In recent weeks I've seen a considerable amount of CIFS traffic in some of our sites, mostly on port 445. No thanks to Microsoft, but it seems to me that a pile of different services and applications are integerted under port 445. Now I understand port 445 can be a vulnerability, but security is not a a concern [at least not my responsiblity]. It's been called a very 'chatty' protocol. Some ISPs do block this port on behalf of their users.
So when I see 4 GB of CIFS traffic through port 445, how do I know what it was used for? Is it file sharing, print sharing, application sharing or something else? It appears to me that some local system admins have deployed all kinds of servers without realizing the flow of data on the link or without consulting with the network group. How do I spell collaboration?