News
SMB in practice: the protocol, its advantages, and the optimal setup for Synology NAS and Windows Server
Since macOS 27, it is final: Apple Filing Protocol (AFP) disappears completely from macOS, even as a client. Apple already switched to SMB as its default protocol back in 2013 and removed the AFP server from macOS in 2020. Now the last step has been taken too. Every Mac that connects to a network drive, NAS, or server now does so exclusively over SMB. For an SMB IT contact, this is a good moment to review that SMB setup properly, whether it involves a Synology NAS in the server cabinet or a Windows Server with shared folders. This whitepaper explains exactly what SMB is, why the protocol became the standard, and how to set up both a Synology NAS and a Windows Server as optimally as possible for file sharing, with an eye on speed and security.
What is SMB?
SMB stands for Server Message Block, a network protocol that lets devices share files, folders, and printers with each other over a network. It was originally developed by Microsoft, but is now supported by virtually every operating system and every NAS: Windows, macOS, Linux (through the open source Samba implementation), and devices from Synology, QNAP, and other NAS brands.
The protocol has existed since the 1980s and has been developed considerably since then. The oldest version, SMB1 (with its predecessor CIFS), is now known as slow and insecure. The protocol is very “chatty,” generating a lot of small network traffic, and was the basis for major attacks such as the WannaCry ransomware in 2017. SMB2, introduced in 2006 with Windows Vista, brought a major cleanup: the number of subcommands went from more than a hundred to fewer than twenty, making the protocol generate far less network traffic. SMB3, with Windows Server 2012 and Windows 8, added SMB Multichannel and end-to-end encryption. The current version, SMB 3.1.1, since Windows Server 2016 and Windows 10, added preauthentication integrity: a mechanism that detects and blocks downgrade attacks on the connection.
Why Apple now leans entirely on SMB
For an Apple environment this history matters because Apple itself long used its own protocol: AFP, Apple Filing Protocol. The move to SMB happened in clear steps.
2013: SMB becomes the default
With OS X Mavericks (10.9), Apple made SMB the default protocol for file sharing, replacing AFP.
2020: the AFP server disappears
macOS 11 Big Sur removed the AFP server entirely from macOS. From then on, a Mac could no longer offer an AFP share to other devices.
May 2025: the AFP client marked deprecated
macOS Sequoia 15.5 marked the AFP client, the component that connects to existing AFP shares, as officially deprecated.
macOS 27: no more AFP
The macOS 27 developer preview no longer includes an AFP client at all. A Mac can then only connect to a network share using SMB.
APFS, the file system Apple has used since 2017, also played a role: AFP was never able to properly support this newer file system. For an SMB IT contact, this mainly means one thing: if there is still an old NAS configuration, script, or backup job anywhere that relies on AFP, it needs to be migrated to SMB now. Waiting is no longer an option.
The advantages of SMB at a glance
The current SMB versions, 3.0 and higher, offer a number of clear advantages over the old SMB1 and over other protocols such as NFS.
⚡ Speed
SMB Multichannel bundles multiple network connections at once, increasing throughput and providing failover if one connection drops. SMB2 and higher are also far less “chatty” than SMB1.
🔒 Security
SMB signing protects against tampering with data traffic, encryption (AES-256-GCM in the newest versions) protects against eavesdropping, and preauthentication integrity prevents an attacker from secretly forcing the connection back down to an older, insecure version.
🌐 Cross-platform
Windows, macOS, Linux, and virtually every NAS brand speak native SMB. In a mixed office with both Mac and Windows, you only need one protocol for all file sharing.
🚀 SMB Direct
With RDMA network cards, Remote Direct Memory Access, SMB Direct can approach the speed of local storage almost directly, with low CPU usage. Especially relevant for heavier environments such as virtualization or large backup jobs.
Which SMB version should you allow at minimum?
Both Synology and Microsoft recommend the same thing: disable SMB1 entirely and use SMB2 as the absolute minimum, with SMB3 (3.1.1) as the maximum. SMB1 has not even been installed by default since Windows 10 and Windows Server version 1709 (2017). On Synology, you actually cannot set the minimum version to SMB3: the combination of minimum SMB2, maximum SMB3 is exactly the recommended configuration for the best balance between compatibility and security.
Network and firewall: what does SMB need to get through?
