netusim co a kde u tebe bezi, ale kdyz pohlednes na vypis (jako root) z ``netstat -tulnp'' tak tam uvidis, jake sluzby bezi .... pokud tam bezi smb a ty ho nechces, tak proste zakaz danou sluzbu ....
take si to muzes nastavit na urovni iptables, tedy zakazes pristup na portech 139 a 445 (na vnejsich rozhranich), muj fw vypada takto
# iptables-save
# Generated by iptables-save v1.4.21 on Thu Mar 3 09:41:29 2016
*filter
:INPUT DROP [5140:433261]
:FORWARD DROP [53:2627]
:OUTPUT ACCEPT [3702924:4411776601]
-A INPUT -i lo -j ACCEPT
-A INPUT -i vboxnet0 -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m tcp --dport 3389 -j ACCEPT
-A INPUT -p tcp -m conntrack --ctstate NEW -m tcp --dport 22 -j ACCEPT
-A FORWARD -s 192.168.255.0/24 -j ACCEPT
-A FORWARD -d 192.168.255.0/24 -j ACCEPT
COMMIT
# Completed on Thu Mar 3 09:41:29 2016
# Generated by iptables-save v1.4.21 on Thu Mar 3 09:41:29 2016
*raw
:PREROUTING ACCEPT [4885807:10441499604]
:OUTPUT ACCEPT [3702924:4411776601]
COMMIT
# Completed on Thu Mar 3 09:41:29 2016
# Generated by iptables-save v1.4.21 on Thu Mar 3 09:41:29 2016
*nat
:PREROUTING ACCEPT [5439:699173]
:INPUT ACCEPT [97:9929]
:OUTPUT ACCEPT [203492:14282735]
:POSTROUTING ACCEPT [203492:14282735]
-A PREROUTING -p tcp -m tcp --dport 3389 -j DNAT --to-destination 192.168.255.10:3389
-A POSTROUTING -s 192.168.255.0/24 -j MASQUERADE
COMMIT
# Completed on Thu Mar 3 09:41:29 2016
btw, v ubu zjevne nemate chkconfig .... v debianu je, za to se omlouvam, nemam ubu, vy mate neco jo rc.update nebo tak nejak ...