pcalvert
June 23rd, 2005, 08:44 PM
I am using Kerio 2.1.5 with BlitzenZeus's default replacement ruleset (standard). I have noticed that some probes generate outgoing network activity. I noticed this when I was using Sygate PF, and it's part of the reason why I am trying Kerio right now.
It seems that the replies are associated with TCP inbound to port 445. I've determined this by looking in the firewall log immediately after the outgoing activity.
After seeing a lot of this going on today, I installed the demo for Port Explorer. By monitoring in real time with Port Explorer, I have a slightly better idea of what's going on. After some of the inbound connection attempts to port 445, my computer is responding by sending something to my ISP's domain name server, and Kerio 2.1.5 is letting it.
It seems odd that probes to port 445 would generate replies of some sort, while probes to other ports do not. I should probably add that, as far as I know, port 445 is closed (I am using Windows 98 SE). Anyone have an idea of what is going on here?
BTW, I'm not sure that this a Kerio 2.1.5 problem. I recall seeing similar behavior when I was using Sygate PF and NetVeda Safety.Net, though probably to a lesser degree.
Phil
It seems that the replies are associated with TCP inbound to port 445. I've determined this by looking in the firewall log immediately after the outgoing activity.
After seeing a lot of this going on today, I installed the demo for Port Explorer. By monitoring in real time with Port Explorer, I have a slightly better idea of what's going on. After some of the inbound connection attempts to port 445, my computer is responding by sending something to my ISP's domain name server, and Kerio 2.1.5 is letting it.
It seems odd that probes to port 445 would generate replies of some sort, while probes to other ports do not. I should probably add that, as far as I know, port 445 is closed (I am using Windows 98 SE). Anyone have an idea of what is going on here?
BTW, I'm not sure that this a Kerio 2.1.5 problem. I recall seeing similar behavior when I was using Sygate PF and NetVeda Safety.Net, though probably to a lesser degree.
Phil