SMB2 and SMB3 only need one port: TCP 445. The older NetBIOS ports 137 through 139 are only relevant for SMB1/CIFS and no longer need to be open in a modern setup.
Setting up a Synology NAS optimally for SMB
On a Synology NAS you manage all SMB settings in DSM through Control Panel > File Services > SMB > Advanced Settings. For most SMB environments this is the recommended baseline setup.
- Set the minimum SMB version to SMB2 and the maximum to SMB3, and disable SMB1 entirely.
- Turn on SMB encryption if sensitive data crosses the network, weighing this against a small impact on speed.
- Keep DSM and the NAS firmware updated regularly, since security fixes for SMB are often included in these updates.
- For Mac backups, create a separate shared folder used only for Time Machine, rather than reusing a general data folder.
- On that Time Machine folder, enable the Bonjour Time Machine broadcast over SMB, not AFP, since that no longer exists, so Mac users automatically see the NAS as a backup destination.
- Turn off the recycle bin and folder encryption on that folder: Time Machine already encrypts the backup itself, so double encryption only costs performance.
- Reserve at least twice, and preferably three to four times, the storage capacity of the Mac’s internal drive, so there is enough room for multiple backup versions.
Setting up Windows Server optimally for SMB
On Windows Server, the setup mainly revolves around three things: getting rid of SMB1 for good, requiring signing, and deliberately choosing where encryption is needed.
- Check that the SMB1 server feature has actually been removed, which happens by default since Windows Server version 1709, using
Get-WindowsFeature FS-SMB1in PowerShell, or through the Files & File Sharing extension in Windows Admin Center. - Require SMB signing, so every packet is signed and cannot be tampered with in transit.
- Turn on SMB encryption per share with
Set-SmbShare -Name <sharename> -EncryptData $true, or for the whole server withSet-SmbServerConfiguration -EncryptData $true. - Leave SMB Multichannel active, which is on by default: with multiple network cards, Windows automatically bundles the bandwidth and handles a broken connection itself.
- Consider SMB Direct if the server has RDMA network cards. Since Windows Server 2022, this traffic can also be encrypted without the major performance hit of the past.
- Keep the server updated: Windows Server 2022 and 2025 automatically negotiate stronger encryption (AES-256-GCM/CCM) and signing (AES-128-GMAC) with clients that support it.
How Mac clients connect
A Mac connects to an SMB share through Finder: Go > Connect to Server (Cmd+K), followed by smb://servername/sharename. Since SMB3 is now the default in macOS, a connection is automatically signed as soon as you log in with a real account. Only guest or anonymous access skips this. For troubleshooting, you can adjust settings such as required signing in /etc/nsmb.conf, but that is meant purely to temporarily isolate a problem on a trusted network, not as a permanent setting.
Synology, Windows Server, or both?
Both platforms speak the same SMB protocol, so the choice mainly depends on what else the business needs.
💾 Synology NAS
Lower purchase cost, quick to set up, and ideal as a central storage and backup destination, including Time Machine for Mac users.
🖥️ Windows Server
Needed as soon as Active Directory or Entra ID integration, Group Policy, detailed NTFS permissions, or Windows specific business applications come into play.
🤝 Both at once
Common among SMB clients: Synology for general storage and Mac backups, Windows Server for domain-bound shares. Mac and Windows clients connect the same way over SMB in both cases.
A practical scenario for SMBs
A common path for an IT contact at an SMB client with a mixed Mac/Windows environment and an older NAS that still partly relied on AFP:
- Take stock of which shares, backup jobs, or scripts still rely on AFP, given its complete removal in macOS 27.
- Update the Synology NAS to the latest DSM version and set minimum SMB2, maximum SMB3, with SMB1 off.
- Create a separate Time Machine share with Bonjour broadcast over SMB, without a recycle bin or folder encryption.
- Check on the Windows Server that SMB1 is actually removed and require signing.
- Decide per share whether encryption is needed: yes for, say, a finance department, not necessarily for general project folders.
- Test the connection from both a Mac (Cmd+K,
smb://) and a Windows client (\\servername\sharename). - Document the chosen settings and schedule a fixed moment to update firmware and Windows Server.
With this setup, the SMB client is not just prepared for the complete disappearance of AFP, but immediately benefits from a faster and better secured network for all Mac and Windows users.
Analyst ICT is an officially recognised Apple Technical Partner. Want to know more about Apple within your organisation? See our overview for business or email frank@analystict.nl.