Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other firewalls
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 27th, 2004, 05:26 PM
cibaker cibaker is offline
Infrequent Poster
 
Join Date: Oct 2004
Posts: 1
Default Kerio Firewall.

Hi all, Ive just downloaded Kerio Personal Firewall 4, and ive noticed it doesnt ask me if i want to permit or block applications when i start programs, like Zonealarm and other software firewalls do. I have enabled the option "Use existing system security rules, or ask me" option under "When an application is about to start".

But it doesnt ask me when i start new applications, it just doesn't feel safe, What if a virus or a dialer trys to connect to the internet, it will let it.

Any ideas how to fix this?
  #2  
Old October 27th, 2004, 06:26 PM
ronjor's Avatar
ronjor ronjor is online now
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,357
Default Re: Kerio Firewall.

cibaker

It's been awhile since I tested KPF4. If it were me, I would download the manual or check the help file closely.
It should alert when apps try to open other apps.

Kerio
  #3  
Old October 27th, 2004, 06:47 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,620
Default Re: Kerio Firewall.

It absoluty should alert you.
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #4  
Old October 27th, 2004, 08:41 PM
Kerodo Kerodo is offline
Incredibly Massive Poster
 
Join Date: Oct 2004
Posts: 6,153
Default Re: Kerio Firewall.

Quote:
Originally Posted by cibaker
Hi all, Ive just downloaded Kerio Personal Firewall 4, and ive noticed it doesnt ask me if i want to permit or block applications when i start programs, like Zonealarm and other software firewalls do. I have enabled the option "Use existing system security rules, or ask me" option under "When an application is about to start".

But it doesnt ask me when i start new applications, it just doesn't feel safe, What if a virus or a dialer trys to connect to the internet, it will let it.

Any ideas how to fix this?

You might want to consider another firewall. Kerio 4.1x is quite buggy still. I'd give it another 3-6 months before they get things stabilized. I played with several of the beta's before the 4.1 release and there were many bugs. Then they rushed right into release, with many things unfixed.

Check Kerio's forums for more info and see some of the problems others are having..
  #5  
Old October 28th, 2004, 01:22 AM
Amerk_5's Avatar
Amerk_5 Amerk_5 is offline
Regular Poster
 
Join Date: May 2003
Location: Dansville, NY
Posts: 78
Default Re: Kerio Firewall.

Kerio v2.1.5 is an excellent choice. I still use it among many people who tried Kerio v4.x and couldn't stand it.
  #6  
Old October 28th, 2004, 02:56 AM
Kerodo Kerodo is offline
Incredibly Massive Poster
 
Join Date: Oct 2004
Posts: 6,153
Default Re: Kerio Firewall.

Quote:
Originally Posted by Amerk_5
Kerio v2.1.5 is an excellent choice. I still use it among many people who tried Kerio v4.x and couldn't stand it.

Kerio 2.1.5 is definitely the best of the two. Doesn't seem like 4.x will survive.
  #7  
Old October 28th, 2004, 05:05 AM
no13's Avatar
no13 no13 is offline
Retired Major Resident Nutcase
 
Join Date: Sep 2004
Location: Wouldn't YOU like to know?
Posts: 1,327
Default Re: Kerio Firewall.

kerio 4.0.x is better and less buggy.
  #8  
Old October 28th, 2004, 06:27 AM
Kerodo Kerodo is offline
Incredibly Massive Poster
 
Join Date: Oct 2004
Posts: 6,153
Default Re: Kerio Firewall.

Quote:
Originally Posted by no13
kerio 4.0.x is better and less buggy.

That's probably true.. 4.0.16 might be ok. 4.1.x is a mess...
  #9  
Old November 4th, 2004, 02:09 PM
dlhan dlhan is offline
Infrequent Poster
 
Join Date: Nov 2004
Posts: 6
Default Re: Kerio Firewall.

Quote:
Originally Posted by cibaker
Hi all, Ive just downloaded Kerio Personal Firewall 4, and ive noticed it doesnt ask me if i want to permit or block applications when i start programs, like Zonealarm and other software firewalls do. I have enabled the option "Use existing system security rules, or ask me" option under "When an application is about to start".

But it doesnt ask me when i start new applications, it just doesn't feel safe, What if a virus or a dialer trys to connect to the internet, it will let it.

Any ideas how to fix this?
Just to make sure (because I forgot to) you did place a checkmark in the "Enable System security Module" at the top of the applications page.
  #10  
Old November 6th, 2004, 11:30 AM
Jimbob1989's Avatar
Jimbob1989 Jimbob1989 is offline
Banned
 
Join Date: Oct 2004
Posts: 2,529
Default Re: Kerio Firewall.

