Unable to access ROCK via LAN on Windows for codec upload (ref#A00T7T)

Hi! What’s not quite right with Roon?

· None of the above quite fits

None of the above quite fits

· None of these quite match

Tell us what's going on

· I can't access my ROCK via LAN (on Windows) for upload codecs. username and password not working

Tell us about your home network

· 1gbps lan (wired)

Please read this post:

Thank you

Does Roon Rock work on SMB1??!!?? That’s super dangerous!

No - it doesn’t. It uses SMBv2. The issue is caused by Microsoft being ultra cautious. Valid for business networks, but overkill in a home network.

I uploaded the codecs to the CODECS directory (the ffmpeg file), but after restarting the server, I’m still getting a message saying the codecs are missing.

Did you copy the archive or extract and copy a single file: ffmpeg?

I repeated the procedure and it works.
On Windows Pro 25H2, there are no “Lanman” or “Insecure Guest Logon” options in Group Policy Editor; the easiest way is to use PowerShell and enter:

Set-SmbClientConfiguration -EnableInsecureGuestLogons $true

Additionally, regarding SMB1—the nmap scan results [shows that SMB v1 works on Roon Core:

Host script results:
| smb-protocols:
| dialects:
| NT LM 0.12 (SMBv1) [dangerous, but default]
|_ 2.0.2

I repeated the procedure and everything is working. Thank you for your help.

But you should use SMB 2.0 for obvious reasons.

That’s clear, but the Roon ROCK itself shouldn’t have SMB v1 enabled at all! After all, that involves a known security vulnerability. Why hasn’t Roon Labs updated it?

I think you’ll find that the negotiated version is SMB 2.0.

Yes, but having SMB v1 enabled is a security vulnerability.

It works but it defaults to SMBv2. There are older devices out there that would break if v1 was disabled because they don’t do v2.

It’s also only super dangerous if used over the internet or maybe in a not entirely trusted company network where you shouldn’t use Roon in the first place, not on a trusted home LAN. Nevertheless, v1 is a crappy, chatty protocol, but it defaults to v2 anyway.

I think there should be an option to manually enable SMB v1 for anyone who still needs that protocol.

Maybe but if you have intruders on the LAN that can exploit v1, you have bigger problems

that’s for sure!

Hi @Marcin_Wojna,

Thanks for confirming that it works now, and for sharing the Windows steps you used. It is useful context for anyone running into the same LAN access issue on ROCK.

We’re aware this area needs some attention and we have a ticket looking into how we can better improve this experience from Windows remotes.

Glad this is resolved. Enjoy your music, and we will go ahead and close this one out.