![]() |
|
#1
|
||||
|
||||
|
I don't exactly understand Blitz's kerio 2.1.5 rules. I am behind a router, and over at dsl reports he says to use the router configuration, what do I do with that as I am not using it and all seems to be working fine. How does this look so far for my rules?
|
|
#2
|
||||
|
||||
|
Second part
|
|
#3
|
||||
|
||||
|
I am an idiot when it comes to rules, so please help me out
|
|
#4
|
||||
|
||||
|
Hi Slovak
You may be fine without the router rule. If you were logging from the router, then a rule would be required. If you have other systems behind the router, LAN rules would also be required. Secondary DNS is a duplicate (same as Primary DNS). Unrestricted DNS not needed if using above. Your Block All rules should be at the end of the rule set. Enable the Inbound, but leave the Outbound disabled for now. Regards, CrazyM
__________________
"The best thing we can do in cyberspace is exactly what we do in the real world: do our best to manage the risks." - Bruce Schneier |
|
#5
|
||||
|
||||
|
The router rule allows you not to have to specify the router dns/dhcp in the rules, and allows for a second configuration without any hassle. Like if you use your laptop at home, and away from home, this already allows for two seperate configurations.
I did mention in the default replacement thread some basic things like disabling the unresticted dns when you had specified your dns servers to prevent dns tunneling, and making sure the block all rules were at the end of your ruleset. Also Avast's mail, and web filtering are a software proxy so you need to exclude those ports used from the ports available with the software proxy loopback rule. This way any software you don't want getting out, won't get out without your permission that is being redirected by these services.
__________________
Yesterday we obeyed kings, and bent our necks before emperors. But today we kneel only to the truth. -Kahlil Gibran |
|
#6
|
||||
|
||||
|
Quote:
|
|
#7
|
||||
|
||||
|
Quote:
|
|
#8
|
||||
|
||||
|
Also Avast's mail, and web filtering are a software proxy so you need to exclude those ports used from the ports available with the software proxy loopback rule. This way any software you don't want getting out, won't get out without your permission that is being redirected by these services.
Do you still need to use the standard loopback rule with the software loopback rule? Regards
__________________
I think computer viruses should count as life. I think it says something about human nature that the only form of life we have created so far is purely destructive. We've created life in our own image. - Stephen Hawking |
|
#9
|
||||
|
||||
|
Quote:
![]()
__________________
Yesterday we obeyed kings, and bent our necks before emperors. But today we kneel only to the truth. -Kahlil Gibran |
|
#10
|
||||
|
||||
|
Quote:
Are you sharing any files or printers with other systems on the LAN? Regards, CrazyM
__________________
"The best thing we can do in cyberspace is exactly what we do in the real world: do our best to manage the risks." - Bruce Schneier |
|
#11
|
||||
|
||||
|
Quote:
Thanks, for the reply, I must have missed it entirely when I read the ruleset page everything else I seem to have grasped fairly well. I just switched to Kerio 2.1.5 a week ago from Sygate and love it. Your ruleset page made it very easy to understand things I did not know prior. Thanx again for the reply.
__________________
I think computer viruses should count as life. I think it says something about human nature that the only form of life we have created so far is purely destructive. We've created life in our own image. - Stephen Hawking |
|
#12
|
||||
|
||||
|
Quote:
|
|
#13
|
||||
|
||||
|
Anyone?
|
|
#14
|
||||
|
||||
|
ipconfig /all should display full configuration information.
Regards, CrazyM
__________________
"The best thing we can do in cyberspace is exactly what we do in the real world: do our best to manage the risks." - Bruce Schneier |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|