I have heard great things about the firewall however problems can occur with any software.

Jimbob
  #11  
Old November 6th, 2004, 12:19 PM
james2323
 
Posts: n/a
Default Re: Kerio Firewall.

Quote:
Originally Posted by Kerodo
Kerio 2.1.5 is definitely the best of the two. Doesn't seem like 4.x will survive.

Except kerio 2.1.5 doesnt handle fragmented packets which is very serious
  #12  
Old November 6th, 2004, 12:27 PM
no13's Avatar
no13 no13 is offline
Retired Major Resident Nutcase
 
Join Date: Sep 2004
Location: Wouldn't YOU like to know?
Posts: 1,327
Default Re: Kerio Firewall.

hey james2323... care to explain "fragmented packets" and their mishandling? What kind of hacker would implement THAT attack on a poor home user? Maybe such an attack from usual website is more probable (just as a result of poor programming)
__________________
1337 4-3v3r!
Thanks for all this...
take down my gmail and yahoo [msgr] id's if you want
//||// [[]] 11 33
  #13  
Old November 6th, 2004, 02:55 PM
Kerodo Kerodo is offline
Incredibly Massive Poster
 
Join Date: Oct 2004
Posts: 6,153
Default Re: Kerio Firewall.

Quote:
Originally Posted by james2323
Except kerio 2.1.5 doesnt handle fragmented packets which is very serious

Yes, this is very true.. I have stopped using 2.1.5 because of this problem. Not only fragmented packets, but it looks like it doesn't handle TCP with certain flags also. A lot of Kerio 2.x users are going to be very unhappy about this. The sad thing is, I'm betting that a lot of people are just going to ignore it too.

See the thread below for more details:

http://www.dslreports.com/forum/rema...7449~mode=flat
  #14  
Old November 6th, 2004, 07:36 PM
james232
 
Posts: n/a
Default Re: Kerio Firewall.

Quote:
Originally Posted by no13
hey james2323... care to explain "fragmented packets" and their mishandling? What kind of hacker would implement THAT attack on a poor home user? Maybe such an attack from usual website is more probable (just as a result of poor programming)

LOL, it does not take a hacker to craft fragmented packets.

Altough Kerodo apparantly just discovered it ,it is actually very old news. Search this forum for details.
  #15  
Old November 6th, 2004, 07:37 PM
james232r
 
Posts: n/a
Default Re: Kerio Firewall.

Quote:
Originally Posted by Kerodo
Yes, this is very true.. I have stopped using 2.1.5 because of this problem. Not only fragmented packets, but it looks like it doesn't handle TCP with certain flags also. A lot of Kerio 2.x users are going to be very unhappy about this. The sad thing is, I'm betting that a lot of people are just going to ignore it too.

See the thread below for more details:

http://www.dslreports.com/forum/rema...7449~mode=flat


LOL, sure they will ignore it, they have ignored it for years... Search this forum for instance and you will see it is periodically mentioned.
  #16  
Old November 6th, 2004, 07:44 PM
james232r
 
Posts: n/a
Default Re: Kerio Firewall.

Quote:
Originally Posted by Kerodo
The sad thing is, I'm betting that a lot of people are just going to ignore it too.

Here's a tip, most people have no idea at all about TCP/IP at all. SYN, ACK,FIN etc just greek to them.

To many, a good firewall is something that gives them a stealth rating at grc, and one that blocks leak test
  #17  
Old November 6th, 2004, 07:51 PM
Kerodo Kerodo is offline
Incredibly Massive Poster
 
Join Date: Oct 2004
Posts: 6,153
Default Re: Kerio Firewall.

Quote:
Originally Posted by james232r
Here's a tip, most people have no idea at all about TCP/IP at all. SYN, ACK,FIN etc just greek to them.

To many, a good firewall is something that gives them a stealth rating at grc, and one that blocks leak test

Very true..
  #18  
Old November 6th, 2004, 11:02 PM
no13's Avatar
no13 no13 is offline
Retired Major Resident Nutcase
 
Join Date: Sep 2004
Location: Wouldn't YOU like to know?
Posts: 1,327
Default Re: Kerio Firewall.

hmm... so is it impossible for us to "break into" kerio's "hiden" default rules that show up in the logs but not in the ruleset listing? Kerio 4x IDS may be manipulated (its snort based), but I was told that the rest is encrypted. So can we? Shouldn't a 3rd party program exist for this?
__________________
1337 4-3v3r!
Thanks for all this...
take down my gmail and yahoo [msgr] id's if you want
//||// [[]] 11 33
 

Wilders Security Forums > Security Products > other firewalls « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:41 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums