20be%20restored%20by%20enabling%20the%20%E2%80%9CConfigure%20NetBIOS%20settings%E2%80%9D%20Group%20Policy%20and%20select%20one%20of%20the%20allow%20or%20learning%20modes.%20This%20Group%20Policy%20can%20be%20found%20under%20Computer%20Configuration%20%26gt%3B%20Administrative%20Templates%20%26gt%3B%20Network%20%26gt%3B%20DNS%20Client.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22tojens_1-1650495363980.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F365691i3C40DC4C91C98910%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22tojens_1-1650495363980.png%22%20alt%3D%22tojens_1-1650495363980.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAnother%20way%20to%20restore%20the%20original%20NetBIOS%20name%20resolution%20behavior%20is%20to%20use%20the%20registry.%20Under%20the%20%E2%80%9CComputer%5CHKEY_LOCAL_MACHINE%5CSYSTEM%5CCurrentControlSet%5CServices%5CDnscache%5CParameters%E2%80%9D%20key%2C%20create%20a%20REG_DWORD%20called%20%E2%80%9CEnableNetbios%E2%80%9D%20and%20set%20it%20to%20one%20of%20the%20following%20values%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CTABLE%20style%3D%22width%3A%2080%25%3B%22%20border%3D%221%22%20width%3D%2280%25%22%3E%0A%3CTBODY%3E%0A%3CTR%3E%0A%3CTD%20width%3D%2250%25%22%3E0%3C%2FTD%3E%0A%3CTD%20width%3D%2250%25%22%3EDisabled%3C%2FTD%3E%0A%3C%2FTR%3E%0A%3CTR%3E%0A%3CTD%20width%3D%2250%25%22%3E1%3C%2FTD%3E%0A%3CTD%20width%3D%2250%25%22%3EAllowed%3C%2FTD%3E%0A%3C%2FTR%3E%0A%3CTR%3E%0A%3CTD%20width%3D%2250%25%22%3E2%3C%2FTD%3E%0A%3CTD%20width%3D%2250%25%22%3EDisabled%20on%20public%20networks%3C%2FTD%3E%0A%3C%2FTR%3E%0A%3CTR%3E%0A%3CTD%20width%3D%2250%25%22%3E3%3C%2FTD%3E%0A%3CTD%20width%3D%2250%25%22%3ELearning%20mode%20(the%20current%20default%20in%20Insider%20builds)%3C%2FTD%3E%0A%3C%2FTR%3E%0A%3C%2FTBODY%3E%0A%3C%2FTABLE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20default%20LLMNR%20behavior%20has%20not%20been%20changed%20in%20Windows%20yet.%20This%20will%20be%20part%20of%20the%20next%20steps%20toward%20the%20%E2%80%9CmDNS%20is%20the%20only%20multicast%20name%20resolution%20protocol%20on%20by%20default%E2%80%9D%20goal.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EGoing%20forward%2C%20depending%20on%20how%20this%20first%20stage%20goes%20(so%20far%2C%20the%20data%20indicate%20it%20is%20going%20well)%2C%20these%20protocols%20will%20progress%20toward%20being%20turned%20off%20by%20default%20in%20all%20cases.%20Like%20any%20other%20case%20of%20disabling%20long-enabled%20OS%20functionality%2C%20this%20will%20be%20a%20careful%20process%20open%20to%20feedback.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-3290816%22%20slang%3D%22en-US%22%3E%3CP%3EDescribing%20our%20first%20step%20toward%20turning%20NetBIOS%20name%20resolution%20and%20LLMNR%20off%20by%20default%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3297725%22%20slang%3D%22en-US%22%3ERe%3A%20Aligning%20on%20mDNS%3A%20ramping%20down%20NetBIOS%20name%20resolution%20and%20LLMNR%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3297725%22%20slang%3D%22en-US%22%3E%3CP%3EWhere%20do%20you%20download%20the%20ADMX%20for%20this%20setting%3F%20I%20tried%20downloading%20the%20latest%20Windows%2010%20ADMX%20files%20%22Administrative%20Templates%20(.admx)%20for%20Windows%2010%20November%202021%20Update.msi%22%20and%20updating%20our%20central%20store%20but%20this%20policy%20does%20not%20show%20up.%20I%20also%20checked%20a%20Windows%2011%20workstation%20and%20the%20policy%20is%20not%20present%20either.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3294477%22%20slang%3D%22en-US%22%3ERe%3A%20Aligning%20on%20mDNS%3A%20ramping%20down%20NetBIOS%20name%20resolution%20and%20LLMNR%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3294477%22%20slang%3D%22en-US%22%3E%3CP%3EHey%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F129574%22%20target%3D%22_blank%22%3E%40Rafa%C5%82%20Fitt%3C%2FA%3E%26nbsp%3Bgood%20question.%20PNRP%20is%20deprecated.%20The%20official%20notice%20can%20be%20found%20on%20this%20page%20alongside%20other%20deprecations%20in%20the%20same%20release%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fplanning%2Fwindows-10-removed-features%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fplanning%2Fwindows-10-removed-features%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3292857%22%20slang%3D%22en-US%22%3ERe%3A%20Aligning%20on%20mDNS%3A%20ramping%20down%20NetBIOS%20name%20resolution%20and%20LLMNR%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3292857%22%20slang%3D%22en-US%22%3E%3CP%3EFrom%20the%20link%20you%20supplied%2C%26nbsp%3BPeer%20Name%20Resolution%20Protocol%20(PNRP)%20looks%20very%20interesting.%20Was%20is%20the%20support%20status%20of%20PNRP%3F%20Sunsetting%2Fdeprecated%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3345261%22%20slang%3D%22en-US%22%3ERe%3A%20Aligning%20on%20mDNS%3A%20ramping%20down%20NetBIOS%20name%20resolution%20and%20LLMNR%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3345261%22%20slang%3D%22en-US%22%3E%3CP%3EHey%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1148950%22%20target%3D%22_blank%22%3E%40Jason_Palazzo%3C%2FA%3E%26nbsp%3Bbecause%20this%20feature%20is%20in%20Windows%2011%20Insider%20builds%20only%2C%20it%20is%20not%20part%20of%20any%20previous%20product%20release%2C%20including%20Windows%2010.%20You%20will%20need%20to%20test%20out%20the%20feature%20using%20Insider%20builds%20available%20at%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Finsider.windows.com%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Finsider.windows.com%2F%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3372767%22%20slang%3D%22en-US%22%3ERe%3A%20Aligning%20on%20mDNS%3A%20ramping%20down%20NetBIOS%20name%20resolution%20and%20LLMNR%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3372767%22%20slang%3D%22en-US%22%3E%3CP%3ETommy%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAssuming%20then%20that%20the%20Registry%20key%20also%20does%20nothing%20on%20prior%20Windows%2011%2F10%20builds%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3415832%22%20slang%3D%22en-US%22%3ERe%3A%20Aligning%20on%20mDNS%3A%20ramping%20down%20NetBIOS%20name%20resolution%20and%20LLMNR%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3415832%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F104158%22%20target%3D%22_blank%22%3E%40Brian%20Steingraber%3C%2FA%3E%26nbsp%3Bthat%20is%20correct.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Version history
Last update:
‎Apr 22 2022 09:00 AM
Updated by: