Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other firewalls
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 20th, 2005, 09:20 PM
Slovak's Avatar
Slovak Slovak is offline
Frequent Poster
 
Join Date: Mar 2004
Location: Medina, Ohio
Posts: 515
Default Help me with Kerio 2.1.5 rules please

I don't exactly understand Blitz's kerio 2.1.5 rules. I am behind a router, and over at dsl reports he says to use the router configuration, what do I do with that as I am not using it and all seems to be working fine. How does this look so far for my rules?
Attached Images
 
  #2  
Old February 20th, 2005, 09:27 PM
Slovak's Avatar
Slovak Slovak is offline
Frequent Poster
 
Join Date: Mar 2004
Location: Medina, Ohio
Posts: 515
Default Re: Help me with Kerio 2.1.5 rules please

Second part
Attached Images
 
  #3  
Old February 20th, 2005, 09:28 PM
Slovak's Avatar
Slovak Slovak is offline
Frequent Poster
 
Join Date: Mar 2004
Location: Medina, Ohio
Posts: 515
Default Re: Help me with Kerio 2.1.5 rules please

I am an idiot when it comes to rules, so please help me out
  #4  
Old February 20th, 2005, 09:41 PM
CrazyM's Avatar
CrazyM CrazyM is offline
Firewall Moderator
 
Join Date: Feb 2002
Location: BC, Canada
Posts: 2,433
Default Re: Help me with Kerio 2.1.5 rules please

Hi Slovak

You may be fine without the router rule. If you were logging from the router, then a rule would be required. If you have other systems behind the router, LAN rules would also be required.

Secondary DNS is a duplicate (same as Primary DNS).

Unrestricted DNS not needed if using above.

Your Block All rules should be at the end of the rule set. Enable the Inbound, but leave the Outbound disabled for now.

Regards,

CrazyM
__________________
"The best thing we can do in cyberspace is exactly what we do in the real world: do our best to manage the risks."
- Bruce Schneier
  #5  
Old February 20th, 2005, 09:50 PM
BlitzenZeus's Avatar
BlitzenZeus BlitzenZeus is offline
Security Expert
 
Join Date: Feb 2002
Location: Oregon, USA
Posts: 451
Default Re: Help me with Kerio 2.1.5 rules please

The router rule allows you not to have to specify the router dns/dhcp in the rules, and allows for a second configuration without any hassle. Like if you use your laptop at home, and away from home, this already allows for two seperate configurations.

I did mention in the default replacement thread some basic things like disabling the unresticted dns when you had specified your dns servers to prevent dns tunneling, and making sure the block all rules were at the end of your ruleset.

Also Avast's mail, and web filtering are a software proxy so you need to exclude those ports used from the ports available with the software proxy loopback rule. This way any software you don't want getting out, won't get out without your permission that is being redirected by these services.
__________________
Yesterday we obeyed kings, and bent our necks before emperors. But today we kneel only to the truth. -Kahlil Gibran
  #6  
Old February 20th, 2005, 10:08 PM
Slovak's Avatar
Slovak Slovak is offline
Frequent Poster
 
Join Date: Mar 2004
Location: Medina, Ohio
Posts: 515
Default Re: Help me with Kerio 2.1.5 rules please

Quote:
Originally Posted by BlitzenZeus
The router rule allows you not to have to specify the router dns/dhcp in the rules,
So for the dhcp stuff, I get it from ipconfig /all, and put the dhcp address in Assign DHCP Server?
  #7  
Old February 20th, 2005, 10:17 PM
Slovak's Avatar
Slovak Slovak is offline
Frequent Poster
 
Join Date: Mar 2004
Location: Medina, Ohio
Posts: 515
Default Re: Help me with Kerio 2.1.5 rules please

Quote:
Originally Posted by CrazyM
Hi Slovak

If you have other systems behind the router, LAN rules would also be required.
I do, I only need them IF I want them to be able to connect to me, right?
  #8  
Old February 20th, 2005, 10:39 PM
Honyak's Avatar
Honyak Honyak is offline
Frequent Poster
 
Join Date: Jul 2004
Location: Deep South
Posts: 346
Default Re: Help me with Kerio 2.1.5 rules please

Also Avast's mail, and web filtering are a software proxy so you need to exclude those ports used from the ports available with the software proxy loopback rule. This way any software you don't want getting out, won't get out without your permission that is being redirected by these services.

Do you still need to use the standard loopback rule with the software loopback rule?

Regards
__________________
I think computer viruses should count as life. I think it says something about human nature that the only form of life we have created so far is purely destructive. We've created life in our own image.
- Stephen Hawking
  #9  
Old February 20th, 2005, 10:50 PM
BlitzenZeus's Avatar
BlitzenZeus BlitzenZeus is offline
Security Expert
 
Join Date: Feb 2002
Location: Oregon, USA
Posts: 451
Default Re: Help me with Kerio 2.1.5 rules please

Quote:
Originally Posted by Honyak
Do you still need to use the standard loopback rule with the software loopback rule?
No, and that is another question already answered by looking at the page where the ruleset is located
__________________
Yesterday we obeyed kings, and bent our necks before emperors. But today we kneel only to the truth. -Kahlil Gibran
  #10  
Old February 20th, 2005, 11:00 PM
CrazyM's Avatar
CrazyM CrazyM is offline
Firewall Moderator
 
Join Date: Feb 2002
Location: BC, Canada
Posts: 2,433
Default Re: Help me with Kerio 2.1.5 rules please

Quote:
Originally Posted by Slovak
I do, I only need them IF I want them to be able to connect to me, right?
Right, just keep in mind your current rule set will likely result in numerous log entries from these systems.

Are you sharing any files or printers with other systems on the LAN?

Regards,

CrazyM
__________________
"The best thing we can do in cyberspace is exactly what we do in the real world: do our best to manage the risks."
- Bruce Schneier
  #11  
Old February 20th, 2005, 11:02 PM
Honyak's Avatar
Honyak Honyak is offline
Frequent Poster
 
Join Date: Jul 2004
Location: Deep South
Posts: 346
Default Re: Help me with Kerio 2.1.5 rules please

Quote:
Originally Posted by BlitzenZeus
No, and that is another question already answered by looking at the page where the ruleset is located

Thanks, for the reply, I must have missed it entirely when I read the ruleset page everything else I seem to have grasped fairly well. I just switched to Kerio 2.1.5 a week ago from Sygate and love it. Your ruleset page made it very easy to understand things I did not know prior.
Thanx again for the reply.
__________________
I think computer viruses should count as life. I think it says something about human nature that the only form of life we have created so far is purely destructive. We've created life in our own image.
- Stephen Hawking
  #12  
Old February 21st, 2005, 09:44 AM
Slovak's Avatar
Slovak Slovak is offline
Frequent Poster
 
Join Date: Mar 2004
Location: Medina, Ohio
Posts: 515
Default Re: Help me with Kerio 2.1.5 rules please

Quote:
Originally Posted by Slovak
So for the dhcp stuff, I get it from ipconfig /all, and put the dhcp address in Assign DHCP Server?
Is this correct?
  #13  
Old February 22nd, 2005, 05:32 AM
Slovak's Avatar
Slovak Slovak is offline
Frequent Poster
 
Join Date: Mar 2004
Location: Medina, Ohio
Posts: 515
Default Re: Help me with Kerio 2.1.5 rules please

Anyone?
  #14  
Old February 23rd, 2005, 02:44 AM
CrazyM's Avatar
CrazyM CrazyM is offline
Firewall Moderator
 
Join Date: Feb 2002
Location: BC, Canada
Posts: 2,433
Default Re: Help me with Kerio 2.1.5 rules please

ipconfig /all should display full configuration information.

Regards,

CrazyM
__________________
"The best thing we can do in cyberspace is exactly what we do in the real world: do our best to manage the risks."
- Bruce Schneier
 

Wilders Security Forums > Security Products > other firewalls « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:07 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums